๐บ๐ธ
TPI-Abuse
2026-06-23 00:56:01
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 39.35.199.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.199.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 20:55:55.475218 2026] [security2:error] [pid 20321:tid 20321] [client 39.35.199.19:12303] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.199.19 (+1 hits since last alert)|odinathletes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "odinathletes.com"] [uri "/xmlrpc.php"] [unique_id "ajnZmyD55h_g_Ne_VRJrywAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-06-23 00:05:32
(3 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 23:53:44
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 39.35.199.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.199.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 19:53:37.964902 2026] [security2:error] [pid 6972:tid 6980] [client 39.35.199.19:15683] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.199.19 (+1 hits since last alert)|frannykingsmith.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "frannykingsmith.com"] [uri "/xmlrpc.php"] [unique_id "ajnLAUjhzv4Et7O87nfZCgAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-22 22:41:05
(3 days ago)
trying wp-login.php/xmlrpc.php 31 times in 1 minutes
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-22 21:53:11
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-06-22 21:51:40
(3 days ago)
(xmlrpc) Failed xmlrpc access from 39.35.199.19 (PK/Pakistan/-): 5 in the last 3600 secs (0-122)
Hacking
๐ฉ๐ช
konseptit
2026-06-22 21:16:35
(3 days ago)
(wordpress) Failed wordpress login from 39.35.199.19 (PK/Pakistan/-)
Brute-Force
๐ฌ๐ง
NotCool
2026-06-22 20:55:55
(3 days ago)
(XMLRPC) WP XMLPRC Attack 39.35.199.19 (PK/Pakistan/-): 50 in the last 3600 secs
Web App Attack
Anonymous
2026-06-22 19:44:10
(3 days ago)
Attac
Brute-Force
Anonymous
2026-06-22 19:15:47
(3 days ago)
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 18:05:01
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 39.35.199.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.199.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 14:04:54.623339 2026] [security2:error] [pid 26184:tid 26184] [client 39.35.199.19:40449] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.199.19 (+1 hits since last alert)|legacy-insight.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "legacy-insight.com"] [uri "/xmlrpc.php"] [unique_id "ajl5RkzEQt23YVFdtbvLqwAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-22 18:03:49
(3 days ago)
6.893 post requests in 1 hour (1w3d9h)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-22 17:48:05
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 39.35.199.19 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.199.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 13:47:58.391358 2026] [security2:error] [pid 14709:tid 14709] [client 39.35.199.19:15565] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.199.19 (+1 hits since last alert)|scrunchiebuttbikinis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "scrunchiebuttbikinis.com"] [uri "/xmlrpc.php"] [unique_id "ajl1Tkww4usty61fKPLYwwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 17:47:06
(3 days ago)
[redacted] 39.35.199.19 - - [22/Jun/2026:19:46:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 39.35.199.19 - - [22/Jun/2026:19:46:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 39.35.199.19 - - [22/Jun/2026:19:46:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.2; http://site62650196.com"
[redacted] 39.35.199.19 - - [22/Jun/2026:19:46:42 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
[redacted] 39.35.199.19 - - [22/Jun/2026:19:46:53 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.3; http://site51202761.com"
[redacted] 39.35.199.19 - - [22/Jun/2026:19:47:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
cwytech
2026-06-22 17:44:36
(3 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack