๐ฉ๐ช
rh24
2026-07-22 13:37:45
(1 day ago)
(xmlrpc_405) XMLRPC-Bot 405 196.216.58.24 (AO/Angola/c62271.cust.ao.afrisp.net)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-22 11:20:33
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 196.216.58.24 (c62271.cust.ao.afrisp.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 196.216.58.24 (c62271.cust.ao.afrisp.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 07:20:26.567120 2026] [security2:error] [pid 1085375:tid 1085375] [client 196.216.58.24:56315] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||riccardiagency.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "riccardiagency.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amCner6QLZAbBSsn2PNlFAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-22 09:34:17
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฒ๐น
Malta
2026-07-21 14:37:55
(2 days ago)
196.216.58.24 - - [21/Jul/2026:16:37:55 +0200] "POST /xmlrpc.php HTTP/1.1" "WordPress.com; https://w ...
show more
196.216.58.24 - - [21/Jul/2026:16:37:55 +0200] "POST /xmlrpc.php HTTP/1.1" "WordPress.com; https://wordpress.com"
show less
Hacking
Web App Attack
๐ฉ๐ช
4server
2026-07-21 13:35:53
(2 days ago)
[TueJul2115:35:51.2953182026][security2:error][pid2578751:tid2578759][client196.216.58.24:0]ModSecur ...
show more
[TueJul2115:35:51.2953182026][security2:error][pid2578751:tid2578759][client196.216.58.24:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"newbeauty-pully.ch\"][uri\"/xmlrpc.php\"][unique_id\"al91t9Mt7cgUfOOQuF9r4AAAAAU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-20 13:48:37
(3 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-07-20 10:36:19
(3 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
directorioeducativo.com
2026-07-19 20:28:07
(4 days ago)
POST URL: "/xmlrpc.php"Agent: "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Ge ...
show more
POST URL: "/xmlrpc.php"Agent: "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/10.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-19 12:39:02
(4 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 196.216.58.24 (AO/Angola/c62271.cus ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 196.216.58.24 (AO/Angola/c62271.cust.ao.afrisp.net): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 09:19:21
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 196.216.58.24 (c62271.cust.ao.afrisp.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 196.216.58.24 (c62271.cust.ao.afrisp.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 05:19:16.490267 2026] [security2:error] [pid 17158:tid 17158] [client 196.216.58.24:62811] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mkdesignndetailing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mkdesignndetailing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alnzlMwj1PuSvfhfbWYPcgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 06:59:20
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 196.216.58.24 (c62271.cust.ao.afrisp.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 196.216.58.24 (c62271.cust.ao.afrisp.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 02:59:15.403749 2026] [security2:error] [pid 27046:tid 27046] [client 196.216.58.24:58183] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.216.58.24 (+1 hits since last alert)|swcbsa.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "swcbsa.org"] [uri "/xmlrpc.php"] [unique_id "alnSw9GFrTIGMS0jbne41AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-07-16 15:36:01
(1 week ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐ซ๐ฎ
YF
2026-07-16 14:30:52
(1 week ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-16 05:37:11
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 196.216.58.24 (c62271.cust.ao.afrisp.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 196.216.58.24 (c62271.cust.ao.afrisp.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 01:37:02.494039 2026] [security2:error] [pid 381:tid 381] [client 196.216.58.24:62363] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.216.58.24 (+1 hits since last alert)|accommodation-perthairport.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "accommodation-perthairport.com"] [uri "/xmlrpc.php"] [unique_id "alht_l8o7NPc9dBoaSMC0QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 16:39:58
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 196.216.58.24 (c62271.cust.ao.afrisp.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 196.216.58.24 (c62271.cust.ao.afrisp.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 12:39:54.125590 2026] [security2:error] [pid 24242:tid 24242] [client 196.216.58.24:51619] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.216.58.24 (+1 hits since last alert)|bervick.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bervick.com"] [uri "/xmlrpc.php"] [unique_id "alJx2oNIMqGLHVpVJDXfIAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack