π³π±
Site.eu
2026-08-24 08:23:12
(12 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
π¦πΊ
screwlooseit.com.au
2026-08-24 07:32:02
(13 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
MA/Morocco/-
Web App Attack
π³π±
ConsulHosting
2026-08-24 06:11:26
(14 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 01:30:08
(19 hours ago)
(mod_security) mod_security (id:240335) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 21:30:04.195421 2026] [security2:error] [pid 22209:tid 22209] [client 41.141.149.39:57312] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.141.149.39 (+1 hits since last alert)|yerevanpress.am|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yerevanpress.am"] [uri "/xmlrpc.php"] [unique_id "aouenBhq0kxDWJqzd3gxHgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
debestelapp
2026-08-24 01:15:07
(19 hours ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 00:11:05
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 20:10:58.714562 2026] [security2:error] [pid 28750:tid 28750] [client 41.141.149.39:48685] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.141.149.39 (+1 hits since last alert)|rwabutazafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rwabutazafoundation.org"] [uri "/xmlrpc.php"] [unique_id "aouMEoPuaXMb652vaIR6BQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
konseptit
2026-08-24 00:09:10
(20 hours ago)
(wordpress) Failed wordpress login from 41.141.149.39 (MA/Morocco/-)
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-23 22:57:46
(21 hours ago)
(mod_security) mod_security (id:240335) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 18:57:40.630621 2026] [security2:error] [pid 32296:tid 32296] [client 41.141.149.39:56150] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.141.149.39 (+1 hits since last alert)|hotpay.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hotpay.co"] [uri "/xmlrpc.php"] [unique_id "aot65MEtcgsyfFndJ5OrSAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 22:08:30
(22 hours ago)
(mod_security) mod_security (id:240335) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 18:08:26.341727 2026] [security2:error] [pid 18416:tid 18416] [client 41.141.149.39:52800] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.141.149.39 (+1 hits since last alert)|certifiedfarmersmarkets.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "certifiedfarmersmarkets.org"] [uri "/xmlrpc.php"] [unique_id "aotvWtLp1CKTxQG8pCWTCQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Kenshin869
2026-08-23 21:53:41
(23 hours ago)
Wordpress unauthorized access attempt
Brute-Force
Anonymous
2026-08-23 20:21:28
(1 day ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 18:29:06
(1 day ago)
(wordpress) Failed wordpress login from 41.141.149.39 (MA/Morocco/-)
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-23 17:04:48
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 13:04:43.281416 2026] [security2:error] [pid 27513:tid 27513] [client 41.141.149.39:56837] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.141.149.39 (+1 hits since last alert)|mkdesignndetailing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mkdesignndetailing.com"] [uri "/xmlrpc.php"] [unique_id "aosoK15kJZT64SSXxOZRMAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 15:50:48
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 41.141.149.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 11:50:42.223365 2026] [security2:error] [pid 21848:tid 21848] [client 41.141.149.39:37747] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||naominixon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "naominixon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aosW0n60MXxEMETY5mOeMgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-08-23 15:09:42
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack