🇫🇷
Kenshin869
2026-07-24 16:21:41
(18 hours ago)
Wordpress unauthorized access attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-07-24 12:49:41
(21 hours ago)
(mod_security) mod_security (id:240335) triggered by 179.53.0.218 (218.0.53.179.d.dyn.claro.net.do): ...
show more
(mod_security) mod_security (id:240335) triggered by 179.53.0.218 (218.0.53.179.d.dyn.claro.net.do): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:49:35.163150 2026] [security2:error] [pid 1292848:tid 1292848] [client 179.53.0.218:55099] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 179.53.0.218 (+1 hits since last alert)|fishleadership.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fishleadership.org"] [uri "/xmlrpc.php"] [unique_id "amNfXx6VV8ZNo3K0TMlNWwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-07-24 12:45:52
(21 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-07-24 12:19:24
(22 hours ago)
(mod_security) mod_security (id:240335) triggered by 179.53.0.218 (218.0.53.179.d.dyn.claro.net.do): ...
show more
(mod_security) mod_security (id:240335) triggered by 179.53.0.218 (218.0.53.179.d.dyn.claro.net.do): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:19:18.586069 2026] [security2:error] [pid 166581:tid 166581] [client 179.53.0.218:64844] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 179.53.0.218 (+1 hits since last alert)|mosheimlib.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mosheimlib.org"] [uri "/xmlrpc.php"] [unique_id "amNYRnlPjpMi5-7GzfOuYgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
integrantservices.com
2026-07-24 10:12:49
(1 day ago)
(wordpress) Failed wordpress login from 179.53.0.218 (DO/Dominican Republic/218.0.53.179.d.dyn.claro ...
show more
(wordpress) Failed wordpress login from 179.53.0.218 (DO/Dominican Republic/218.0.53.179.d.dyn.claro.net.do)
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-07-24 08:43:33
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 179.53.0.218 (218.0.53.179.d.dyn.claro.net.do): ...
show more
(mod_security) mod_security (id:240335) triggered by 179.53.0.218 (218.0.53.179.d.dyn.claro.net.do): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:43:28.300431 2026] [security2:error] [pid 2057864:tid 2057864] [client 179.53.0.218:52265] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 179.53.0.218 (+1 hits since last alert)|maprada92.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "maprada92.com"] [uri "/xmlrpc.php"] [unique_id "amMlsKtyz2HcLTAKTXW7WAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-07-24 08:00:06
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇺🇸
n2nguyenn2nguyen
2026-07-24 05:56:03
(1 day ago)
Blocked by YFC Security on https://brixzly.com — type: xmlrpc_attempts
Brute-Force
Web App Attack
🇪🇸
alferez
2026-07-24 03:03:22
(1 day ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
🇫🇷
dynamix
2026-07-24 03:01:00
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
🇱🇻
garmtech.com
2026-07-24 01:35:59
(1 day ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
🇱🇻
garmtech.com
2026-07-23 23:58:40
(1 day ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
🇺🇸
TPI-Abuse
2026-07-23 22:17:05
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 179.53.0.218 (218.0.53.179.d.dyn.claro.net.do): ...
show more
(mod_security) mod_security (id:240335) triggered by 179.53.0.218 (218.0.53.179.d.dyn.claro.net.do): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 18:16:58.675738 2026] [security2:error] [pid 3337612:tid 3337612] [client 179.53.0.218:51145] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 179.53.0.218 (+1 hits since last alert)|stlouisdave.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "stlouisdave.com"] [uri "/xmlrpc.php"] [unique_id "amKS2t95DrJNuqicjHceVQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-23 18:29:32
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 179.53.0.218 (218.0.53.179.d.dyn.claro.net.do): ...
show more
(mod_security) mod_security (id:240335) triggered by 179.53.0.218 (218.0.53.179.d.dyn.claro.net.do): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 14:29:24.159452 2026] [security2:error] [pid 14236:tid 14236] [client 179.53.0.218:58781] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 179.53.0.218 (+1 hits since last alert)|3beeze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "3beeze.com"] [uri "/xmlrpc.php"] [unique_id "amJdhEGMJNBdBT9UTEdz5gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
konseptit
2026-07-23 12:40:42
(1 day ago)
(wordpress) Failed wordpress login from 179.53.0.218 (DO/Dominican Republic/218.0.53.179.d.dyn.claro ...
show more
(wordpress) Failed wordpress login from 179.53.0.218 (DO/Dominican Republic/218.0.53.179.d.dyn.claro.net.do)
show less
Brute-Force