๐บ๐ธ
TPI-Abuse
2026-07-03 00:28:13
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink ...
show more
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 20:28:07.058986 2026] [security2:error] [pid 18223:tid 18223] [client 216.234.213.100:8835] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.234.213.100 (+1 hits since last alert)|casadelsolmexico.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "casadelsolmexico.net"] [uri "/xmlrpc.php"] [unique_id "akcCFyZ9fOEH0K_is_6f-wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 23:58:47
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink ...
show more
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 19:58:43.777805 2026] [security2:error] [pid 13841:tid 13841] [client 216.234.213.100:56694] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.234.213.100 (+1 hits since last alert)|fundaciondamashcc.org.ec|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fundaciondamashcc.org.ec"] [uri "/xmlrpc.php"] [unique_id "akb7M1M7A3K3Ynmidi2oiQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 23:27:18
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink ...
show more
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 19:27:13.906602 2026] [security2:error] [pid 9262:tid 9262] [client 216.234.213.100:52384] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.234.213.100 (+1 hits since last alert)|guarinofurnituredesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "guarinofurnituredesigns.com"] [uri "/xmlrpc.php"] [unique_id "akbz0XfQeEY-OmuaHMvkOAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-02 23:24:01
(4 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/customer.jhngzaf1.isp.starlink.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 11:53:18
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink ...
show more
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 07:53:15.502787 2026] [security2:error] [pid 3841:tid 3841] [client 216.234.213.100:39230] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.234.213.100 (+1 hits since last alert)|edgecomix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "edgecomix.com"] [uri "/xmlrpc.php"] [unique_id "akZRK9O4PVAKcNX4Esx7RAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 07:26:47
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink ...
show more
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 03:26:42.549018 2026] [security2:error] [pid 12230:tid 12230] [client 216.234.213.100:36877] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.234.213.100 (+1 hits since last alert)|meganmurph.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "meganmurph.com"] [uri "/xmlrpc.php"] [unique_id "akYSsrSwIRqySTWcHoNSYgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-02 03:00:04
(4 weeks ago)
[news.tmg.gr] legacy-local-block: samples=imported from ipset host_guard4 at 2026-07-02T03:00:04+00: ...
show more
[news.tmg.gr] legacy-local-block: samples=imported from ipset host_guard4 at 2026-07-02T03:00:04+00:00
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 02:20:06
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink ...
show more
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 22:20:03.079773 2026] [security2:error] [pid 23123:tid 23131] [client 216.234.213.100:31948] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.234.213.100 (+1 hits since last alert)|hearthandhomestudio.art|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hearthandhomestudio.art"] [uri "/xmlrpc.php"] [unique_id "akXK09U6yCaxuCXjr-X6NwAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 00:19:22
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink ...
show more
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 20:19:17.467456 2026] [security2:error] [pid 25118:tid 25118] [client 216.234.213.100:13324] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.234.213.100 (+1 hits since last alert)|morninginc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "morninginc.com"] [uri "/xmlrpc.php"] [unique_id "akWuhZ8DBKnKLDCjcWAz-wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-07-02 00:17:32
(4 weeks ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-xmlrpc-bf-high.
Bad Web Bot
Web App Attack
Anonymous
2026-07-01 21:43:13
(4 weeks ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-01 19:02:44
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink ...
show more
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 15:02:38.722975 2026] [security2:error] [pid 4908:tid 4908] [client 216.234.213.100:48276] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.234.213.100 (+1 hits since last alert)|glassclublake.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "glassclublake.com"] [uri "/xmlrpc.php"] [unique_id "akVkTj98Fb0z0qmTkTrR8gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-07-01 18:37:21
(4 weeks ago)
(wordpress) Failed wordpress login from 216.234.213.100 (ZM/Zambia/customer.jhngzaf1.isp.starlink.co ...
show more
(wordpress) Failed wordpress login from 216.234.213.100 (ZM/Zambia/customer.jhngzaf1.isp.starlink.com): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-01 18:07:58
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink ...
show more
(mod_security) mod_security (id:240335) triggered by 216.234.213.100 (customer.jhngzaf1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 14:07:54.100988 2026] [security2:error] [pid 564:tid 564] [client 216.234.213.100:10400] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.234.213.100 (+1 hits since last alert)|bigheartskitchen.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bigheartskitchen.net"] [uri "/xmlrpc.php"] [unique_id "akVXesVHl7RLNy1TQmqg4wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-01 12:59:36
(4 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack