๐ฉ๐ช
ghostwarriors
2026-07-26 22:20:41
(13 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-26 22:12:23
(13 hours ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-07-26 18:38:44
(17 hours ago)
(xmlrpc) Failed xmlrpc access from 185.38.195.237 (AL/Albania/-): 5 in the last 3600 secs (0-122)
Hacking
๐ฉ๐ช
FeG Deutschland
2026-07-24 02:04:26
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 28
Exploited Host
Web App Attack
๐น๐ท
ycoskun41
2026-07-05 16:16:15
(3 weeks ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-05 14:13:47
(3 weeks ago)
(wordpress) Failed wordpress login from 185.38.195.237 (AL/Albania/-)
Brute-Force
๐ฆ๐บ
clapper
2026-07-05 11:41:41
(3 weeks ago)
(mod_security) mod_security (id:350202) triggered by 185.38.195.237 (AL/Albania/-): 5 in the last 60 ...
show more
(mod_security) mod_security (id:350202) triggered by 185.38.195.237 (AL/Albania/-): 5 in the last 600 secs; ID: rub
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-04 21:25:07
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 17:25:03.831783 2026] [security2:error] [pid 450:tid 456] [client 185.38.195.237:50750] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.237 (+1 hits since last alert)|northtexaslive.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "northtexaslive.com"] [uri "/xmlrpc.php"] [unique_id "akl6L5V_JDQDWWNr-cMxqgAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 16:38:09
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 12:38:03.202212 2026] [security2:error] [pid 16088:tid 16088] [client 185.38.195.237:64959] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.237 (+1 hits since last alert)|aifactoid.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aifactoid.com"] [uri "/xmlrpc.php"] [unique_id "akk261j4sxh2hdXeMkPxEgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 09:58:58
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 05:58:53.467348 2026] [security2:error] [pid 20505:tid 20505] [client 185.38.195.237:62805] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.237 (+1 hits since last alert)|freemanfoundationcle.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "freemanfoundationcle.org"] [uri "/xmlrpc.php"] [unique_id "akjZXRYNC7FuuzElmBk2NwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-04 05:29:45
(3 weeks ago)
(wordpress) Failed wordpress login from 185.38.195.237 (AL/Albania/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-04 04:30:05
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 00:29:57.846093 2026] [security2:error] [pid 30551:tid 30577] [client 185.38.195.237:5949] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.237 (+1 hits since last alert)|tradersofficepark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tradersofficepark.com"] [uri "/xmlrpc.php"] [unique_id "akiMRZS1GKPcZvkLVIKIMwAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 18:27:09
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 14:27:03.419440 2026] [security2:error] [pid 11037:tid 11037] [client 185.38.195.237:59897] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.237 (+1 hits since last alert)|csm-dtc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "csm-dtc.com"] [uri "/xmlrpc.php"] [unique_id "akf-9zgwzNJWqYgEkYouZQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 17:53:17
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 13:53:13.421792 2026] [security2:error] [pid 22451:tid 22451] [client 185.38.195.237:4987] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.237 (+1 hits since last alert)|egelfitness.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "egelfitness.nl"] [uri "/xmlrpc.php"] [unique_id "akf3CZ_3YU3p3yiL-53LbgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-03 13:46:06
(3 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack