|
π«π·
dynamix
|
|
WordPress XMLRPC Brute Force Attack
|
Brute-Force
Web App Attack
|
|
|
πΊπΈ
oralunal
|
|
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
|
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 38.196.81.182 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 38.196.81.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 17:08:07.060405 2026] [security2:error] [pid 20371:tid 20371] [client 38.196.81.182:64130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 38.196.81.182 (+1 hits since last alert)|waterjetsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "waterjetsolutions.com"] [uri "/xmlrpc.php"] [unique_id "ajhSt5hHDIg5Dj8reJEHvAAAAAw"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 38.196.81.182 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 38.196.81.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 19:09:50.966257 2026] [security2:error] [pid 24687:tid 24687] [client 38.196.81.182:60383] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 38.196.81.182 (+1 hits since last alert)|nordicbuilders.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nordicbuilders.net"] [uri "/xmlrpc.php"] [unique_id "ajcdvmNOfHba4q4lV_sn0AAAAAc"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
[redacted] 38.196.81.182 - - [21/Jun/2026:01:04:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "W ...
show more
[redacted] 38.196.81.182 - - [21/Jun/2026:01:04:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 38.196.81.182 - - [21/Jun/2026:01:05:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
[redacted] 38.196.81.182 - - [21/Jun/2026:01:05:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
[redacted] 38.196.81.182 - - [21/Jun/2026:01:05:27 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 38.196.81.182 - - [21/Jun/2026:01:05:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.2; http://site89797958.com"
...
show less
|
Hacking
Web App Attack
|
|
|
π«π·
applemooz
|
|
WordPress XMLRPC Brute Force Attacks
...
|
Brute-Force
Web App Attack
|
|
|
πΊπΈ
TAY
|
|
38.196.81.182 - - [19/Jun/2026:09:58:03 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by ...
show more
38.196.81.182 - - [19/Jun/2026:09:58:03 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
38.196.81.182 - - [19/Jun/2026:09:58:14 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack/13.0; WordPress/6.4; http://site21442886.com"
38.196.81.182 - - [19/Jun/2026:09:58:24 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
...
show less
|
Brute-Force
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 38.196.81.182 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 38.196.81.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 19:07:25.948414 2026] [security2:error] [pid 32317:tid 32317] [client 38.196.81.182:62123] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 38.196.81.182 (+1 hits since last alert)|soonerstone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "soonerstone.com"] [uri "/xmlrpc.php"] [unique_id "ajR6LWCkGhMpz0tNlqZGWAAAAAU"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
Anonymous
|
|
Blocked by ModSec and CSF
|
Port Scan
|
|
|
πΊπΈ
TPI-Abuse
|
|
(mod_security) mod_security (id:240335) triggered by 38.196.81.182 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 38.196.81.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 21:27:05.849990 2026] [security2:error] [pid 4940:tid 4940] [client 38.196.81.182:53224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 38.196.81.182 (+1 hits since last alert)|pixelspective.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pixelspective.com"] [uri "/xmlrpc.php"] [unique_id "ajNJaYMx-8P15yAFoPYpBwAAAAs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
π¨π
backslash
|
|
block ruleset A5EE6C8F745F0934168261886A3817E5C386412A
|
Bad Web Bot
|
|
|
π³π±
exxos
|
|
Attacks with Bad user agents
|
Hacking
|
|