๐บ๐ธ
TPI-Abuse
2026-08-24 07:11:57
(29 minutes ago)
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:11:49.709376 2026] [security2:error] [pid 29671:tid 29671] [client 172.56.205.64:4496] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 172.56.205.64 (+1 hits since last alert)|grexicon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "grexicon.com"] [uri "/xmlrpc.php"] [unique_id "aovutZpi6mCw4S-fbOpJ7AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2026-08-24 05:00:03
(2 hours ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-08-24 04:25:25
(3 hours ago)
[redacted] 172.56.205.64 - - [24/Aug/2026:06:24:38 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "J ...
show more
[redacted] 172.56.205.64 - - [24/Aug/2026:06:24:38 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
[redacted] 172.56.205.64 - - [24/Aug/2026:06:24:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 172.56.205.64 - - [24/Aug/2026:06:24:48 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 172.56.205.64 - - [24/Aug/2026:06:24:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 172.56.205.64 - - [24/Aug/2026:06:24:59 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 172.56.205.64 - - [24/Aug/2026:06:25:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 172.56.205.64 - - [24/Aug/2026:06:25:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 21:20:37
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 17:20:30.644188 2026] [security2:error] [pid 5628:tid 5628] [client 172.56.205.64:28245] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 172.56.205.64 (+1 hits since last alert)|blacksheepoffroad.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "blacksheepoffroad.com"] [uri "/xmlrpc.php"] [unique_id "aotkHgSa3dmaYeHENoDqpwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-23 18:43:02
(12 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ท
dynamix
2026-08-23 17:21:39
(14 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 16:54:50
(14 hours ago)
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 12:54:42.608715 2026] [security2:error] [pid 22512:tid 22512] [client 172.56.205.64:18105] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 172.56.205.64 (+1 hits since last alert)|johncyphers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "johncyphers.com"] [uri "/xmlrpc.php"] [unique_id "aosl0tx0zRasp1-92tgifQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
konseptit
2026-08-23 16:53:03
(14 hours ago)
(wordpress) Failed wordpress login from 172.56.205.64 (US/United States/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-23 16:22:10
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 12:22:05.647394 2026] [security2:error] [pid 13794:tid 13794] [client 172.56.205.64:55370] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 172.56.205.64 (+1 hits since last alert)|asapstarsmogcheck.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "asapstarsmogcheck.com"] [uri "/xmlrpc.php"] [unique_id "aoseLb9-9U13l6d_tLh1rwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-08-23 13:29:33
(18 hours ago)
4.980 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ฉ๐ช
dbmwebdesign
2026-08-23 12:50:14
(18 hours ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 12:17:43
(19 hours ago)
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:17:37.990768 2026] [security2:error] [pid 1571:tid 1597] [client 172.56.205.64:45310] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 172.56.205.64 (+1 hits since last alert)|whatismetamodern.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whatismetamodern.com"] [uri "/xmlrpc.php"] [unique_id "aork4SVXkdMClu8lopD8-gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:46:10
(19 hours ago)
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 172.56.205.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:46:03.426200 2026] [security2:error] [pid 1069:tid 1069] [client 172.56.205.64:41762] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 172.56.205.64 (+1 hits since last alert)|circleinthesquare.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "circleinthesquare.org"] [uri "/xmlrpc.php"] [unique_id "aorde0AXaL9J_jastGo7jwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-08-23 10:32:54
(21 hours ago)
172.56.205.64 - - [23/Aug/2026:12:32:54 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack/13.0; WordPress/ ...
show more
172.56.205.64 - - [23/Aug/2026:12:32:54 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack/13.0; WordPress/6.2; http://site41552361.com"
show less
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-23 07:20:39
(1 day ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack