๐บ๐ธ
TPI-Abuse
2026-07-22 07:25:40
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 185.213.193.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.213.193.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 03:25:35.967131 2026] [security2:error] [pid 1029149:tid 1029149] [client 185.213.193.39:53158] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.213.193.39 (+1 hits since last alert)|oakvillenaturopathicclinic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "oakvillenaturopathicclinic.com"] [uri "/xmlrpc.php"] [unique_id "amBwbwiuXvdh80e50i6cHgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 05:25:58
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 185.213.193.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.213.193.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 01:25:55.502234 2026] [security2:error] [pid 323487:tid 323487] [client 185.213.193.39:56511] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.213.193.39 (+1 hits since last alert)|sutherlandyogastudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sutherlandyogastudio.com"] [uri "/xmlrpc.php"] [unique_id "amBUY3f_OmIKG5WxYmzMpgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-22 00:58:49
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 17:38:52
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 185.213.193.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.213.193.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 13:38:46.628901 2026] [security2:error] [pid 21808:tid 21808] [client 185.213.193.39:52525] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.213.193.39 (+1 hits since last alert)|fgrotary.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fgrotary.org"] [uri "/xmlrpc.php"] [unique_id "al-upl9EucG4-CPM8-Xm9QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 00:40:07
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 185.213.193.39 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.213.193.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 20:39:59.162795 2026] [security2:error] [pid 21857:tid 21857] [client 185.213.193.39:55110] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.213.193.39 (+1 hits since last alert)|technesa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "technesa.com"] [uri "/xmlrpc.php"] [unique_id "al6_3yJT0EVn4GXi658C_AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
bigwavedave
2026-07-20 20:53:47
(4 days ago)
Wordpress Attack
Web App Attack
๐ฉ๐ช
Tha_14
2026-07-20 18:49:26
(4 days ago)
Limit on login attempts is reached
Brute-Force
๐ณ๐ฑ
ipoac.nl
2026-07-20 15:43:47
(4 days ago)
2026-07-20T17:43:46.376922+02:00 ipoac.nl wordpress(-)-: XML-RPC authentication failure for-from 185 ...
show more
2026-07-20T17:43:46.376922+02:00 ipoac.nl wordpress(-)-: XML-RPC authentication failure for-from 185.213.193.39
show less
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-20 15:20:30
(4 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 15:13:21
(4 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
NetGuard
2026-06-18 14:55:58
(1 month ago)
#honeypot #netguard247 #ciscoasa
Captured by NetGuard 24/7 T-Pot honeypot (netguard24-7.com).
Timest ...
show more
#honeypot #netguard247 #ciscoasa
Captured by NetGuard 24/7 T-Pot honeypot (netguard24-7.com).
Timestamp: 2026-06-18T14:55:58.245+00:00
Attacker IP: 185.213.193.39 | Port: N/A | Country: United States
Honeypot: ciscoasa | Attack: unknown
Source: NetGuard 24/7 (netguard24-7.com) | PhantomGrid Defense
show less
Web App Attack
๐ฎ๐ฉ
David Koswari
2026-06-17 05:58:00
(1 month ago)
REQ_BLOCKED_ACL
DDoS Attack
FTP Brute-Force
Ping of Death
Port Scan
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
IoT Targeted
๐ฉ๐ช
Reinhard
2026-06-16 17:39:23
(1 month ago)
Unknown activity, but too many attacks with too many users.
Hacking
๐ธ๐ฌ
mypatricks
2026-06-15 00:30:24
(1 month ago)
185.213.193.39 | Port: 10325 | DNS: 185.213.193.39 2026-06-15T08:30:23+08:00 America/New_York | IPs ...
show more
185.213.193.39 | Port: 10325 | DNS: 185.213.193.39 2026-06-15T08:30:23+08:00 America/New_York | IPs res erved list | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0.1 Safari/605.1.15 HTTP/1.1 443 GET | URL: / | Ref: - | Country: US/United States/-08:00 IP City: Washington a0bd77419e4a8793-IAD/Ashburn, VA, United States 1 hits/0 secs Browser 0
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐ต๐ฑ
sefinek.net
2026-06-14 22:02:05
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: / | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot