Anonymous
2026-06-05 01:00:45
(17 hours ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=imeresd.gr; logs=/var/log/httpd/domains/imeresd.gr.log; sam ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=imeresd.gr; logs=/var/log/httpd/domains/imeresd.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-05 00:19:42
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 20:19:38.676926 2026] [security2:error] [pid 29754:tid 29764] [client 37.28.24.70:64396] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.28.24.70 (+1 hits since last alert)|killasgarage.bike|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "killasgarage.bike"] [uri "/xmlrpc.php"] [unique_id "aiIWGkTZ9PFiyFN7r8d4hAAAAYQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 22:18:01
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 18:17:55.374472 2026] [security2:error] [pid 4390:tid 4390] [client 37.28.24.70:51199] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.28.24.70 (+1 hits since last alert)|wealthsec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wealthsec.com"] [uri "/xmlrpc.php"] [unique_id "aiH5k8r-sR0phWqKpRhSawAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 21:05:40
(21 hours ago)
Blocked: Reason='Vulnerability probing β PHP scan detected (69/60 min)'; Requests=69
Port Scan
πΊπΈ
TPI-Abuse
2026-06-04 15:14:20
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 11:14:16.249930 2026] [security2:error] [pid 23381:tid 23381] [client 37.28.24.70:63831] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.28.24.70 (+1 hits since last alert)|konahawaii.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "konahawaii.com"] [uri "/xmlrpc.php"] [unique_id "aiGWSARy-JYJ3BxGANKSuwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
konseptit
2026-06-04 12:39:20
(1 day ago)
(wordpress) Failed wordpress login from 37.28.24.70 (OM/Oman/dynamic.isp.ooredoo.om)
Brute-Force
Anonymous
2026-06-04 09:33:53
(1 day ago)
[redacted] 37.28.24.70 - - [04/Jun/2026:11:33:10 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jet ...
show more
[redacted] 37.28.24.70 - - [04/Jun/2026:11:33:10 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 37.28.24.70 - - [04/Jun/2026:11:33:21 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 37.28.24.70 - - [04/Jun/2026:11:33:31 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 37.28.24.70 - - [04/Jun/2026:11:33:42 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
[redacted] 37.28.24.70 - - [04/Jun/2026:11:33:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 08:34:12
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 04:34:09.193061 2026] [security2:error] [pid 29342:tid 29342] [client 37.28.24.70:53474] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.28.24.70 (+1 hits since last alert)|oshadega.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "oshadega.com"] [uri "/xmlrpc.php"] [unique_id "aiE4gbODlRXDmcjhzBhcJQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 07:02:15
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 03:02:11.221077 2026] [security2:error] [pid 10430:tid 10430] [client 37.28.24.70:65355] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.28.24.70 (+1 hits since last alert)|genevainvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "genevainvestors.com"] [uri "/xmlrpc.php"] [unique_id "aiEi8_MtpnowqnVTDavqMwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Apache
2026-06-04 06:33:59
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (OM/Oman/dynamic.isp.ooredoo.om): 5 ...
show more
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (OM/Oman/dynamic.isp.ooredoo.om): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-04 06:00:00
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 37.28.24.70 (dynamic.isp.ooredoo.om): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 01:59:56.286751 2026] [security2:error] [pid 2064:tid 2064] [client 37.28.24.70:57491] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.28.24.70 (+1 hits since last alert)|rodandreelpiercam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rodandreelpiercam.com"] [uri "/xmlrpc.php"] [unique_id "aiEUXEfx38kGlwzB6oDnhQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack