Anonymous
2026-07-29 07:00:00
(14 hours ago)
Automated Apache web application probing in selected 24h window; attempts=120, unique_paths=1, error ...
show more
Automated Apache web application probing in selected 24h window; attempts=120, unique_paths=1, error_responses=120; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(14 hours ago)
Apache probe; attempts=261; exact paths: /xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-28 00:38:31
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.221.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.221.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 20:38:23.182578 2026] [security2:error] [pid 721849:tid 721849] [client 39.35.221.214:62065] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.221.214 (+1 hits since last alert)|jacquelineperriam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jacquelineperriam.com"] [uri "/xmlrpc.php"] [unique_id "amf5_-eJ9oKzL5kZFcA4ngAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 00:06:08
(1 day ago)
Trying to access config files
Web App Attack
π©πͺ
LRob
2026-07-27 23:58:49
(1 day ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack/12.5; WordPress ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack/12.5; WordPress/6.4; http://site36709844.com
show less
Brute-Force
Web App Attack
Anonymous
2026-07-27 23:52:49
(1 day ago)
[osotir.org] httpd-xmlrpc-post: sites=www.agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.log ...
show more
[osotir.org] httpd-xmlrpc-post: sites=www.agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 23:40:44
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.221.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.221.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 19:40:40.378605 2026] [security2:error] [pid 373536:tid 373536] [client 39.35.221.214:51508] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.221.214 (+1 hits since last alert)|cathybermanmft.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cathybermanmft.com"] [uri "/xmlrpc.php"] [unique_id "amfseFqqb9ipdwL0Q6H1ZgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 23:15:09
(1 day ago)
Web attack blocked by Wordfence on 1valkenburg.nl (4 hits). Reported by CRMON.
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 23:04:44
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 39.35.221.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.221.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 19:04:37.036425 2026] [security2:error] [pid 3643035:tid 3643052] [client 39.35.221.214:9927] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.221.214 (+1 hits since last alert)|aclarityforensics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aclarityforensics.com"] [uri "/xmlrpc.php"] [unique_id "amfkBa0SN2FetvPkizbZ-AAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-07-27 22:25:18
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πͺπΈ
masterguru
2026-07-27 21:56:07
(2 days ago)
(xmlrpc) Failed xmlrpc access from 39.35.221.214 (PK/Pakistan/-): 5 in the last 3600 secs (0-122)
Hacking
πΊπΈ
WeekendWeb
2026-07-27 21:32:20
(2 days ago)
Wordpress Vunerability attack
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 20:55:38
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 39.35.221.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.221.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 16:55:33.176757 2026] [security2:error] [pid 811860:tid 811860] [client 39.35.221.214:21181] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.221.214 (+1 hits since last alert)|artevoix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "artevoix.com"] [uri "/xmlrpc.php"] [unique_id "amfFxWQ_SIinWzaRWiMkZAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
ConsulHosting
2026-07-27 20:32:34
(2 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-27 20:26:09
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 39.35.221.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 39.35.221.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 16:26:04.015154 2026] [security2:error] [pid 25885:tid 25885] [client 39.35.221.214:63298] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.35.221.214 (+1 hits since last alert)|laecovillage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "laecovillage.org"] [uri "/xmlrpc.php"] [unique_id "ame-3M3falIjtuOKpH64vAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack