๐บ๐ธ
TPI-Abuse
2025-05-08 12:45:06
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 08 08:45:01.304792 2025] [security2:error] [pid 389740:tid 389740] [client 192.0.100.89:7120] [client 192.0.100.89] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.100.89 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "aBynTSQp3pNipF8rYHU6nwAAAAc"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1746708301&nonce=1rFXah76gI&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=Au7bWYoulMcCrHqeyrECHL4GEY8%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-20 12:41:23
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 20 07:41:17.851081 2024] [security2:error] [pid 19441:tid 19441] [client 192.0.100.89:25694] [client 192.0.100.89] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.100.89 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "Z2Vl7T9xw2bJmKJAyffHUwAAAAI"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1734698477&nonce=ELSFsxBI9D&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=BLjDCf%2BPfYe6uW3Xm5z5NKCZJs0%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-16 19:05:41
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 16 15:05:34.130513 2024] [security2:error] [pid 25353] [client 192.0.100.89:61126] [client 192.0.100.89] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.100.89 (+1 hits since last alert)|www.adoniahenterprises.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.adoniahenterprises.com"] [uri "/xmlrpc.php"] [unique_id "Zm83fkHqrx-lqI2tSVP7tgAAAAM"], referer: https://www.adoniahenterprises.com/xmlrpc.php?for=jetpack&token=jVAvIuNaG2qd%25MO9St9d%5EyMBX7%25ZnLjy%3A1%3A0×tamp=1718564734&nonce=gQ7lgzaMeH&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=Nx1Q%2BKZtIPD8KaVsIiL2EGlWHi4%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-03 13:19:28
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 03 09:19:22.352822 2024] [security2:error] [pid 25361] [client 192.0.100.89:3356] [client 192.0.100.89] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.100.89 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "Zl3C2vh9s9bYKEmi_Hv0JQAAAAM"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1717420762&nonce=AylCRw8m9A&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=Jb37f1nC7TapamWKvgZrWcXSGIU%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-05-17 08:00:05
(2 years ago)
Unauthorized login attempts [ wordpress-xmlrpc]
Brute-Force
Web App Attack
Anonymous
2024-05-08 03:43:58
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-04-29 05:16:52
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-04-26 11:46:07
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-04-19 07:17:47
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-04-01 00:48:50
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2024-03-15 04:26:27
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 15 00:26:22.461874 2024] [security2:error] [pid 22243] [client 192.0.100.89:24568] [client 192.0.100.89] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.100.89 (+1 hits since last alert)|solarizelouisville.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solarizelouisville.com"] [uri "/xmlrpc.php"] [unique_id "ZfPN7ggKKh8PwBqSrRd6PgAAAAU"], referer: https://solarizelouisville.com/xmlrpc.php?for=jetpack&token=N3%2AGP42Z1%21gz%2ARmJa%40lJr5I1FNi%26vC%21Y%3A1%3A0×tamp=1710476782&nonce=pJlmdFXeBx&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=0UmBAGGtT1%2BT8IWMPuJUNeNF4F8%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-03-13 01:02:57
(2 years ago)
Unauthorized login attempts [ wordpress-xmlrpc]
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-01-13 12:42:25
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.100.89 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 13 07:42:16.828658 2024] [security2:error] [pid 9792] [client 192.0.100.89:37430] [client 192.0.100.89] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.100.89 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "ZaKFKFXt8BIhGYA0HT-ybgAAABM"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1705149736&nonce=PA7p76GZZf&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=h6wJwMlgKznGI%2BwO6h6yLlPZMHo%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
wnbhosting.dk
2023-08-26 13:02:40
(3 years ago)
WP xmlrpc [2023-08-26T15:02:40+02:00]
Hacking
Web App Attack
๐ช๐ธ
10dencehispahard SL
2023-05-04 23:28:59
(3 years ago)
Unauthorized login attempts [{'wp-content-404', 'wordpress-xmlrpc'}]
Brute-Force
Web App Attack