๐บ๐ธ
TPI-Abuse
2026-08-24 10:29:24
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 217.165.27.108 (bba-217-165-27-108.alshamil.net ...
show more
(mod_security) mod_security (id:240335) triggered by 217.165.27.108 (bba-217-165-27-108.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 06:29:17.628675 2026] [security2:error] [pid 27521:tid 27521] [client 217.165.27.108:64276] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 217.165.27.108 (+1 hits since last alert)|ideaofauniversity.website|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ideaofauniversity.website"] [uri "/xmlrpc.php"] [unique_id "aowc_eie1N9tySlPijCwiQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 08:57:44
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 217.165.27.108 (bba-217-165-27-108.alshamil.net ...
show more
(mod_security) mod_security (id:240335) triggered by 217.165.27.108 (bba-217-165-27-108.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 04:57:35.579928 2026] [security2:error] [pid 6412:tid 6412] [client 217.165.27.108:40282] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 217.165.27.108 (+1 hits since last alert)|lightupaustralia.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lightupaustralia.org"] [uri "/xmlrpc.php"] [unique_id "aowHf7eKeV9XlxTjxivFQwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-24 08:44:38
(1 week ago)
Web App Attack
๐ฉ๐ช
PHAM
2026-08-24 06:20:33
(1 week ago)
Shield Guard: Scanner: wordpress (+70) | Chemin suspect: /xmlrpc.php | xmlrpc.php bloquรฉ
Web App Attack
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-24 03:20:19
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 217.165.27.108 (bba-217-165-27-108.alshamil.net ...
show more
(mod_security) mod_security (id:225170) triggered by 217.165.27.108 (bba-217-165-27-108.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 23:20:10.930283 2026] [security2:error] [pid 15367:tid 15367] [client 217.165.27.108:18996] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||artigelisim.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "artigelisim.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aou4aoe5SwhVYajF8XGmmwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2026-08-24 03:20:02
(1 week ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ง๐ช
cmbplf
2026-08-24 02:29:04
(1 week ago)
3.794 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
IndigoRidge
2026-08-24 01:17:11
(1 week ago)
217.165.27.108 - - [23/Aug/2026:21:15:13 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5180 "-" "WordPress. ...
show more
217.165.27.108 - - [23/Aug/2026:21:15:13 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5180 "-" "WordPress.com; https://wordpress.com"
217.165.27.108 - - [23/Aug/2026:21:15:23 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5180 "-" "WordPress.com; https://wordpress.com"
217.165.27.108 - - [23/Aug/2026:21:15:34 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5196 "-" "WordPress.com; https://wordpress.com"
217.165.27.108 - - [23/Aug/2026:21:16:58 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5164 "-" "WordPress.com; https://wordpress.com"
217.165.27.108 - - [23/Aug/2026:21:17:09 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5196 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 00:12:30
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 217.165.27.108 (bba-217-165-27-108.alshamil.net ...
show more
(mod_security) mod_security (id:240335) triggered by 217.165.27.108 (bba-217-165-27-108.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 20:12:26.512449 2026] [security2:error] [pid 25633:tid 25654] [client 217.165.27.108:33951] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 217.165.27.108 (+1 hits since last alert)|sweeneyzone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sweeneyzone.com"] [uri "/xmlrpc.php"] [unique_id "aouMaiDWIRS11wg9rcf61gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-23 13:56:10
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-23 12:21:17
(1 week ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 09:43:08
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 217.165.27.108 (bba-217-165-27-108.alshamil.net ...
show more
(mod_security) mod_security (id:240335) triggered by 217.165.27.108 (bba-217-165-27-108.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 05:43:02.119711 2026] [security2:error] [pid 31339:tid 31339] [client 217.165.27.108:51882] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 217.165.27.108 (+1 hits since last alert)|lowkeytiki.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lowkeytiki.com"] [uri "/xmlrpc.php"] [unique_id "aorApooXYxeW-K7ZkKufcAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
konseptit
2026-08-23 08:28:22
(1 week ago)
(wordpress) Failed wordpress login from 217.165.27.108 (AE/United Arab Emirates/bba-217-165-27-108.a ...
show more
(wordpress) Failed wordpress login from 217.165.27.108 (AE/United Arab Emirates/bba-217-165-27-108.alshamil.net.ae)
show less
Brute-Force
Anonymous
2026-08-21 18:20:58
(1 week ago)
(wordpress) Failed wordpress login from 217.165.27.108 (AE/United Arab Emirates/bba-217-165-27-108.a ...
show more
(wordpress) Failed wordpress login from 217.165.27.108 (AE/United Arab Emirates/bba-217-165-27-108.alshamil.net.ae)
show less
Brute-Force
๐ฎ๐น
CoreTech srl
2026-08-21 15:58:57
(1 week ago)
cloudlinux2 fail2ban: 2026-08-21 17:53:56,007 fail2ban.filter [1480]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-21 17:53:56,007 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 185.251.19.71 - 2026-08-21 17:53:55cloudlinux2 fail2ban: 2026-08-21 17:54:13,570 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 34.23.120.252 - 2026-08-21 17:54:13cloudlinux2 fail2ban: 2026-08-21 17:54:15,181 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 39.47.14.155 - 2026-08-21 17:54:15cloudlinux2 fail2ban: 2026-08-21 17:54:38,293 fail2ban.actions [1480]: NOTICE [plesk-modsecurity] Unban 122.183.38.197cloudlinux2 fail2ban: 2026-08-21 17:55:39,194 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 39.47.14.155 - 2026-08-21 17:55:39cloudlinux2 fail2ban: 2026-08-21 17:55:55,237 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 217.165.27.108 - 2026-08-21 17:55:55cloudlinux2 fail2ban: 2026-08-21 17:56:10,206 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 185.251.19.61 - 2026-08-21 17:56:09cloudlinux2 fail2ban:
show less
Web App Attack