πΊπΈ
TPI-Abuse
2026-06-26 04:51:34
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 41.47.214.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 41.47.214.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 00:51:30.805589 2026] [security2:error] [pid 27266:tid 27266] [client 41.47.214.35:64456] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.47.214.35 (+1 hits since last alert)|athletefirst.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "athletefirst.org"] [uri "/xmlrpc.php"] [unique_id "aj4FUqZ49vGGuFgG7bDmdQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
rh24
2026-06-25 23:12:05
(8 hours ago)
(wordpress) Failed wordpress login from 41.47.214.35 (EG/Egypt/-): (CF_ENABLE)
Brute-Force
π¦πΊ
screwlooseit.com.au
2026-06-25 22:41:03
(9 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
EG/Egypt/-
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-25 21:33:20
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 41.47.214.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 41.47.214.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 17:33:15.043963 2026] [security2:error] [pid 18650:tid 18790] [client 41.47.214.35:65266] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.47.214.35 (+1 hits since last alert)|smarterproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "smarterproductions.com"] [uri "/xmlrpc.php"] [unique_id "aj2em6dpt_X2IyQgq9DnawAAAoo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-25 19:23:03
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 41.47.214.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 41.47.214.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 15:22:58.073047 2026] [security2:error] [pid 9787:tid 9787] [client 41.47.214.35:62528] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.47.214.35 (+1 hits since last alert)|lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lysedzija.com"] [uri "/xmlrpc.php"] [unique_id "aj2AEqAwaHB7g4UDtmAe9AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-25 16:40:00
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 41.47.214.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 41.47.214.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 12:39:56.926144 2026] [security2:error] [pid 32557:tid 32557] [client 41.47.214.35:51090] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.47.214.35 (+1 hits since last alert)|persnicketyinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "persnicketyinc.com"] [uri "/xmlrpc.php"] [unique_id "aj1Z3JjswvhBErYDV5-U5gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
alferez
2026-06-25 16:26:11
(15 hours ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
πΊπΈ
cwytech
2026-06-25 13:51:47
(18 hours ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
πΊπΈ
Dolphi
2026-06-25 01:20:04
(1 day ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-23 21:52:50
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 41.47.214.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 41.47.214.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 17:52:46.271265 2026] [security2:error] [pid 9304:tid 9304] [client 41.47.214.35:50927] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.47.214.35 (+1 hits since last alert)|daisydoesoap.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "daisydoesoap.com"] [uri "/xmlrpc.php"] [unique_id "ajsALgnzgOsqAL3JoRAtDwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-06-23 18:16:08
(2 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking