๐บ๐ธ
TPI-Abuse
2026-06-18 15:39:56
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 39.48.66.76 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 39.48.66.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 11:39:52.754716 2026] [security2:error] [pid 29157:tid 29157] [client 39.48.66.76:52008] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.48.66.76 (+1 hits since last alert)|gacstoday.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gacstoday.com"] [uri "/xmlrpc.php"] [unique_id "ajQRSAKr6mF4_ahm0_xmxAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-18 11:13:52
(10 hours ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=electromecanica.gr; logs=/var/log/httpd/domains/electromecan ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=electromecanica.gr; logs=/var/log/httpd/domains/electromecanica.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
Anonymous
2026-06-18 11:08:15
(10 hours ago)
[redacted] 39.48.66.76 - - [18/Jun/2026:13:07:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Wor ...
show more
[redacted] 39.48.66.76 - - [18/Jun/2026:13:07:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 39.48.66.76 - - [18/Jun/2026:13:07:33 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 39.48.66.76 - - [18/Jun/2026:13:07:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 39.48.66.76 - - [18/Jun/2026:13:08:03 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.1; http://site78689710.com"
[redacted] 39.48.66.76 - - [18/Jun/2026:13:08:13 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.2; http://site27191201.com"
...
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-06-17 17:42:47
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 15:37:12
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 39.48.66.76 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 39.48.66.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 11:37:09.165149 2026] [security2:error] [pid 15415:tid 15415] [client 39.48.66.76:52871] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.48.66.76 (+1 hits since last alert)|tedharris.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tedharris.com"] [uri "/xmlrpc.php"] [unique_id "ajFtpTk7s31l3kS77d6w9wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-16 11:40:38
(2 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ณ๐ฑ
ConsulHosting
2026-06-15 09:43:45
(3 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 07:40:28
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 39.48.66.76 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 39.48.66.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 03:40:21.983930 2026] [security2:error] [pid 30286:tid 30286] [client 39.48.66.76:57506] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.48.66.76 (+1 hits since last alert)|equipoperu.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "equipoperu.org"] [uri "/xmlrpc.php"] [unique_id "ai-sZRy8RBgaxjODv5wHIQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-06-15 07:39:24
(3 days ago)
(wordpress) Failed wordpress login from 39.48.66.76 (PK/Pakistan/Khyber Pakhtunkhwa/Peshawar/-)
Brute-Force
๐ซ๐ท
dynamix
2026-06-14 18:39:36
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-06-14 16:06:35
(4 days ago)
[redacted] 39.48.66.76 - - [14/Jun/2026:18:05:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Wor ...
show more
[redacted] 39.48.66.76 - - [14/Jun/2026:18:05:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 39.48.66.76 - - [14/Jun/2026:18:05:49 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 39.48.66.76 - - [14/Jun/2026:18:05:53 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 39.48.66.76 - - [14/Jun/2026:18:06:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
[redacted] 39.48.66.76 - - [14/Jun/2026:18:06:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack/12.5; WordPress/6.2; http://site68302255.com"
[redacted] 39.48.66.76 - - [14/Jun/2026:18:06:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 39.48.66.76 - - [14/Jun/2026:18:06:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 12.5;
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 16:21:29
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 39.48.66.76 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 39.48.66.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 12:21:25.426479 2026] [security2:error] [pid 9990:tid 9990] [client 39.48.66.76:54540] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.48.66.76 (+1 hits since last alert)|xyncom.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "xyncom.com"] [uri "/xmlrpc.php"] [unique_id "aiwyBQ08VLp63bskfMtJEgAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 15:51:23
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 39.48.66.76 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 39.48.66.76 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 11:51:19.615095 2026] [security2:error] [pid 24602:tid 24602] [client 39.48.66.76:64442] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.48.66.76 (+1 hits since last alert)|pakistanvision.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pakistanvision.com"] [uri "/xmlrpc.php"] [unique_id "aiwq9ylkzSwARpv2l5zLNwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-06-12 12:32:05
(6 days ago)
(xmlrpc) Failed xmlrpc access from 39.48.66.76 (PK/Pakistan/-): 5 in the last 3600 secs (0-122)
Hacking