🇩🇪
ghostwarriors
2026-09-08 23:50:11
(12 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-08 23:22:00
(12 hours ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
🇺🇸
WeekendWeb
2026-09-06 22:24:56
(2 days ago)
Wordpress Vunerability attack
Web App Attack
🇫🇷
dynamix
2026-08-24 22:27:14
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-08-24 01:33:21
(2 weeks ago)
3.676 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-23 23:28:57
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 19:28:50.466343 2026] [security2:error] [pid 30848:tid 30848] [client 186.193.140.9:65476] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.193.140.9 (+1 hits since last alert)|mccompu.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mccompu.com"] [uri "/xmlrpc.php"] [unique_id "aouCMtV0YXjlVj_g9ExMjQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 23:09:06
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 19:09:02.388830 2026] [security2:error] [pid 6588:tid 6588] [client 186.193.140.9:54115] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.193.140.9 (+1 hits since last alert)|dogarttoday.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dogarttoday.com"] [uri "/xmlrpc.php"] [unique_id "aot9jl3FFtJlA_Vej4LQlwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 22:29:36
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 18:29:31.329131 2026] [security2:error] [pid 23857:tid 23857] [client 186.193.140.9:55001] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.193.140.9 (+1 hits since last alert)|waterjetsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "waterjetsolutions.com"] [uri "/xmlrpc.php"] [unique_id "aot0S5AMPmmDqMbzzzGeKgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
rh24
2026-08-23 21:52:29
(2 weeks ago)
(wordpress) Failed wordpress login from 186.193.140.9 (BR/Brazil/140-193-186-9.andradas-net.com.br): ...
show more
(wordpress) Failed wordpress login from 186.193.140.9 (BR/Brazil/140-193-186-9.andradas-net.com.br): (CF_ENABLE)
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-08-20 22:12:08
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 18:12:01.826667 2026] [security2:error] [pid 8935:tid 8958] [client 186.193.140.9:53470] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.193.140.9 (+1 hits since last alert)|hoffmanandassoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hoffmanandassoc.com"] [uri "/xmlrpc.php"] [unique_id "aod7sQHgrOgAmF93A7MQugAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
myintarweb
2026-08-14 23:58:06
(3 weeks ago)
186.193.140.9 - - [13/Aug/2026:00:12:25 +0100] 443 "POST /xmlrpc.php HTTP/1.1" 301 6558 "-" "Jetpack ...
show more
186.193.140.9 - - [13/Aug/2026:00:12:25 +0100] 443 "POST /xmlrpc.php HTTP/1.1" 301 6558 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-13 00:10:39
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 20:10:33.293193 2026] [security2:error] [pid 24486:tid 24486] [client 186.193.140.9:53831] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.193.140.9 (+1 hits since last alert)|jacquelineperriam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jacquelineperriam.com"] [uri "/xmlrpc.php"] [unique_id "an0LeRoWMdsbFRdeCVFkpQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
myintarweb
2026-08-12 23:12:26
(3 weeks ago)
186.193.140.9 - - [13/Aug/2026:00:12:25 +0100] 443 "POST /xmlrpc.php HTTP/1.1" 301 6558 "-" "Jetpack ...
show more
186.193.140.9 - - [13/Aug/2026:00:12:25 +0100] 443 "POST /xmlrpc.php HTTP/1.1" 301 6558 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-09 22:36:37
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 18:36:29.245399 2026] [security2:error] [pid 1192:tid 1192] [client 186.193.140.9:54906] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.193.140.9 (+1 hits since last alert)|major33.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "major33.com"] [uri "/xmlrpc.php"] [unique_id "ankA7WWRMP0JGpUQ8pekBQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 09:53:27
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 186.193.140.9 (140-193-186-9.andradas-net.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 05:53:19.324964 2026] [security2:error] [pid 1625636:tid 1625636] [client 186.193.140.9:53815] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.193.140.9 (+1 hits since last alert)|genevaatlantic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "genevaatlantic.com"] [uri "/xmlrpc.php"] [unique_id "anWrD2BPctnAPjCElms-_AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack