๐ฉ๐ช
IloGus
2026-07-22 19:30:41
(6 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ซ๐ท
dynamix
2026-07-22 18:47:37
(7 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-07-22 16:27:27
(9 hours ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 14:24:01
(11 hours ago)
(mod_security) mod_security (id:240335) triggered by 183.82.124.210 (183.82.124.210.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 183.82.124.210 (183.82.124.210.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 10:23:54.063690 2026] [security2:error] [pid 967047:tid 967047] [client 183.82.124.210:13377] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 183.82.124.210 (+1 hits since last alert)|writebetweenthelines.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "writebetweenthelines.com"] [uri "/xmlrpc.php"] [unique_id "amDSeqy8IGOVee88k4rQDAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 10:37:58
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 183.82.124.210 (183.82.124.210.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 183.82.124.210 (183.82.124.210.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 06:37:54.482167 2026] [security2:error] [pid 1204909:tid 1204928] [client 183.82.124.210:1226] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 183.82.124.210 (+1 hits since last alert)|michaelrandon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "michaelrandon.com"] [uri "/xmlrpc.php"] [unique_id "amCdgj-Cb5WzvgiitLMnRQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 09:45:14
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 183.82.124.210 (183.82.124.210.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 183.82.124.210 (183.82.124.210.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 05:45:06.878113 2026] [security2:error] [pid 615392:tid 615392] [client 183.82.124.210:17127] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 183.82.124.210 (+1 hits since last alert)|studioyau.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "studioyau.com"] [uri "/xmlrpc.php"] [unique_id "amCRIqDLl-YU7hksNmPy3wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-22 07:17:54
(18 hours ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-22 07:17:22
(18 hours ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 05:38:34
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 183.82.124.210 (183.82.124.210.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 183.82.124.210 (183.82.124.210.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 01:38:25.408102 2026] [security2:error] [pid 28550:tid 28550] [client 183.82.124.210:12212] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 183.82.124.210 (+1 hits since last alert)|rohanbyles.com.au|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rohanbyles.com.au"] [uri "/xmlrpc.php"] [unique_id "amBXUQJcsn1CE25ZsAkZNwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-22 02:50:13
(22 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 02:22:34
(23 hours ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 01:43:29
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 183.82.124.210 (183.82.124.210.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 183.82.124.210 (183.82.124.210.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 21:43:23.656995 2026] [security2:error] [pid 175822:tid 175822] [client 183.82.124.210:15687] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 183.82.124.210 (+1 hits since last alert)|rodandreelpiercam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rodandreelpiercam.com"] [uri "/xmlrpc.php"] [unique_id "amAgOyDbws6LmqkbRaCBkQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 18:24:14
(1 month ago)
Attac
Brute-Force
๐จ๐ญ
Mario Bretscher
2026-06-02 15:56:14
(1 month ago)
Jun 2 17:52:09 tubegrabe-stafel.ch Cerber(tubegrabe-stafel.ch)[2329733]: Authentication failure for ...
show more
Jun 2 17:52:09 tubegrabe-stafel.ch Cerber(tubegrabe-stafel.ch)[2329733]: Authentication failure for admin from 183.82.124.210
Jun 2 17:56:13 tubegrabe-stafel.ch Cerber(tubegrabe-stafel.ch)[2328175]: Authentication failure for admin from 183.82.124.210
...
show less
Web Spam
๐ฉ๐ช
dbmwebdesign
2026-06-02 06:50:25
(1 month ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack