๐บ๐ธ
TPI-Abuse
2026-06-20 10:21:46
(56 minutes ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 06:21:40.634477 2026] [security2:error] [pid 24417:tid 24417] [client 31.208.97.153:30175] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.153 (+1 hits since last alert)|insidepublications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "insidepublications.com"] [uri "/xmlrpc.php"] [unique_id "ajZptK4vgdZaPnmskEdN3QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-20 08:05:41
(3 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-20 07:37:27
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 03:37:21.325772 2026] [security2:error] [pid 27743:tid 27743] [client 31.208.97.153:58604] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.153 (+1 hits since last alert)|iconconstructors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iconconstructors.com"] [uri "/xmlrpc.php"] [unique_id "ajZDMRFT889Kw2H7RRQRHQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-20 03:18:00
(8 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 22:33:04
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 18:32:56.769079 2026] [security2:error] [pid 28024:tid 28024] [client 31.208.97.153:38933] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.153 (+1 hits since last alert)|starcrestsales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "starcrestsales.com"] [uri "/xmlrpc.php"] [unique_id "ajXDmCxla_S25IxtLHUHZgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 18:52:59
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 14:52:54.081046 2026] [security2:error] [pid 18938:tid 18938] [client 31.208.97.153:28262] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.153 (+1 hits since last alert)|oshadega.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "oshadega.com"] [uri "/xmlrpc.php"] [unique_id "ajWQBrGG4p6BFnJZmCPZOAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 16:49:26
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 12:49:23.297517 2026] [security2:error] [pid 25212:tid 25212] [client 31.208.97.153:27856] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.153 (+1 hits since last alert)|incrp.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "incrp.org"] [uri "/xmlrpc.php"] [unique_id "ajVzE5e8lgT3LRLYkhzMiQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-06-19 15:32:00
(19 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 13:14:16
(22 hours ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 09:14:10.681602 2026] [security2:error] [pid 8442:tid 8442] [client 31.208.97.153:55590] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.153 (+1 hits since last alert)|hotelkona.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hotelkona.com"] [uri "/xmlrpc.php"] [unique_id "ajVAonMh2C2_-ljhMxzBQgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-19 02:07:12
(1 day ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-19 00:29:18
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (31-208-97-153.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 20:29:12.928991 2026] [security2:error] [pid 26080:tid 26080] [client 31.208.97.153:37076] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.153 (+1 hits since last alert)|ardath.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ardath.net"] [uri "/xmlrpc.php"] [unique_id "ajSNWFab_h6256jH6ICDzwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-06-19 00:29:00
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (SE/Sweden/31-208-97-153.cust.bre ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.153 (SE/Sweden/31-208-97-153.cust.bredband2.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-18 19:17:41
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-18 18:00:10
(1 day ago)
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-18 16:45:12
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH