๐บ๐ธ
TPI-Abuse
2026-07-30 16:02:13
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 12:02:08.153112 2026] [security2:error] [pid 830375:tid 830375] [client 36.50.162.43:61284] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kadinisi.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kadinisi.org"] [uri "/wp-json/wp/v2/users"] [unique_id "amt1gP3_2Jnsft6yPlS9ZAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 13:56:00
(21 hours ago)
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 09:55:54.087457 2026] [security2:error] [pid 2833250:tid 2833250] [client 36.50.162.43:53874] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.162.43 (+1 hits since last alert)|rajabarber.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rajabarber.com"] [uri "/xmlrpc.php"] [unique_id "amtX6sCxIKBb_3BnrQ-0gAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-30 13:53:30
(21 hours ago)
[redacted] 36.50.162.43 - - [30/Jul/2026:15:52:46 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6597 "-" "W ...
show more
[redacted] 36.50.162.43 - - [30/Jul/2026:15:52:46 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6597 "-" "WordPress.com; https://wordpress.com"
[redacted] 36.50.162.43 - - [30/Jul/2026:15:52:58 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6642 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
[redacted] 36.50.162.43 - - [30/Jul/2026:15:53:07 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6642 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 36.50.162.43 - - [30/Jul/2026:15:53:18 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6642 "-" "Jetpack/12.1; WordPress/6.4; http://site19745776.com"
[redacted] 36.50.162.43 - - [30/Jul/2026:15:53:29 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6556 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
oralunal
2026-07-30 05:36:34
(1 day ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 13:00:15
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 09:00:10.604838 2026] [security2:error] [pid 2871839:tid 2871839] [client 36.50.162.43:60194] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.162.43 (+1 hits since last alert)|greensandbeans.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "greensandbeans.us"] [uri "/xmlrpc.php"] [unique_id "amn5Wn0d-AWOX9IZSMwCBwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 05:49:26
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 01:49:19.903047 2026] [security2:error] [pid 1008140:tid 1008140] [client 36.50.162.43:58168] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.162.43 (+1 hits since last alert)|drbolen.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "drbolen.com"] [uri "/xmlrpc.php"] [unique_id "ammUX2uurnQvcyEfUPyb6QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 04:46:53
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 00:46:48.471309 2026] [security2:error] [pid 1904604:tid 1904604] [client 36.50.162.43:63045] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.162.43 (+1 hits since last alert)|knoxbestos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "knoxbestos.com"] [uri "/xmlrpc.php"] [unique_id "ammFuHJbaj5G0E2_zwOragAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 13:36:23
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 09:36:20.030968 2026] [security2:error] [pid 1127921:tid 1127921] [client 36.50.162.43:56727] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.162.43 (+1 hits since last alert)|crr-construction.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "crr-construction.com"] [uri "/xmlrpc.php"] [unique_id "amiwVBrLsdtaWWlhTiFltAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 11:05:12
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 07:05:05.872215 2026] [security2:error] [pid 930294:tid 930294] [client 36.50.162.43:55534] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.162.43 (+1 hits since last alert)|famagustacyprus.eu|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "famagustacyprus.eu"] [uri "/xmlrpc.php"] [unique_id "amiM4dHtF6_6m5_4a81cXAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 10:10:53
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.162.43 (162.50.36.joitex.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 06:10:49.061614 2026] [security2:error] [pid 1010716:tid 1010716] [client 36.50.162.43:50400] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.162.43 (+1 hits since last alert)|wsffjatc.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wsffjatc.org"] [uri "/xmlrpc.php"] [unique_id "amiAKXcZz-jb7DWGXQl4agAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 05:37:49
(3 days ago)
[redacted] 36.50.162.43 - - [28/Jul/2026:07:37:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Wo ...
show more
[redacted] 36.50.162.43 - - [28/Jul/2026:07:37:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 36.50.162.43 - - [28/Jul/2026:07:37:15 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
[redacted] 36.50.162.43 - - [28/Jul/2026:07:37:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 36.50.162.43 - - [28/Jul/2026:07:37:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
[redacted] 36.50.162.43 - - [28/Jul/2026:07:37:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
exxos
2025-09-09 17:03:01
(10 months ago)
Attacks with Bad user agents
Hacking