πΊπΈ
TPI-Abuse
2026-06-23 00:29:19
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 20:29:12.709082 2026] [security2:error] [pid 24849:tid 24849] [client 39.35.209.215:12787] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.209.215 (+1 hits since last alert)|pondplain.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pondplain.org"] [uri "/xmlrpc.php"] [unique_id "ajnTWIY7954j9p4fz7UZPgAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
masterguru
2026-06-22 23:06:19
(1 day ago)
(xmlrpc) Failed xmlrpc access from 39.35.209.215 (PK/Pakistan/-): 5 in the last 3600 secs (0-122)
Hacking
πΊπΈ
TPI-Abuse
2026-06-22 22:51:02
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 18:50:57.591963 2026] [security2:error] [pid 9296:tid 9296] [client 39.35.209.215:18407] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.209.215 (+1 hits since last alert)|navarrete.ws|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "navarrete.ws"] [uri "/xmlrpc.php"] [unique_id "ajm8URe7nUC6wP1-Zl6WfwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-06-22 22:41:03
(1 day ago)
trying wp-login.php/xmlrpc.php 30 times in 1 minutes
Brute-Force
Web App Attack
π«π·
SpaceHost-Server
2026-06-22 22:32:29
(1 day ago)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 22:11:24
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 18:11:19.787203 2026] [security2:error] [pid 14084:tid 14084] [client 39.35.209.215:25513] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.209.215 (+1 hits since last alert)|enjoymycondos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "enjoymycondos.com"] [uri "/xmlrpc.php"] [unique_id "ajmzB5E73DG9FFrbt-ye1AAAAF0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-06-22 21:53:07
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 20:53:03
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 16:52:55.530608 2026] [security2:error] [pid 31192:tid 31192] [client 39.35.209.215:60115] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.209.215 (+1 hits since last alert)|thehealthyplaceclayton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thehealthyplaceclayton.com"] [uri "/xmlrpc.php"] [unique_id "ajmgp6_orhAQNmtTSTEPTgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 20:14:33
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 16:14:28.232674 2026] [security2:error] [pid 29983:tid 29983] [client 39.35.209.215:2565] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.209.215 (+1 hits since last alert)|crittergetterpestcontrol.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "crittergetterpestcontrol.com"] [uri "/xmlrpc.php"] [unique_id "ajmXpGloM8JUA6QREIHT7wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 19:47:36
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 15:47:32.968853 2026] [security2:error] [pid 22084:tid 22084] [client 39.35.209.215:41341] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.209.215 (+1 hits since last alert)|thenutritionfixhollysprings.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thenutritionfixhollysprings.com"] [uri "/xmlrpc.php"] [unique_id "ajmRVMM8A-sTysrbRs6S6AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 19:32:28
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 15:32:20.864960 2026] [security2:error] [pid 2683:tid 2683] [client 39.35.209.215:43469] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.209.215 (+1 hits since last alert)|d-sinema.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "d-sinema.com"] [uri "/xmlrpc.php"] [unique_id "ajmNxIexAXjoRofE7PvnrAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 19:30:30
(1 day ago)
[redacted] 39.35.209.215 - - [22/Jun/2026:21:29:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 39.35.209.215 - - [22/Jun/2026:21:29:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.4; http://site65742889.com"
[redacted] 39.35.209.215 - - [22/Jun/2026:21:29:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 39.35.209.215 - - [22/Jun/2026:21:30:07 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 39.35.209.215 - - [22/Jun/2026:21:30:18 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 39.35.209.215 - - [22/Jun/2026:21:30:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.2; http://site59332905.com"
...
show less
Hacking
Web App Attack
π¬π§
Apache
2026-06-22 18:59:42
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (PK/Pakistan/-): 5 in the last 30 ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (PK/Pakistan/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
Anonymous
2026-06-22 18:59:04
(1 day ago)
[ns65.kdns.gr] httpd-xmlrpc-post: sites=plaero.gr; logs=/var/log/httpd/domains/plaero.gr.log; sample ...
show more
[ns65.kdns.gr] httpd-xmlrpc-post: sites=plaero.gr; logs=/var/log/httpd/domains/plaero.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 18:31:20
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.209.215 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 14:31:16.467069 2026] [security2:error] [pid 17628:tid 17628] [client 39.35.209.215:63613] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.209.215 (+1 hits since last alert)|arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "arsenalfordemocracy.com"] [uri "/xmlrpc.php"] [unique_id "ajl_dFM2x5PV-jKxgH-1OgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack