๐ฉ๐ช
Vegascosmetics
2026-06-14 06:44:51
(1 week ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-06-12 16:27:20
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 12:27:13.493635 2026] [security2:error] [pid 17251:tid 17251] [client 163.61.129.88:55710] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 163.61.129.88 (+1 hits since last alert)|caquintet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "caquintet.com"] [uri "/xmlrpc.php"] [unique_id "aiwzYSJDZAc2kpd_EA5TYAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-12 13:02:12
(1 week ago)
[FriJun1215:02:04.9853112026][security2:error][pid269639:tid270976][client163.61.129.88:0]ModSecurit ...
show more
[FriJun1215:02:04.9853112026][security2:error][pid269639:tid270976][client163.61.129.88:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"367\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"manishimwe.ch\"][uri\"/xmlrpc.php\"][unique_id\"aiwDTNmsFpfgPcm3W2dlqAAAAFg\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 11:40:27
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 07:40:20.406702 2026] [security2:error] [pid 26867:tid 26867] [client 163.61.129.88:52133] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 163.61.129.88 (+1 hits since last alert)|marianozaro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "marianozaro.com"] [uri "/xmlrpc.php"] [unique_id "aivwJFvJPOU0_aYp6QOFHwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-12 04:35:57
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 04:05:14
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 00:05:02.951109 2026] [security2:error] [pid 27135:tid 27135] [client 163.61.129.88:56937] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 163.61.129.88 (+1 hits since last alert)|luxandunion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "luxandunion.com"] [uri "/xmlrpc.php"] [unique_id "aiuFbu_3Kw647qFP7W6JZAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 16:20:07
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 12:20:00.517474 2026] [security2:error] [pid 5670:tid 5670] [client 163.61.129.88:50830] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 163.61.129.88 (+1 hits since last alert)|circleinthesquare.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "circleinthesquare.org"] [uri "/xmlrpc.php"] [unique_id "airgMLgpHQCK2K4WD7xvTQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 06:08:47
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 02:08:38.279259 2026] [security2:error] [pid 27050:tid 27064] [client 163.61.129.88:64026] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 163.61.129.88 (+1 hits since last alert)|vinylnotespodcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vinylnotespodcast.com"] [uri "/xmlrpc.php"] [unique_id "aipQ5viig3wHNNWILQq7gAAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 15:54:13
(1 week ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-09 15:33:29
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 163.61.129.88 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:33:25.227769 2026] [security2:error] [pid 17628:tid 17628] [client 163.61.129.88:52177] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 163.61.129.88 (+1 hits since last alert)|wurkroom.biz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wurkroom.biz"] [uri "/xmlrpc.php"] [unique_id "aigyRQ2eQue1c0VWxILfRAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-09 11:32:35
(1 week ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ฉ๐ช
LRob.fr
2026-03-27 16:15:03
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
Anonymous
2025-11-20 09:03:22
(7 months ago)
scanning http requests from known botnet
Web App Attack