๐บ๐ธ
lostswordfish.com
2026-07-24 11:42:03
(1 hour ago)
Wordfence waf block on fairregistry
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-07-24 11:02:18
(2 hours ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 06:38:38
(6 hours ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:38:32.709472 2026] [security2:error] [pid 4099049:tid 4099049] [client 31.208.97.26:9443] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.26 (+1 hits since last alert)|palumbodesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "palumbodesigns.com"] [uri "/xmlrpc.php"] [unique_id "amMIaKKdjUdYXX_kEegA2gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 05:04:22
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:04:18.882914 2026] [security2:error] [pid 3368633:tid 3368633] [client 31.208.97.26:33760] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.26 (+1 hits since last alert)|geriterry.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "geriterry.com"] [uri "/xmlrpc.php"] [unique_id "amLyUuWblf3Hb0pMffkekwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
HighWay
2026-07-24 03:00:24
(10 hours ago)
31.208.97.26 - - [24/Jul/2026:03:00:01 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4664 "-" "WordPress.co ...
show more
31.208.97.26 - - [24/Jul/2026:03:00:01 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4664 "-" "WordPress.com; https://wordpress.com"
31.208.97.26 - - [24/Jul/2026:03:00:11 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4665 "-" "Jetpack by WordPress.com"
31.208.97.26 - - [24/Jul/2026:03:00:22 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4664 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 22:48:35
(14 hours ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 18:48:29.845423 2026] [security2:error] [pid 3644739:tid 3644739] [client 31.208.97.26:44403] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.26 (+1 hits since last alert)|roguetechscene.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "roguetechscene.com"] [uri "/xmlrpc.php"] [unique_id "amKaPVbzX09J9X3giKPbCgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-07-23 21:30:42
(15 hours ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
IndigoRidge
2026-07-23 21:18:48
(15 hours ago)
31.208.97.26 - - [23/Jul/2026:17:17:33 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5090 "-" "WordPress.co ...
show more
31.208.97.26 - - [23/Jul/2026:17:17:33 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5090 "-" "WordPress.com; https://wordpress.com"
31.208.97.26 - - [23/Jul/2026:17:18:05 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5090 "-" "WordPress.com; https://wordpress.com"
31.208.97.26 - - [23/Jul/2026:17:18:16 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5090 "-" "WordPress.com; https://wordpress.com"
31.208.97.26 - - [23/Jul/2026:17:18:37 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5090 "-" "WordPress.com; https://wordpress.com"
31.208.97.26 - - [23/Jul/2026:17:18:47 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5090 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 16:39:24
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 12:39:18.722910 2026] [security2:error] [pid 2800:tid 2800] [client 31.208.97.26:22098] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.26 (+1 hits since last alert)|produktives.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "produktives.com"] [uri "/xmlrpc.php"] [unique_id "amJDtioS57fpj9oYQNQ0HQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-23 15:06:33
(22 hours ago)
31.208.97.26 - - [23/Jul/2026:11:05:51 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.co ...
show more
31.208.97.26 - - [23/Jul/2026:11:05:51 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
31.208.97.26 - - [23/Jul/2026:11:06:01 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
31.208.97.26 - - [23/Jul/2026:11:06:12 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
31.208.97.26 - - [23/Jul/2026:11:06:22 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
31.208.97.26 - - [23/Jul/2026:11:06:33 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-07-23 15:03:45
(22 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 13:53:54
(23 hours ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 09:53:49.548328 2026] [security2:error] [pid 27664:tid 27664] [client 31.208.97.26:44612] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.26 (+1 hits since last alert)|bikinitweets.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bikinitweets.com"] [uri "/xmlrpc.php"] [unique_id "amIc7SO9hiSmGbvOI_NvQAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-23 10:16:52
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-23 10:16:52
(1 day ago)
(wordpress) Failed wordpress login from 31.208.97.26 (SE/Sweden/31-208-97-26.cust.bredband2.com)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-23 06:14:29
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): ...
show more
(mod_security) mod_security (id:240335) triggered by 31.208.97.26 (31-208-97-26.cust.bredband2.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 02:14:23.143659 2026] [security2:error] [pid 1847384:tid 1847384] [client 31.208.97.26:22854] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 31.208.97.26 (+1 hits since last alert)|ontimelogistiks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ontimelogistiks.com"] [uri "/xmlrpc.php"] [unique_id "amGxP0JPGrC4YKLycBj46wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack