๐ฉ๐ช
abdubhai
2026-08-20 10:53:47
(5 days ago)
36.81.62.36 - - [20/Aug/2026:15:
...
Brute-Force
๐ซ๐ท
Kenshin869
2026-08-20 09:41:41
(5 days ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-20 06:12:11
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 02:11:57.453302 2026] [security2:error] [pid 31625:tid 31625] [client 36.81.62.36:63156] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.81.62.36 (+1 hits since last alert)|rdhtrucking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rdhtrucking.com"] [uri "/xmlrpc.php"] [unique_id "aoaarYnMPwU4ODzg1lfWjAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2026-08-20 04:10:05
(5 days ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 16:06:36
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 12:06:21.214287 2026] [security2:error] [pid 1693:tid 1693] [client 36.81.62.36:56477] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.81.62.36 (+1 hits since last alert)|georgesmarina.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "georgesmarina.com"] [uri "/xmlrpc.php"] [unique_id "aoXUfRVcgtYmwdjX8C-g6QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
. .
2026-08-19 15:02:14
(6 days ago)
[20/Aug/2026:00:01:32 +0900] [REDACTED] 36.81.62.36 0.016 "POST /xmlrpc.php HTTP/1.1" 200 1197 1764 ...
show more
[20/Aug/2026:00:01:32 +0900] [REDACTED] 36.81.62.36 0.016 "POST /xmlrpc.php HTTP/1.1" 200 1197 1764 - WordPress.com; https://wordpress.com
[20/Aug/2026:00:01:41 +0900] [REDACTED] 36.81.62.36 0.013 "POST /xmlrpc.php HTTP/1.1" 200 1200 1767 - WordPress.com; https://wordpress.com
[20/Aug/2026:00:01:53 +0900] [REDACTED] 36.81.62.36 0.013 "POST /xmlrpc.php HTTP/1.1" 200 1198 1765 - Jetpack by WordPress.com
[20/Aug/2026:00:02:02 +0900] [REDACTED] 36.81.62.36 0.013 "POST /xmlrpc.php HTTP/1.1" 200 1198 1765 - Jetpack by WordPress.com
[20/Aug/2026:00:02:13 +0900] [REDACTED] 36.81.62.36 0.010 "POST /xmlrpc.php HTTP/1.1" 200 1198 1765 - Jetpack/12.5; WordPress/6.1; http://site19647534.com
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 14:21:03
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 10:20:50.833619 2026] [security2:error] [pid 1197:tid 1197] [client 36.81.62.36:61621] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gegkal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gegkal.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoW7wuTCMNv6KlnYBN2GBQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 04:35:59
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 00:35:42.790609 2026] [security2:error] [pid 21517:tid 21517] [client 36.81.62.36:52879] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.81.62.36 (+1 hits since last alert)|savingspools.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "savingspools.com"] [uri "/xmlrpc.php"] [unique_id "aoUynlx-05T_1Xp4OXgCrAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-08-19 04:25:23
(6 days ago)
36.81.62.36 - - [19/Aug/2026:06:25:23 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack by WordPress.com ( ...
show more
36.81.62.36 - - [19/Aug/2026:06:25:23 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 12:04:15
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 08:04:01.318710 2026] [security2:error] [pid 28661:tid 28661] [client 36.81.62.36:55753] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.81.62.36 (+1 hits since last alert)|jonasrimkunas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jonasrimkunas.com"] [uri "/xmlrpc.php"] [unique_id "aoGnMTTDcac_eLxA55KKygAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 09:49:28
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 36.81.62.36 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 05:49:14.409751 2026] [security2:error] [pid 30952:tid 30996] [client 36.81.62.36:61320] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.81.62.36 (+1 hits since last alert)|gabegabel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gabegabel.com"] [uri "/xmlrpc.php"] [unique_id "aoGHmiXYt94a243V7P8o_wAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-16 08:35:25
(1 week ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-16 08:20:28
(1 week ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-16 08:14:09
(1 week ago)
Brute-force login attack detected by WordPress firewall.
Brute-Force
Web App Attack