๐บ๐ธ
TPI-Abuse
2026-07-24 05:10:50
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 01:10:44.644943 2026] [security2:error] [pid 1964719:tid 1964719] [client 36.50.148.85:59004] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.85 (+1 hits since last alert)|joevallone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "joevallone.com"] [uri "/xmlrpc.php"] [unique_id "amLz1LKmjRgwsxRsS-KICAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-22 18:08:41
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 28
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 06:35:45
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 02:35:37.469356 2026] [security2:error] [pid 20761:tid 20761] [client 36.50.148.85:53264] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.85 (+1 hits since last alert)|cubbylure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cubbylure.com"] [uri "/xmlrpc.php"] [unique_id "al8TOTQjO9LMjBsg2XjhdgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-20 06:20:09
(4 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 06:05:03
(4 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 09:13:22
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 05:13:16.668085 2026] [security2:error] [pid 23878:tid 23878] [client 36.50.148.85:52231] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.85 (+1 hits since last alert)|frogdesignmexico.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "frogdesignmexico.com"] [uri "/xmlrpc.php"] [unique_id "aldPLCazATHmO5pCDz-0mwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 06:13:01
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 02:12:55.426225 2026] [security2:error] [pid 24899:tid 24899] [client 36.50.148.85:50130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.85 (+1 hits since last alert)|psychiatryabuse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "psychiatryabuse.com"] [uri "/xmlrpc.php"] [unique_id "alSB53BC9wuU4DsiESMGWwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-07-05 13:35:49
(2 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-06-22 08:52:17
(1 month ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-03 06:55:17
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 02:55:10.651398 2026] [security2:error] [pid 28151:tid 28151] [client 36.50.148.85:60883] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.85 (+1 hits since last alert)|starsmogsandiego.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "starsmogsandiego.com"] [uri "/xmlrpc.php"] [unique_id "ah_PzpM-hS06nrLpdTKacQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
sashan
2026-04-13 14:38:58
(3 months ago)
2026-04-13T17:38:58.598117+03:00 gate kernel: nftables: JAIL-TELNET IN=wan OUT= MAC= SRC=36.50.148.8 ...
show more
2026-04-13T17:38:58.598117+03:00 gate kernel: nftables: JAIL-TELNET IN=wan OUT= MAC= SRC=36.50.148.85 DST=xxx.xxx.xxx.xxx LEN=60 TOS=0x00 PREC=0x00 TTL=47 ID=51454 DF PROTO=TCP SPT=58626 DPT=23 WINDOW=65535 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐จ๐ญ
4server
2026-04-08 08:23:23
(3 months ago)
[WedApr0810:23:20.2364012026][security2:error][pid770985:tid770998][client36.50.148.85:0]ModSecurity ...
show more
[WedApr0810:23:20.2364012026][security2:error][pid770985:tid770998][client36.50.148.85:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"201\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"aidweb.ch\"][uri\"/xmlrpc.php\"][unique_id\"adYQeKDVicaQMaFe6p9sSgAAAEo\"]
show less
Hacking
Web App Attack
๐ซ๐ท
Kenshin869
2026-04-05 04:54:44
(3 months ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
octageeks.com
2026-03-20 04:07:16
(4 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐ซ๐ท
tecnicorioja
2026-03-18 23:00:14
(4 months ago)
POST /xmlrpc.php [18/Mar/2026:05:33:59
Brute-Force
Web App Attack