๐ซ๐ท
SpaceHost-Server
2026-07-17 22:30:20
(2 days ago)
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-17 04:50:20
(3 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-17 04:41:43
(3 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-16 23:53:55
(3 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
BR/Brazil/186-225-225-102-dynamic.unetvale.com.br
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 21:54:21
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetva ...
show more
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetvale.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 17:54:17.409020 2026] [security2:error] [pid 7615:tid 7697] [client 186.225.225.102:62714] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.225.225.102 (+1 hits since last alert)|sparkhypnotherapy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sparkhypnotherapy.com"] [uri "/xmlrpc.php"] [unique_id "allTCd15dZJOWSNZDvnLAAAAAhQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-16 14:59:04
(4 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 13:50:11
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetva ...
show more
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetvale.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 09:50:06.217908 2026] [security2:error] [pid 22311:tid 22311] [client 186.225.225.102:62969] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.225.225.102 (+1 hits since last alert)|soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "soundtrax.net"] [uri "/xmlrpc.php"] [unique_id "aljhjrkwqIx7dL6cgRLGEwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 09:44:04
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetva ...
show more
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetvale.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 05:43:57.752485 2026] [security2:error] [pid 31355:tid 31355] [client 186.225.225.102:62848] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.225.225.102 (+1 hits since last alert)|jmichaelpope.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jmichaelpope.com"] [uri "/xmlrpc.php"] [unique_id "alin3d20uKK4klkBwBfwzwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 11:06:47
(1 month ago)
(mod_security) mod_security (id:217210) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetva ...
show more
(mod_security) mod_security (id:217210) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetvale.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 07:06:40.776847 2026] [security2:error] [pid 15445:tid 15445] [client 186.225.225.102:27662] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||moon7sources.top|F|4"] [data "GET http://moon7sources.top HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "moon7sources.top"] [uri "/"] [unique_id "ajUiwHGh4EIU_Wp_OmXh0QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 04:14:20
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetva ...
show more
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetvale.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 00:14:15.426038 2026] [security2:error] [pid 28996:tid 28996] [client 186.225.225.102:64639] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.225.225.102 (+1 hits since last alert)|altoshp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "altoshp.com"] [uri "/xmlrpc.php"] [unique_id "ajTCFweHyd7rIDOixwpjngAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-19 03:43:09
(1 month ago)
Attac
Brute-Force
๐บ๐ธ
WeekendWeb
2026-06-18 21:51:49
(1 month ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 21:22:11
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetva ...
show more
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetvale.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 17:22:05.627225 2026] [security2:error] [pid 4337:tid 4337] [client 186.225.225.102:62223] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.225.225.102 (+1 hits since last alert)|modalguitarist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "modalguitarist.com"] [uri "/xmlrpc.php"] [unique_id "ajRhff3rJM1B21Xb8RRQIgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-18 19:38:23
(1 month ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=enerescpm.com; logs=/var/log/httpd/domains/enerescpm.com.log ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=enerescpm.com; logs=/var/log/httpd/domains/enerescpm.com.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 16:24:46
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetva ...
show more
(mod_security) mod_security (id:240335) triggered by 186.225.225.102 (186-225-225-102-dynamic.unetvale.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 12:24:40.933398 2026] [security2:error] [pid 23490:tid 23490] [client 186.225.225.102:62306] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.225.225.102 (+1 hits since last alert)|avvmarchetticollini.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "avvmarchetticollini.it"] [uri "/xmlrpc.php"] [unique_id "ajQbyEAmTrml1OZSXBTL9AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack