πΊπΈ
TPI-Abuse
2026-06-05 03:25:53
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 185.213.193.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 185.213.193.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 23:25:45.848032 2026] [security2:error] [pid 32034:tid 32034] [client 185.213.193.157:54530] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.213.193.157 (+1 hits since last alert)|morninginc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "morninginc.com"] [uri "/xmlrpc.php"] [unique_id "aiJBuaV2wCgJzCH1lkmu0AAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
CELOS-SOC
2026-06-05 00:31:26
(3 weeks ago)
Multiple Unauthorized SSLVPN Login Attempts
Hacking
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-04 22:59:48
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 185.213.193.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 185.213.193.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 18:59:44.777758 2026] [security2:error] [pid 8932:tid 8932] [client 185.213.193.157:63891] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.213.193.157 (+1 hits since last alert)|bikinitweets.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bikinitweets.com"] [uri "/xmlrpc.php"] [unique_id "aiIDYHn-t6kyhU_VVOEPJAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 14:42:57
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 185.213.193.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 185.213.193.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 10:42:52.227086 2026] [security2:error] [pid 24329:tid 24329] [client 185.213.193.157:55695] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.213.193.157 (+1 hits since last alert)|kavahawaii.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kavahawaii.com"] [uri "/xmlrpc.php"] [unique_id "aiGO7CLm4YeJnkDlOQrYIwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
WellSpring
2026-06-04 13:55:38
(3 weeks ago)
xmlrpc exploit on 614.today/xmlrpc.php β WellSpr.ing/NetSentinel civic-AI security layer
Brute-Force
Web App Attack
Anonymous
2026-06-04 12:20:44
(3 weeks ago)
Attac
Brute-Force
Anonymous
2026-06-03 11:52:17
(3 weeks ago)
[redacted] 185.213.193.157 - - [03/Jun/2026:13:51:32 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 185.213.193.157 - - [03/Jun/2026:13:51:32 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 185.213.193.157 - - [03/Jun/2026:13:51:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 185.213.193.157 - - [03/Jun/2026:13:51:56 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 185.213.193.157 - - [03/Jun/2026:13:52:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.3; http://site67130137.com"
[redacted] 185.213.193.157 - - [03/Jun/2026:13:52:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
π«π·
bazter.pro
2026-06-02 18:48:25
(3 weeks ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-06-02 18:46:14
(3 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
DE/Germany/-
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 15:13:13
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 185.213.193.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 185.213.193.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 11:13:06.484058 2026] [security2:error] [pid 3792:tid 3792] [client 185.213.193.157:60872] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.213.193.157 (+1 hits since last alert)|rnance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rnance.com"] [uri "/xmlrpc.php"] [unique_id "ah7zAlrTQbjssYgbmkCYjgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 15:12:25
(3 weeks ago)
Attac
Brute-Force
π©πͺ
CELOS-SOC
2026-05-31 16:31:44
(4 weeks ago)
Multiple Unauthorized SSLVPN Login Attempts
Hacking
Brute-Force
π©πͺ
CELOS-SOC
2026-05-25 04:31:06
(1 month ago)
Multiple Unauthorized SSLVPN Login Attempts
Hacking
Brute-Force
πΊπΈ
TPI-Abuse
2026-05-23 10:45:00
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 185.213.193.157 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 185.213.193.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 06:44:54.852379 2026] [security2:error] [pid 15407:tid 15407] [client 185.213.193.157:52482] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.213.193.157 (+1 hits since last alert)|kiinlog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kiinlog.com"] [uri "/xmlrpc.php"] [unique_id "ahGFJo5__iAS2Ae7tqcYEgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
integrantservices.com
2026-05-23 04:39:00
(1 month ago)
(wordpress) Failed wordpress login from 185.213.193.157 (US/United States/-)
Brute-Force