๐ง๐ช
cmbplf
2026-08-23 00:06:09
(19 hours ago)
5.150 requests from abuseipdb.com blacklisted IP (4mos2w6d)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-22 22:44:38
(21 hours ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 18:44:33.705831 2026] [security2:error] [pid 27873:tid 27873] [client 185.38.195.238:54420] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.238 (+1 hits since last alert)|pondplain.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pondplain.org"] [uri "/xmlrpc.php"] [unique_id "aoomURTIArHeNDaH3OiSZQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 21:36:02
(22 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-22 21:01:41
(22 hours ago)
(wordpress) Failed wordpress login from 185.38.195.238 (AL/Albania/Tirana/Tirana/-)
Brute-Force
Anonymous
2026-08-22 17:34:15
(1 day ago)
[redacted] 185.38.195.238 - - [22/Aug/2026:19:33:32 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 185.38.195.238 - - [22/Aug/2026:19:33:32 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
[redacted] 185.38.195.238 - - [22/Aug/2026:19:33:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 185.38.195.238 - - [22/Aug/2026:19:33:53 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
[redacted] 185.38.195.238 - - [22/Aug/2026:19:34:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 185.38.195.238 - - [22/Aug/2026:19:34:15 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-22 17:20:17
(1 day ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 17:05:53
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:05:46.535930 2026] [security2:error] [pid 23248:tid 23248] [client 185.38.195.238:4729] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.238 (+1 hits since last alert)|kmelson.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kmelson.com"] [uri "/xmlrpc.php"] [unique_id "aonW6saU4nPgfl7a_yyIIQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-22 16:02:53
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-22 15:33:16
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 11:33:11.969550 2026] [security2:error] [pid 18889:tid 18889] [client 185.38.195.238:58304] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.238 (+1 hits since last alert)|rotentendales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rotentendales.com"] [uri "/xmlrpc.php"] [unique_id "aonBN6gurVA3ViVop9rVIgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 12:58:34
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:58:27.081551 2026] [security2:error] [pid 5985:tid 5985] [client 185.38.195.238:52919] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.238 (+1 hits since last alert)|josephshv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "josephshv.com"] [uri "/xmlrpc.php"] [unique_id "aomc8_5A4gFHvxXcS39_HAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 10:56:38
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:56:30.862007 2026] [security2:error] [pid 8020:tid 8020] [client 185.38.195.238:49391] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.238 (+1 hits since last alert)|susanoneill.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "susanoneill.us"] [uri "/xmlrpc.php"] [unique_id "aomAXoIsBvXoYh_88XbZNgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-22 10:55:09
(1 day ago)
(xmlrpc) Apache: Failed xmlrpc access from 185.38.195.238 (AL/Albania/-): 10 in the last 3600 secs ( ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 185.38.195.238 (AL/Albania/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-22 09:26:03
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 185.38.195.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 05:25:56.933450 2026] [security2:error] [pid 30096:tid 30096] [client 185.38.195.238:22937] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.38.195.238 (+1 hits since last alert)|usaenquirer.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "usaenquirer.com"] [uri "/xmlrpc.php"] [unique_id "aolrJBuXXSr3sTN2y7LEOgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-22 08:41:09
(1 day ago)
Web App Attack
๐บ๐ธ
cwytech
2026-08-22 08:21:42
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-xmlrpc-bf-high.
Bad Web Bot
Web App Attack