Anonymous
2026-06-28 12:42:18
(3 hours ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-28 11:09:42
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 07:09:37.336109 2026] [security2:error] [pid 8080:tid 8107] [client 197.219.96.233:63247] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.219.96.233 (+1 hits since last alert)|chaoticperception.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "chaoticperception.com"] [uri "/xmlrpc.php"] [unique_id "akEA8WRP9M6KYBd1hLTkxAAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 07:54:06
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 03:53:58.741326 2026] [security2:error] [pid 3272:tid 3272] [client 197.219.96.233:51878] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.219.96.233 (+1 hits since last alert)|495metro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "495metro.com"] [uri "/xmlrpc.php"] [unique_id "akDTFgpGUCZSOmqaz0nnagAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 04:19:28
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 00:19:21.464613 2026] [security2:error] [pid 7503:tid 7503] [client 197.219.96.233:62202] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.219.96.233 (+1 hits since last alert)|oshadega.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "oshadega.com"] [uri "/xmlrpc.php"] [unique_id "akCgyR8UxFWCMJi6TPz4agAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 02:07:45
(14 hours ago)
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 22:07:38.985647 2026] [security2:error] [pid 29477:tid 29477] [client 197.219.96.233:51049] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.219.96.233 (+1 hits since last alert)|clipper1970.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "clipper1970.com"] [uri "/xmlrpc.php"] [unique_id "akCB6jhK4eCH2FjldyMINQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-06-28 00:47:18
(15 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 00:32:20
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 20:32:14.894384 2026] [security2:error] [pid 16027:tid 16027] [client 197.219.96.233:53845] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.219.96.233 (+1 hits since last alert)|celebritybikinigossip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "celebritybikinigossip.com"] [uri "/xmlrpc.php"] [unique_id "akBrju-5lsGnKH5dJUsyFwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
QT
2026-06-27 23:17:47
(17 hours ago)
Unauthorised WordPress admin login attempted at 2026-06-28 09:17:46 +1000
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 19:45:11
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 15:45:05.693019 2026] [security2:error] [pid 1634:tid 1634] [client 197.219.96.233:55815] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.219.96.233 (+1 hits since last alert)|hawarcenter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hawarcenter.com"] [uri "/xmlrpc.php"] [unique_id "akAoQf7DNgXege0C-NZ9-QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-06-27 15:51:01
(1 day ago)
197.219.96.233 - [27/Jun/2026:18:50:50 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "WordPress.com ...
show more
197.219.96.233 - [27/Jun/2026:18:50:50 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "WordPress.com; https://wordpress.com" "-"
197.219.96.233 - [27/Jun/2026:18:51:00 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-06-27 15:35:42
(1 day ago)
197.219.96.233 - [27/Jun/2026:18:35:32 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "WordPress.com ...
show more
197.219.96.233 - [27/Jun/2026:18:35:32 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "WordPress.com; https://wordpress.com" "-"
197.219.96.233 - [27/Jun/2026:18:35:42 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "Jetpack/12.1; WordPress/6.4; http://site85683756.com" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 09:32:19
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 05:32:11.403663 2026] [security2:error] [pid 24408:tid 24420] [client 197.219.96.233:50833] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.219.96.233 (+1 hits since last alert)|managementlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "managementlaw.com"] [uri "/xmlrpc.php"] [unique_id "aj-Ym0ODEF7eEX9CFgRqggAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-27 06:56:36
(1 day ago)
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-27 03:23:56
(1 day ago)
5.259 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-26 17:57:13
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 197.219.96.233 (dynamic-adsl.movitel.co.mz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 13:57:05.216268 2026] [security2:error] [pid 14451:tid 14466] [client 197.219.96.233:52613] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.219.96.233 (+1 hits since last alert)|rawhabitat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rawhabitat.com"] [uri "/xmlrpc.php"] [unique_id "aj69cfpqzcePCfyROZ2dtAAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack