๐ซ๐ฎ
YF
2026-06-04 00:00:58
(8 hours ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-03 23:09:42
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 19:09:34.465994 2026] [security2:error] [pid 20146:tid 20146] [client 181.24.25.92:55449] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 181.24.25.92 (+1 hits since last alert)|warpedweed.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "warpedweed.com"] [uri "/xmlrpc.php"] [unique_id "aiC0LpKEwiS8sBNtSooe9gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Yepngo
2026-06-03 18:59:46
(13 hours ago)
181.24.25.92 - - [03/Jun/2026:20:59:35 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "Jetpack by Wo ...
show more
181.24.25.92 - - [03/Jun/2026:20:59:35 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
181.24.25.92 - - [03/Jun/2026:20:59:45 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-03 18:30:05
(13 hours ago)
Web App Attack
๐ฒ๐น
Malta
2026-06-03 04:12:40
(1 day ago)
181.24.25.92 - - [03/Jun/2026:06:12:39 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack by WordPress.com ...
show more
181.24.25.92 - - [03/Jun/2026:06:12:39 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
show less
Hacking
Web App Attack
Anonymous
2026-06-03 03:12:46
(1 day ago)
Attac
Brute-Force
๐บ๐ธ
cwytech
2026-06-03 02:40:49
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 00:47:48
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 20:47:44.499644 2026] [security2:error] [pid 3116:tid 3116] [client 181.24.25.92:62507] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 181.24.25.92 (+1 hits since last alert)|walterceron.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "walterceron.com"] [uri "/xmlrpc.php"] [unique_id "ah95sKYQlVd5Cr8jzrrlVgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 14:32:26
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 10:32:21.444904 2026] [security2:error] [pid 32625:tid 32671] [client 181.24.25.92:62327] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 181.24.25.92 (+1 hits since last alert)|tkfay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tkfay.com"] [uri "/xmlrpc.php"] [unique_id "ah7pdToDmTgk5-8DA4nX5gAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 09:14:22
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 05:14:16.558543 2026] [security2:error] [pid 16719:tid 16719] [client 181.24.25.92:63204] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 181.24.25.92 (+1 hits since last alert)|38floorsupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "38floorsupply.com"] [uri "/xmlrpc.php"] [unique_id "ah6e6Occn06cshiQk2k40wAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 07:40:36
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 03:40:31.370585 2026] [security2:error] [pid 8846:tid 8846] [client 181.24.25.92:65048] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 181.24.25.92 (+1 hits since last alert)|isslv.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "isslv.net"] [uri "/xmlrpc.php"] [unique_id "ah6I78pnhOVVUG0scRJYVwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-02 07:08:47
(2 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 181.24.25.92 (AR/Argentina/181-24-25-92.mrse.com.ar): 10 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 181.24.25.92 (AR/Argentina/181-24-25-92.mrse.com.ar): 10 in the last 3600 secs (0-201)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-02 00:00:13
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 20:00:07.212178 2026] [security2:error] [pid 27293:tid 27293] [client 181.24.25.92:50263] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 181.24.25.92 (+1 hits since last alert)|abilityengraving.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abilityengraving.com"] [uri "/xmlrpc.php"] [unique_id "ah4dB34dbw-Y4tvFdPIQKQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 23:19:15
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 181.24.25.92 (181-24-25-92.mrse.com.ar): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 19:19:09.850519 2026] [security2:error] [pid 21137:tid 21153] [client 181.24.25.92:64193] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 181.24.25.92 (+1 hits since last alert)|dontbeajerklikeyourwork.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dontbeajerklikeyourwork.com"] [uri "/xmlrpc.php"] [unique_id "ah4TbeUvEeG52QFyGVLEMwAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-06-01 15:35:42
(2 days ago)
Wordpress Vunerability attack
Web App Attack