๐ฉ๐ช
Marc
2026-06-18 15:05:01
(2 hours ago)
37.114.150.83 - - [18/Jun/2026:17:04:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3299 "-" "Jetpack/12. ...
show more
37.114.150.83 - - [18/Jun/2026:17:04:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3299 "-" "Jetpack/12.5; WordPress/6.4; http://site94430607.com" 37.114.150.83 - - [18/Jun/2026:17:04:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3299 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)" 37.114.150.83 - - [18/Jun/2026:17:05:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3298 "-" "WordPress.com; https://wordpress.com"
show less
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-18 14:07:36
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 09:24:42
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 37.114.150.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 37.114.150.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 05:24:36.452447 2026] [security2:error] [pid 14260:tid 14260] [client 37.114.150.83:4187] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.114.150.83 (+1 hits since last alert)|modalguitarist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "modalguitarist.com"] [uri "/xmlrpc.php"] [unique_id "ajO5VNAnjOnrgxicdl784gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-06-18 05:58:33
(11 hours ago)
(xmlrpc) Failed xmlrpc access from 37.114.150.83 (AZ/Azerbaijan/-): 5 in the last 3600 secs (0-122)
Hacking
Anonymous
2026-06-18 03:55:02
(13 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-06-17 14:43:02
(1 day ago)
37.114.150.83 - [17/Jun/2026:17:42:54 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18965 "-" "Jetpack by W ...
show more
37.114.150.83 - [17/Jun/2026:17:42:54 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18965 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)" "-"
37.114.150.83 - [17/Jun/2026:17:43:02 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18052 "-" "Jetpack/12.0; WordPress/6.4; http://site32472878.com" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-06-17 14:27:46
(1 day ago)
37.114.150.83 - [17/Jun/2026:17:27:38 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18965 "-" "Jetpack by W ...
show more
37.114.150.83 - [17/Jun/2026:17:27:38 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18965 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)" "-"
37.114.150.83 - [17/Jun/2026:17:27:46 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18052 "-" "Jetpack by WordPress.com" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-06-17 10:45:08
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
Anonymous
2026-06-17 10:44:13
(1 day ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-17 09:34:14
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.114.150.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 37.114.150.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 05:34:09.730434 2026] [security2:error] [pid 31242:tid 31242] [client 37.114.150.83:3057] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.114.150.83 (+1 hits since last alert)|aroilcontrolsystem.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aroilcontrolsystem.com"] [uri "/xmlrpc.php"] [unique_id "ajJqESsRGznEbGOnD_x78wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 06:30:55
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.114.150.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 37.114.150.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 02:30:49.905257 2026] [security2:error] [pid 17227:tid 17227] [client 37.114.150.83:6776] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.114.150.83 (+1 hits since last alert)|texascottagebakers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "texascottagebakers.com"] [uri "/xmlrpc.php"] [unique_id "ajI_GV37rf0ypoXi1f5M0wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-06-17 06:02:05
(1 day ago)
(wordpress) Failed wordpress login from 37.114.150.83 (AZ/Azerbaijan/Baku City/Baku/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-17 04:28:37
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.114.150.83 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 37.114.150.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 00:28:31.303006 2026] [security2:error] [pid 3191:tid 3191] [client 37.114.150.83:6759] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.114.150.83 (+1 hits since last alert)|jimrichardart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jimrichardart.com"] [uri "/xmlrpc.php"] [unique_id "ajIib-1fMqCpZPAkm3yBzgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-30 16:09:32
(1 month ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in thread-post.asp
show less
Exploited Host
Bad Web Bot
๐บ๐ธ
SiliSoftware
2026-04-08 15:31:35
(2 months ago)
/phpBB3/viewforum.php?f=10&sid=8e44747abd451561194dfb578c38ffe6
Web App Attack