Anonymous
2026-09-09 07:41:46
(11 hours ago)
Malicious activity
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-16 14:08:33
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 10:08:28.636065 2026] [security2:error] [pid 15999:tid 15999] [client 192.0.96.209:4266] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.96.209 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "agh6XOfKJ1l-p7K3IYN3MQAAAAA"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1778940508&nonce=XKzscC0SKC&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=HSwVKdgMebeHAWDPT1K1DJfDkes%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
factor1
2025-12-15 09:16:59
(8 months ago)
Fail2ban at atlas Reports Abuse.
Bad Web Bot
🇪🇸
10dencehispahard SL
2025-07-23 05:52:27
(1 year ago)
WP probing for vulnerabilities
Hacking
Exploited Host
🇺🇸
TPI-Abuse
2025-02-24 13:31:47
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 24 08:31:44.324162 2025] [security2:error] [pid 32451:tid 32451] [client 192.0.96.209:10986] [client 192.0.96.209] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.96.209 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "Z7x0wCmFkkoUkqfRJ8w8FAAAACA"], referer: http://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=%25%5E9U2RN0QzpGl66z%5E4%23X0hiB22%25gU92w%3A1%3A1×tamp=1740403904&nonce=Nb17X9Dnsp&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=C6Tal2Ke8Psq9s7EUSVCJYgUdGw%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-10-10 03:33:49
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 09 23:33:44.784396 2024] [security2:error] [pid 941250:tid 941250] [client 192.0.96.209:58112] [client 192.0.96.209] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.96.209 (+1 hits since last alert)|solarizelouisville.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solarizelouisville.com"] [uri "/xmlrpc.php"] [unique_id "ZwdLGGkW8V3gJKu_njLqygAAABE"], referer: https://solarizelouisville.com/xmlrpc.php?for=jetpack&token=N3%2AGP42Z1%21gz%2ARmJa%40lJr5I1FNi%26vC%21Y%3A1%3A0×tamp=1728531224&nonce=KmtFMbfvGe&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=rKlJ1Q%2BkEFLmo3IJNvESAI0iFfc%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-09-01 18:56:23
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 01 14:56:15.915779 2024] [security2:error] [pid 21914:tid 21914] [client 192.0.96.209:39750] [client 192.0.96.209] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.96.209 (+1 hits since last alert)|www.adoniahenterprises.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.adoniahenterprises.com"] [uri "/xmlrpc.php"] [unique_id "ZtS4zw3RMKKAvQ1xL39MrgAAAAo"], referer: https://www.adoniahenterprises.com/xmlrpc.php?for=jetpack&token=jVAvIuNaG2qd%25MO9St9d%5EyMBX7%25ZnLjy%3A1%3A0×tamp=1725216975&nonce=vHIu50q5lO&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=wD9imfnBAucI3oI%2FhtDvDFC3x0A%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Ba-Yu
2024-08-29 06:09:07
(2 years ago)
WordPress hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2024-04-28 04:31:40
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-04-17 20:32:14
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-04-16 02:32:25
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
🇩🇪
Ba-Yu
2024-04-11 21:17:00
(2 years ago)
WordPress hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2024-02-23 05:03:44
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 23 00:03:39.750735 2024] [security2:error] [pid 27376] [client 192.0.96.209:52546] [client 192.0.96.209] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.96.209 (+1 hits since last alert)|solarizelouisville.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solarizelouisville.com"] [uri "/xmlrpc.php"] [unique_id "ZdgnK7qLtRvGbbFKrsv-fwAAAA4"], referer: https://solarizelouisville.com/xmlrpc.php?for=jetpack&token=N3%2AGP42Z1%21gz%2ARmJa%40lJr5I1FNi%26vC%21Y%3A1%3A0×tamp=1708664619&nonce=JBiiONCQ0s&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=NwZ%2B4w7rs1CX2LlAUO2YH5n5RT8%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2024-02-12 13:58:07
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.96.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 12 08:58:01.828350 2024] [security2:error] [pid 22857] [client 192.0.96.209:62338] [client 192.0.96.209] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.96.209 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "Zcoj6Q9oGtOsZF-EX4RS1gAAAAw"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1707746281&nonce=l9JgknSfsk&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=FkVg6BMufI64A0UO5t4iv6GBxxk%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇰
wnbhosting.dk
2022-11-28 12:00:43
(3 years ago)
WP xmlrpc [2022-11-28T13:00:43+01:00]
Hacking
Web App Attack