๐บ๐ธ
TPI-Abuse
2026-06-05 09:37:38
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 05:37:33.406124 2026] [security2:error] [pid 1463:tid 1463] [client 38.211.30.252:63347] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 38.211.30.252 (+1 hits since last alert)|ixd.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ixd.net"] [uri "/xmlrpc.php"] [unique_id "aiKY3WZkupV92WGbF2j13AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-05 01:11:37
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-05 01:11:33
(1 week ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-05 00:12:22
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 20:12:15.891576 2026] [security2:error] [pid 28818:tid 28818] [client 38.211.30.252:56584] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 38.211.30.252 (+1 hits since last alert)|caralis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "caralis.com"] [uri "/xmlrpc.php"] [unique_id "aiIUXwpYhpA7DDWqrsmerQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-06-05 00:01:06
(1 week ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐ฉ๐ช
Hazzard
2026-06-04 21:29:05
(1 week ago)
(wordpress) Failed wordpress login from 38.211.30.252 (BR/Brazil/Rio de Janeiro/Duque de Caxias/-/[r ...
show more
(wordpress) Failed wordpress login from 38.211.30.252 (BR/Brazil/Rio de Janeiro/Duque de Caxias/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-04 20:25:51
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 16:25:47.573883 2026] [security2:error] [pid 6519:tid 6519] [client 38.211.30.252:60613] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 38.211.30.252 (+1 hits since last alert)|riccardiagency.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "riccardiagency.com"] [uri "/xmlrpc.php"] [unique_id "aiHfS2vkKoxiJ8UqjP2uiQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 18:11:39
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 14:11:34.237624 2026] [security2:error] [pid 14689:tid 14689] [client 38.211.30.252:59396] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 38.211.30.252 (+1 hits since last alert)|lighthousescm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lighthousescm.com"] [uri "/xmlrpc.php"] [unique_id "aiG_1m4ZPz2vOUU83oe0cwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-06-04 18:00:22
(1 week ago)
AutoBlock: ๐ WordPress Login Brute Force (20X or 30X) (Decay-Based)
Brute-Force
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-04 15:35:00
(1 week ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 13:36:07
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 09:36:01.264704 2026] [security2:error] [pid 688:tid 688] [client 38.211.30.252:60155] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 38.211.30.252 (+1 hits since last alert)|mobileonlinecasinos.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mobileonlinecasinos.co"] [uri "/xmlrpc.php"] [unique_id "aiF_QaM87KqxhEjNS6P9_wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 13:06:30
(1 week ago)
[ns67.kdns.gr] httpd-xmlrpc-post: sites=kapaweb.gr; logs=/var/www/vhosts/kapaweb.gr/logs/access_ssl_ ...
show more
[ns67.kdns.gr] httpd-xmlrpc-post: sites=kapaweb.gr; logs=/var/www/vhosts/kapaweb.gr/logs/access_ssl_log,/var/www/vhosts/system/kapaweb.gr/logs/access_ssl_log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-06-04 12:25:08
(1 week ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 12:22:03
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 38.211.30.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 08:21:55.419491 2026] [security2:error] [pid 32529:tid 32560] [client 38.211.30.252:62601] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 38.211.30.252 (+1 hits since last alert)|woodamy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "woodamy.com"] [uri "/xmlrpc.php"] [unique_id "aiFt41vEFKLzyQngU6zUlQAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-06-04 11:05:22
(1 week ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack