๐ฎ๐น
Progetto1
2026-08-26 16:10:04
(9 hours ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
dynamix
2026-08-25 15:03:29
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ง๐ช
madeit
2026-08-25 14:22:29
(1 day ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 19:13:52
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 205.217.255.218 (205-217-255-218.candw.ag): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 205.217.255.218 (205-217-255-218.candw.ag): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 15:13:44.988100 2026] [security2:error] [pid 3840:tid 3840] [client 205.217.255.218:13693] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 205.217.255.218 (+1 hits since last alert)|fuentevictoria.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fuentevictoria.com"] [uri "/xmlrpc.php"] [unique_id "aoyX6FXywKttv31d3aKYOgAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 15:01:23
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 205.217.255.218 (205-217-255-218.candw.ag): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 205.217.255.218 (205-217-255-218.candw.ag): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 11:01:18.402092 2026] [security2:error] [pid 22767:tid 22767] [client 205.217.255.218:62660] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 205.217.255.218 (+1 hits since last alert)|d365geek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "d365geek.com"] [uri "/xmlrpc.php"] [unique_id "aoxcvnWheSoIhs-S3JhTDAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-24 13:58:20
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-08-23 00:59:00
(4 days ago)
(wordpress) Failed wordpress login from 205.217.255.218 (DM/Dominica/205-217-255-218.candw.ag)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-22 23:00:50
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 205.217.255.218 (205-217-255-218.candw.ag): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 205.217.255.218 (205-217-255-218.candw.ag): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 19:00:45.422992 2026] [security2:error] [pid 13106:tid 13121] [client 205.217.255.218:56954] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 205.217.255.218 (+1 hits since last alert)|executiveconsultingpr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "executiveconsultingpr.com"] [uri "/xmlrpc.php"] [unique_id "aooqHc6ay8bRoAaEdv4Z9AAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 22:25:06
(4 days ago)
[redacted] 205.217.255.218 - - [23/Aug/2026:00:24:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" ...
show more
[redacted] 205.217.255.218 - - [23/Aug/2026:00:24:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
[redacted] 205.217.255.218 - - [23/Aug/2026:00:24:33 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/13.0; WordPress/6.1; http://site24313228.com"
[redacted] 205.217.255.218 - - [23/Aug/2026:00:24:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
[redacted] 205.217.255.218 - - [23/Aug/2026:00:24:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 205.217.255.218 - - [23/Aug/2026:00:25:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-08-22 21:54:12
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
pscriptos
2026-08-22 17:35:21
(4 days ago)
{"ClientAddr":"205.217.255.218:13420","ClientHost":"205.217.255.218","ClientPort":"13420","ClientUse ...
show more
{"ClientAddr":"205.217.255.218:13420","ClientHost":"205.217.255.218","ClientPort":"13420","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":510628028,"OriginContentSize":418,"OriginDuration":506208010,"OriginStatus":403,"Overhead":4420018,"RequestAddr":"www.cleveradmin.de","RequestContentSize":714,"RequestCount":4632204,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-08-22T19:35:00.035205792+02:00","StartUTC":"2026-08-22T17:35:00.035205792Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-08-22T19:35:00+02:00"}
{"ClientAddr":"205.217.255.218:13420","ClientHost":"205.217.25
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
Kenshin869
2026-08-19 22:39:28
(1 week ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-19 13:34:29
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 205.217.255.218 (205-217-255-218.candw.ag): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 205.217.255.218 (205-217-255-218.candw.ag): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 09:34:25.520570 2026] [security2:error] [pid 28407:tid 28407] [client 205.217.255.218:57062] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 205.217.255.218 (+1 hits since last alert)|freemanfoundationcle.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "freemanfoundationcle.org"] [uri "/xmlrpc.php"] [unique_id "aoWw4bOf2kbNEejXUNBJLwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 22:56:16
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 205.217.255.218 (205-217-255-218.candw.ag): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 205.217.255.218 (205-217-255-218.candw.ag): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 18:56:09.333798 2026] [security2:error] [pid 25232:tid 25232] [client 205.217.255.218:13977] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 205.217.255.218 (+1 hits since last alert)|michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "michelehoop.com"] [uri "/xmlrpc.php"] [unique_id "aoTjCcDMmQxcd_CzC8bpKgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-18 15:50:37
(1 week ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack