๐ฆ๐บ
screwlooseit.com.au
2026-07-31 14:02:13
(15 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
TN/Tunisia/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 13:35:23
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 196.178.62.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.178.62.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 09:35:17.692905 2026] [security2:error] [pid 3942160:tid 3942160] [client 196.178.62.21:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.178.62.21 (+1 hits since last alert)|local639.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "local639.com"] [uri "/xmlrpc.php"] [unique_id "amyklfTeMVvJ1-9_0GqEswAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 10:07:44
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 196.178.62.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.178.62.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 06:07:38.484697 2026] [security2:error] [pid 367004:tid 367004] [client 196.178.62.21:50673] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.178.62.21 (+1 hits since last alert)|tigerpathteam.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tigerpathteam.org"] [uri "/xmlrpc.php"] [unique_id "amxz6rrbqdF5MSfcXkdzLgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-07-31 01:46:45
(1 day ago)
{"ClientAddr":"196.178.62.21:53106","ClientHost":"196.178.62.21","ClientPort":"53106","ClientUsernam ...
show more
{"ClientAddr":"196.178.62.21:53106","ClientHost":"196.178.62.21","ClientPort":"53106","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":175596577,"OriginContentSize":418,"OriginDuration":169527870,"OriginStatus":403,"Overhead":6068707,"RequestAddr":"www.cleveradmin.de","RequestContentSize":716,"RequestCount":2455132,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-07-31T03:46:23.269464642+02:00","StartUTC":"2026-07-31T01:46:23.269464642Z","TLSCipher":"TLS_AES_128_GCM_SHA256","TLSVersion":"1.3","entryPointName":"websecure","level":"info","msg":"","time":"2026-07-31T03:46:23+02:00"}
{"ClientAddr":"196.178.62.21:53106","ClientHost":"196.178.62.21","ClientPort":"53
...
show less
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-07-30 23:48:01
(1 day ago)
5.387 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ฎ๐น
CoreTech srl
2026-07-30 22:33:57
(1 day ago)
cloudlinux2 fail2ban: 2026-07-31 00:28:57,167 fail2ban.filter [1584]: INFO [plesk-apache] ...
show more
cloudlinux2 fail2ban: 2026-07-31 00:28:57,167 fail2ban.filter [1584]: INFO [plesk-apache] Found 102.209.109.203 - 2026-07-31 00:28:56cloudlinux2 fail2ban: 2026-07-31 00:29:07,085 fail2ban.filter [1584]: INFO [plesk-apache] Found 102.209.109.203 - 2026-07-31 00:29:07cloudlinux2 fail2ban: 2026-07-31 00:29:20,566 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 196.178.62.21 - 2026-07-31 00:29:20cloudlinux2 fail2ban: 2026-07-31 00:29:17,978 fail2ban.filter [1584]: INFO [plesk-apache] Found 102.209.109.203 - 2026-07-31 00:29:17cloudlinux2 fail2ban: 2026-07-31 00:29:28,785 fail2ban.filter [1584]: INFO [plesk-apache] Found 102.209.109.203 - 2026-07-31 00:29:28cloudlinux2 fail2ban: 2026-07-31 00:29:35,040 fail2ban.filter [1584]: INFO [plesk-modsecurity] Found 77.90.185.129 - 2026-07-31 00:29:35cloudlinux2 fail2ban: 2026-07-31 00:29:39,846 fail2ban.filter [1584]: INFO [plesk-apache] Found 102.209.109.203 - 2026-07-31 00:29:39cloudlinux
show less
Brute-Force
๐ณ๐ฑ
Site.eu
2026-07-30 21:41:09
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
bigwavedave
2026-07-30 19:47:08
(1 day ago)
Wordpress Attack
Web App Attack
Anonymous
2026-07-30 15:31:01
(1 day ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 04:08:42
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 196.178.62.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.178.62.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 00:08:34.704781 2026] [security2:error] [pid 1621228:tid 1621228] [client 196.178.62.21:58534] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.178.62.21 (+1 hits since last alert)|budgetbyron.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "budgetbyron.com"] [uri "/xmlrpc.php"] [unique_id "amrOQg1FoniN7q9nr2NujQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 02:39:00
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 196.178.62.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.178.62.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 22:38:53.459082 2026] [security2:error] [pid 24825:tid 24825] [client 196.178.62.21:52108] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.178.62.21 (+1 hits since last alert)|celebritybikinigossip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "celebritybikinigossip.com"] [uri "/xmlrpc.php"] [unique_id "amq5PWoy02BG9zaSqWUBnwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 01:04:18
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 196.178.62.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.178.62.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 21:04:14.120041 2026] [security2:error] [pid 687851:tid 687851] [client 196.178.62.21:51711] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.178.62.21 (+1 hits since last alert)|thingstodonude.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thingstodonude.com"] [uri "/xmlrpc.php"] [unique_id "amqjDnWBPke8Rk_iXworDwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-07-29 10:49:35
(2 days ago)
(wordpress) Failed wordpress login from 196.178.62.21 (TN/Tunisia/-): (CF_ENABLE)
Brute-Force
๐ช๐ธ
alferez
2026-07-29 09:19:28
(2 days ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
Anonymous
2026-07-29 07:00:00
(2 days ago)
Automated Apache web application probing in selected 24h window; attempts=17, unique_paths=1, error_ ...
show more
Automated Apache web application probing in selected 24h window; attempts=17, unique_paths=1, error_responses=11; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack