๐บ๐ธ
WeekendWeb
2026-08-24 02:50:52
(9 hours ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 01:21:10
(11 hours ago)
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic. ...
show more
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic.copelfibra.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 21:21:05.603267 2026] [security2:error] [pid 30229:tid 30229] [client 168.181.49.152:13696] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 168.181.49.152 (+1 hits since last alert)|stop902.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "stop902.org"] [uri "/xmlrpc.php"] [unique_id "aoucgalezbfCO-VVgvEKCAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
n2nguyenn2nguyen
2026-08-23 23:46:25
(12 hours ago)
Blocked by YFC Security on https://brixzly.com โ type: xmlrpc_attempts
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2026-08-23 23:20:16
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (BR/Brazil/152.49.181.168.rfc659 ...
show more
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (BR/Brazil/152.49.181.168.rfc6598.dynamic.copelfibra.com.br): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-23 21:30:13
(15 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 16:48:34
(19 hours ago)
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic. ...
show more
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic.copelfibra.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 12:48:29.652047 2026] [security2:error] [pid 2003837:tid 2003851] [client 168.181.49.152:18840] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 168.181.49.152 (+1 hits since last alert)|jofdt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jofdt.com"] [uri "/xmlrpc.php"] [unique_id "aoskXXAgPPG8lXRlnJkA_wAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-23 16:47:13
(19 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-23 15:49:00
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic. ...
show more
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic.copelfibra.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 11:48:54.103648 2026] [security2:error] [pid 31162:tid 31162] [client 168.181.49.152:14342] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 168.181.49.152 (+1 hits since last alert)|lockdownclaim.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lockdownclaim.com"] [uri "/xmlrpc.php"] [unique_id "aosWZtmvmKgp8xMEfxpdsgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 12:11:30
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic. ...
show more
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic.copelfibra.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:11:23.394878 2026] [security2:error] [pid 20838:tid 20838] [client 168.181.49.152:11713] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 168.181.49.152 (+1 hits since last alert)|zacharypowers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "zacharypowers.com"] [uri "/xmlrpc.php"] [unique_id "aorja2P3XFacmZroXRnmXAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-08-23 12:09:55
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
BR/Brazil/152.49.181.168.rfc6598.dynamic.copelfibra.com.br
Web App Attack
๐ซ๐ท
dynamix
2026-08-23 09:05:08
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 08:05:35
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic. ...
show more
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic.copelfibra.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 04:05:28.834608 2026] [security2:error] [pid 2718:tid 2718] [client 168.181.49.152:13953] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 168.181.49.152 (+1 hits since last alert)|ashwoodsecurity.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ashwoodsecurity.com"] [uri "/xmlrpc.php"] [unique_id "aoqpyGY-yDhUD_LBfW4L7gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 07:49:03
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 07:05:01
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic. ...
show more
(mod_security) mod_security (id:240335) triggered by 168.181.49.152 (152.49.181.168.rfc6598.dynamic.copelfibra.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 03:04:55.616726 2026] [security2:error] [pid 11946:tid 11946] [client 168.181.49.152:14111] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 168.181.49.152 (+1 hits since last alert)|soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "soundtrax.net"] [uri "/xmlrpc.php"] [unique_id "aoqbl8iq-JnDnl5oStq7qwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-08-23 05:15:07
(1 day ago)
Web App Attack