๐บ๐ธ
TPI-Abuse
2026-06-12 12:27:53
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 08:27:49.512427 2026] [security2:error] [pid 3347:tid 3347] [client 192.0.101.208:45142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.101.208 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "aiv7RUJSmrW7YgaHnDBf6AAAAAM"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1781267269&nonce=1kN4lRjPZP&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=StGl28qASrL5uEjVNiD0tfTtCwY%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-01 13:28:02
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 01 09:27:56.235830 2026] [security2:error] [pid 24100:tid 24100] [client 192.0.101.208:59774] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.101.208 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "ac0dXOaLF_bm14OG-UZt7AAAAAM"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1775050076&nonce=IjclOtLGNZ&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=hX4tXcAl96gIj3QrC3vsNTbakog%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-28 12:18:54
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 28 08:18:49.628089 2025] [security2:error] [pid 15347:tid 15347] [client 192.0.101.208:27738] [client 192.0.101.208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.101.208 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "Z-aTqQOLeWIax1Q2F3xI2gAAAAU"], referer: http://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1743164329&nonce=7HoXZrX36d&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=tR5WNywVmmHwOUABfwpw38IREh4%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-14 12:50:07
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 14 07:50:04.441939 2024] [security2:error] [pid 20367:tid 20367] [client 192.0.101.208:19748] [client 192.0.101.208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.101.208 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "Z11-_KyZz0EUOwNorIjkIQAAAA4"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1734180604&nonce=cy2xo221C8&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=BrgChKVYU4UhEwZkHS2EueKpS%2Fw%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-22 02:04:41
(2 years ago)
Unauthorized login attempts [ wordpress-xmlrpc]
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-31 19:40:33
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 31 15:40:28.614571 2024] [security2:error] [pid 1835] [client 192.0.101.208:46352] [client 192.0.101.208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.101.208 (+1 hits since last alert)|www.adoniahenterprises.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.adoniahenterprises.com"] [uri "/xmlrpc.php"] [unique_id "ZlonrDoOPFPxtu0sWa0a7AAAAAI"], referer: https://www.adoniahenterprises.com/xmlrpc.php?for=jetpack&token=jVAvIuNaG2qd%25MO9St9d%5EyMBX7%25ZnLjy%3A1%3A0×tamp=1717184428&nonce=Mz5RsM9xwJ&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=QRUopZF96kbAE8S7TKVIRc91wiQ%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-05-11 01:45:24
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-04-30 07:11:29
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-04-26 11:45:31
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ช๐ธ
10dencehispahard SL
2024-04-17 15:00:03
(2 years ago)
Unauthorized login attempts [ wordpress-xmlrpc]
Brute-Force
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-02-26 16:00:04
(2 years ago)
Unauthorized login attempts [ wordpress-xmlrpc]
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-04 12:42:31
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.101.208 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 04 07:42:23.539124 2024] [security2:error] [pid 13593] [client 192.0.101.208:52248] [client 192.0.101.208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.101.208 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "Zb-GL_cec8skmy-Pl6nQoAAAABU"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1707050543&nonce=wDLQqXFj7q&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=NdE1jleItu4noGXEE9hu7xA%2FXD4%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
wnbhosting.dk
2022-09-12 13:11:53
(4 years ago)
WP xmlrpc [2022-09-12T15:11:53+02:00]
Hacking
Web App Attack
๐ฉ๐ช
OiledAmoeba
2022-07-10 17:46:54
(4 years ago)
192.0.101.208 - - [10/Jul/2022:23:46:53 +0200] "www.ruhnke.cloud" "POST /xmlrpc.php?for=jetpack&toke ...
show more
192.0.101.208 - - [10/Jul/2022:23:46:53 +0200] "www.ruhnke.cloud" "POST /xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657489612&nonce=k7OSxXfjLo&body-hash=zM6wtlIR3F15tOMR6hYdh1YDU3A%3D&signature=j8%2FS%2BptEP%2BfiQ3mwY8CRdCttr38%3D HTTP/1.1" 500 0 "https://www.ruhnke.cloud/xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657489612&nonce=k7OSxXfjLo&body-hash=zM6wtlIR3F15tOMR6hYdh1YDU3A%3D&signature=j8%2FS%2BptEP%2BfiQ3mwY8CRdCttr38%3D" "Jetpack by WordPress.com" "-" 0.453 "-"
...
show less
Brute-Force
๐ฉ๐ช
OiledAmoeba
2022-07-10 15:44:30
(4 years ago)
192.0.101.208 - - [10/Jul/2022:21:44:29 +0200] "www.ruhnke.cloud" "POST /xmlrpc.php?for=jetpack&toke ...
show more
192.0.101.208 - - [10/Jul/2022:21:44:29 +0200] "www.ruhnke.cloud" "POST /xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657482268&nonce=ArmDdOrZEH&body-hash=zM6wtlIR3F15tOMR6hYdh1YDU3A%3D&signature=bpAosR7wMNdOZWexkmNctgeM2Hg%3D HTTP/1.1" 500 0 "https://www.ruhnke.cloud/xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657482268&nonce=ArmDdOrZEH&body-hash=zM6wtlIR3F15tOMR6hYdh1YDU3A%3D&signature=bpAosR7wMNdOZWexkmNctgeM2Hg%3D" "Jetpack by WordPress.com" "-" 0.587 "-"
...
show less
Brute-Force