๐บ๐ธ
TPI-Abuse
2026-06-10 09:25:50
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 196.171.28.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.171.28.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 05:25:45.231719 2026] [security2:error] [pid 19360:tid 19376] [client 196.171.28.84:59193] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.171.28.84 (+1 hits since last alert)|dasperformance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dasperformance.com"] [uri "/xmlrpc.php"] [unique_id "aiktmdJP_vYNo0cKsitfpAAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
applemooz
2026-06-10 06:33:20
(6 days ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 15:28:30
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 196.171.28.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.171.28.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:28:26.359841 2026] [security2:error] [pid 2971:tid 2971] [client 196.171.28.84:62556] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.171.28.84 (+1 hits since last alert)|stat-alliance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "stat-alliance.com"] [uri "/xmlrpc.php"] [unique_id "aigxGvjab7XcAgIwM7GM7wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-06-09 13:12:48
(1 week ago)
(wordpress) Failed wordpress login from 196.171.28.84 (TG/Togo/Maritime/Lomรฉ/-)
Brute-Force
Anonymous
2026-06-09 11:08:41
(1 week ago)
196.171.28.84 - - [09/Jun/2026:19:08:40 +0800] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by W ...
show more
196.171.28.84 - - [09/Jun/2026:19:08:40 +0800] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 09:57:28
(1 week ago)
[redacted] 196.171.28.84 - - [09/Jun/2026:11:56:45 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 196.171.28.84 - - [09/Jun/2026:11:56:45 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.4; http://site99991388.com"
[redacted] 196.171.28.84 - - [09/Jun/2026:11:56:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.1; http://site12786006.com"
[redacted] 196.171.28.84 - - [09/Jun/2026:11:57:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.4; http://site19304365.com"
[redacted] 196.171.28.84 - - [09/Jun/2026:11:57:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 196.171.28.84 - - [09/Jun/2026:11:57:27 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.1; http://site55425692.com"
...
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-06-09 07:23:20
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 13:47:06
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 196.171.28.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.171.28.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 09:47:00.281951 2026] [security2:error] [pid 4986:tid 4986] [client 196.171.28.84:64885] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.171.28.84 (+1 hits since last alert)|georgesmarina.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "georgesmarina.com"] [uri "/xmlrpc.php"] [unique_id "ah7e1OjrA-CWPNYqRaun7wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 11:10:47
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 196.171.28.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.171.28.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 07:10:43.703199 2026] [security2:error] [pid 1776:tid 1776] [client 196.171.28.84:55978] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.171.28.84 (+1 hits since last alert)|dvdmasters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dvdmasters.com"] [uri "/xmlrpc.php"] [unique_id "ah1os2PhQX6Te6BeliFN5AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-15 09:35:37
(2 months ago)
196.171.28.84 - - [15/Apr/2026:17:35:35 +0800] "POST /xmlrpc.php HTTP/1.1" 404 300900 "-" "Mozilla/5 ...
show more
196.171.28.84 - - [15/Apr/2026:17:35:35 +0800] "POST /xmlrpc.php HTTP/1.1" 404 300900 "-" "Mozilla/5.0 (Windows NT 6.2; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/91.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-04-14 05:00:08
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-04-13 08:42:28
(2 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-04-07 07:38:50
(2 months ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 14:54:02
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 196.171.28.84 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 196.171.28.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 10:53:54.186717 2026] [security2:error] [pid 22550:tid 22550] [client 196.171.28.84:59680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||atidysort.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "atidysort.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ac_Ugq-fOMt6zf4U4dY3XgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Kenshin869
2026-04-03 11:07:40
(2 months ago)
Wordpress unauthorized access attempt
Brute-Force