๐บ๐ธ
TPI-Abuse
2026-07-22 03:46:53
(11 hours ago)
(mod_security) mod_security (id:240335) triggered by 173.239.224.213 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 173.239.224.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 23:46:47.555299 2026] [security2:error] [pid 3826744:tid 3826744] [client 173.239.224.213:27519] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 173.239.224.213 (+1 hits since last alert)|brianwhitty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "brianwhitty.com"] [uri "/xmlrpc.php"] [unique_id "amA9J_EOT3o5nNDW2A8cfwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 03:18:53
(11 hours ago)
(mod_security) mod_security (id:240335) triggered by 173.239.224.213 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 173.239.224.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 23:18:47.671559 2026] [security2:error] [pid 765287:tid 765287] [client 173.239.224.213:39881] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 173.239.224.213 (+1 hits since last alert)|briannalls.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "briannalls.com"] [uri "/xmlrpc.php"] [unique_id "amA2l3ULlAre7O-35qWmxgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-07-21 19:27:44
(19 hours ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (5001900-122)
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-21 19:23:59
(19 hours ago)
cloudlinux2 fail2ban: 2026-07-21 21:19:57,160 fail2ban.filter [1927]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-21 21:19:57,160 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 173.239.224.213 - 2026-07-21 21:19:56cloudlinux2 fail2ban: 2026-07-21 21:20:17,764 fail2ban.filter [1927]: WARNING [plesk-apache-badbot] Detected a log entry 1m 6s before the current time in operation mode. This looks like a latency problem. Treating such entries as if they just happened.cloudlinux2 fail2ban: 2026-07-21 21:20:17,765 fail2ban.filter [1927]: WARNING [plesk-wordpress] Detected a log entry 1m 6s before the current time in operation mode. This looks like a latency problem. Treating such entries as if they just happened.cloudlinux2 fail2ban: 2026-07-21 21:20:17,765 fail2ban.filter [1927]: WARNING [plesk-wordpress] Please check a jail for a timing issue. Line with odd timestamp: 78.46.201.135 - - [21/Jul/2026:21:19:11 +0200] "POST /wp-load.php?ca0ae6=33063 HTTP/1.1" 200 1276551 "https://cl-informatica.it/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
LRob
2026-07-21 11:27:55
(1 day ago)
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Mozilla/5.0 (Linux; Android 11; Nokia G50) Appl ...
show more
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Mozilla/5.0 (Linux; Android 11; Nokia G50) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.61 Mobile Safari/537.36
show less
Brute-Force
Web App Attack
๐ง๐ฌ
HighWay
2026-07-21 04:02:23
(1 day ago)
173.239.224.213 - - [21/Jul/2026:04:02:18 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4665 "-" "Mozilla/5 ...
show more
173.239.224.213 - - [21/Jul/2026:04:02:18 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4665 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 OPR/114.0.0.0"
173.239.224.213 - - [21/Jul/2026:04:02:19 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4664 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 OPR/114.0.0.0"
173.239.224.213 - - [21/Jul/2026:04:02:21 +0000] "POST /xmlrpc.php HTTP/1.1" 200 736 "-" "Mozilla/5.0 (Linux; Android 11; Nokia G50) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.61 Mobile Safari/537.36"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 00:50:15
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 173.239.224.213 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 173.239.224.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 20:50:08.452292 2026] [security2:error] [pid 2144726:tid 2144726] [client 173.239.224.213:20773] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 173.239.224.213 (+1 hits since last alert)|climasyequipos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "climasyequipos.com"] [uri "/xmlrpc.php"] [unique_id "al7CQLzWofyoVjP7o8ryDAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-07-20 20:08:26
(1 day ago)
2026/07/21 01:37:34 [error] 502823#502823: *74965 access forbidden by rule, client: 173.239.224.213, ...
show more
2026/07/21 01:37:34 [error] 502823#502823: *74965 access forbidden by rule, client: 173.239.224.213, server: [redacted], request: "POST /xmlrpc.php HTTP/1.1", host: "[redacted]"
2026/07/21 01:38:14 [error] 502823#502823: *74972 access forbidden by rule, client: 173.239.224.213, server: [redacted], request: "POST /xmlrpc.php HTTP/1.1", host: "[redacted]"
2026/07/21 01:38:25 [error] 502823#502823: *74980 access forbidden by rule, client: 173.239.224.213, server: [redacted], request: "POST /xmlrpc.php HTTP/1.1", host: "[redacted]"
show less
Port Scan
Web App Attack
๐จ๐ญ
backslash
2026-07-18 16:42:00
(3 days ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ซ๐ท
masterguru
2026-07-16 17:28:54
(5 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
Anonymous
2026-07-15 01:30:00
(1 week ago)
Multiple Violations by Bot
Port Scan
Web App Attack