Anonymous
2026-06-23 04:33:04
(23 minutes ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฌ๐ง
Apache
2026-06-23 03:50:53
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 216.247.28.235 (PH/Philippines/-): 5 in the las ...
show more
(mod_security) mod_security (id:240335) triggered by 216.247.28.235 (PH/Philippines/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐ซ๐ท
bazter.pro
2026-06-22 15:04:44
(13 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 12:50:36
(16 hours ago)
(wordpress) Failed wordpress login from 216.247.28.235 (PH/Philippines/Province of Negros Occidental ...
show more
(wordpress) Failed wordpress login from 216.247.28.235 (PH/Philippines/Province of Negros Occidental/Bacolod City/-/[redacted])
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-22 12:34:53
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 216.247.28.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 216.247.28.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 08:34:48.474268 2026] [security2:error] [pid 24521:tid 24521] [client 216.247.28.235:32075] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.247.28.235 (+1 hits since last alert)|yaseminelhan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yaseminelhan.com"] [uri "/xmlrpc.php"] [unique_id "ajkr6KxNoM-0oPtjkGoNGgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 10:21:42
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 216.247.28.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 216.247.28.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 06:21:34.450361 2026] [security2:error] [pid 1334:tid 1334] [client 216.247.28.235:11515] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.247.28.235 (+1 hits since last alert)|smoothiessoupssalads.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "smoothiessoupssalads.com"] [uri "/xmlrpc.php"] [unique_id "ajkMrjjw_wgA0J6msPaHnwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Holger
2026-06-22 10:02:50
(18 hours ago)
WordPress WebAttack
Brute-Force
Web App Attack
๐บ๐ธ
cwytech
2026-06-21 12:12:05
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-xmlrpc-bf-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 08:10:13
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 216.247.28.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 216.247.28.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 04:10:04.959141 2026] [security2:error] [pid 13493:tid 13493] [client 216.247.28.235:14947] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.247.28.235 (+1 hits since last alert)|sooperare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sooperare.com"] [uri "/xmlrpc.php"] [unique_id "ajecXEaEZDTR0XlohwuysgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-20 14:07:13
(2 days ago)
Attac
Brute-Force
๐บ๐ธ
WeekendWeb
2026-06-20 12:53:59
(2 days ago)
Wordpress Vunerability attack
Web App Attack
๐ซ๐ท
dynamix
2026-06-20 11:52:26
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 08:08:54
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 216.247.28.235 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 216.247.28.235 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 04:08:50.704830 2026] [security2:error] [pid 943:tid 943] [client 216.247.28.235:11638] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 216.247.28.235 (+1 hits since last alert)|nypatriotcards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nypatriotcards.com"] [uri "/xmlrpc.php"] [unique_id "ajZKkiQaT59uLJGTImaJuAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-02-13 16:52:03
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH