๐บ๐ธ
WeekendWeb
2026-07-03 05:49:09
(5 hours ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 04:50:20
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 27.34.73.152 (152.73.34.27.dynamic.wlink.com.np ...
show more
(mod_security) mod_security (id:240335) triggered by 27.34.73.152 (152.73.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 00:50:13.215879 2026] [security2:error] [pid 21021:tid 21021] [client 27.34.73.152:54026] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.34.73.152 (+1 hits since last alert)|coolcustomproducts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "coolcustomproducts.com"] [uri "/xmlrpc.php"] [unique_id "akc_hd7g8qsblLazTX4YuQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2026-07-03 03:54:24
(6 hours ago)
27.34.73.152 - - [02/Jul/2026:17:33:06 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4758 "-" "Jetpack/12.1 ...
show more
27.34.73.152 - - [02/Jul/2026:17:33:06 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4758 "-" "Jetpack/12.1; WordPress/6.2; http://site70628810.com"
27.34.73.152 - - [02/Jul/2026:17:35:24 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4756 "-" "Jetpack by WordPress.com"
27.34.73.152 - - [02/Jul/2026:17:37:42 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4758 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
27.34.73.152 - - [02/Jul/2026:17:40:02 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4758 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
27.34.73.152 - - [02/Jul/2026:17:42:20 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4756 "-" "Jetpack/12.0; WordPress/6.3; http://site46004931.com"
...
show less
Web App Attack
Anonymous
2026-07-02 23:01:10
(11 hours ago)
Attac
Brute-Force
๐ซ๐ท
dynamix
2026-07-02 22:59:49
(11 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 20:58:34
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 27.34.73.152 (152.73.34.27.dynamic.wlink.com.np ...
show more
(mod_security) mod_security (id:240335) triggered by 27.34.73.152 (152.73.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 16:58:27.142357 2026] [security2:error] [pid 26707:tid 26707] [client 27.34.73.152:51643] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.34.73.152 (+1 hits since last alert)|theamarals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theamarals.com"] [uri "/xmlrpc.php"] [unique_id "akbQ8_zXn7d-lw8aIj8-dgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 19:56:11
(14 hours ago)
(mod_security) mod_security (id:240335) triggered by 27.34.73.152 (152.73.34.27.dynamic.wlink.com.np ...
show more
(mod_security) mod_security (id:240335) triggered by 27.34.73.152 (152.73.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 15:56:05.641067 2026] [security2:error] [pid 11979:tid 11979] [client 27.34.73.152:17626] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.34.73.152 (+1 hits since last alert)|capriexpress.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "capriexpress.com"] [uri "/xmlrpc.php"] [unique_id "akbCVWmEKTLTr3ZZYjN04QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 18:55:05
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 27.34.73.152 (152.73.34.27.dynamic.wlink.com.np ...
show more
(mod_security) mod_security (id:240335) triggered by 27.34.73.152 (152.73.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 14:54:57.982221 2026] [security2:error] [pid 17256:tid 17274] [client 27.34.73.152:54725] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.34.73.152 (+1 hits since last alert)|rubenluis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rubenluis.com"] [uri "/xmlrpc.php"] [unique_id "aka0Ac_lmmRV5OJ89JPWhQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-07-02 18:21:53
(16 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-06-29 12:36:07
(3 days ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2026-03-20 13:21:09
(3 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
tropicalidad.be
2026-03-03 16:26:41
(3 months ago)
blog comment/referrer spam
Web Spam
๐จ๐ญ
Elysium Security
2026-01-18 22:36:06
(5 months ago)
Mass port scanning on a whole network
Port Scan
Anonymous
2025-11-26 05:14:50
(7 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2025-11-22 16:58:12
(7 months ago)
scanning http requests from known botnet
Web App Attack