Anonymous
2026-07-26 04:31:15
(1 hour ago)
Failed login attempt detected by Fail2Ban in plesk-postfix jail
Brute-Force
๐ฆ๐บ
screwlooseit.com.au
2026-07-25 00:38:42
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
KE/Kenya/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 00:10:17
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 20:10:11.212629 2026] [security2:error] [pid 266721:tid 266721] [client 41.90.144.224:1890] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.90.144.224 (+1 hits since last alert)|mskimberleesspace.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mskimberleesspace.com"] [uri "/xmlrpc.php"] [unique_id "amP-49G1QRFvGvh0hWpHMwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 18:11:14
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 14:11:10.437173 2026] [security2:error] [pid 957298:tid 957298] [client 41.90.144.224:2147] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.90.144.224 (+1 hits since last alert)|amywoodruff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "amywoodruff.com"] [uri "/xmlrpc.php"] [unique_id "amOqvjh8GUck6R8SNZ0ZVAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 17:39:17
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 13:39:10.169006 2026] [security2:error] [pid 3971670:tid 3971670] [client 41.90.144.224:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.90.144.224 (+1 hits since last alert)|cloudex.click|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cloudex.click"] [uri "/xmlrpc.php"] [unique_id "amOjPpRcRSXCLaBxHxtbUgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 17:07:03
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 10:28:41
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:28:37.033491 2026] [security2:error] [pid 2493683:tid 2493683] [client 41.90.144.224:6014] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.90.144.224 (+1 hits since last alert)|peacecampus.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "peacecampus.org"] [uri "/xmlrpc.php"] [unique_id "amM-VTBoexifzYm-fBBa1gAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 08:02:29
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฒ๐น
Malta
2026-07-24 02:09:23
(2 days ago)
41.90.144.224 - - [24/Jul/2026:04:09:23 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack by WordPress.com ...
show more
41.90.144.224 - - [24/Jul/2026:04:09:23 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 00:40:28
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 20:40:22.640121 2026] [security2:error] [pid 545354:tid 545354] [client 41.90.144.224:2208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.90.144.224 (+1 hits since last alert)|primemanagementmn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "primemanagementmn.com"] [uri "/xmlrpc.php"] [unique_id "amK0dhMdq_FqVzb6z4OPmwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 22:38:29
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 18:38:24.656078 2026] [security2:error] [pid 3646831:tid 3646831] [client 41.90.144.224:2480] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.90.144.224 (+1 hits since last alert)|avalderlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "avalderlaw.com"] [uri "/xmlrpc.php"] [unique_id "amKX4N7DSq1Sha4NH_UGKwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 17:37:50
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 13:37:43.053134 2026] [security2:error] [pid 3109490:tid 3109490] [client 41.90.144.224:8266] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.90.144.224 (+1 hits since last alert)|lighthousescm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lighthousescm.com"] [uri "/xmlrpc.php"] [unique_id "amJRZ0qkcR_nUW4L3vJL2QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 16:35:05
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 12:34:55.931368 2026] [security2:error] [pid 2496401:tid 2496401] [client 41.90.144.224:8454] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.90.144.224 (+1 hits since last alert)|difusionens.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "difusionens.org"] [uri "/xmlrpc.php"] [unique_id "amJCrzczmCLHDLKYARDM8wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 16:06:39
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.90.144.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 12:06:34.050880 2026] [security2:error] [pid 882698:tid 882698] [client 41.90.144.224:2783] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.90.144.224 (+1 hits since last alert)|karenbernsteinlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "karenbernsteinlaw.com"] [uri "/xmlrpc.php"] [unique_id "amI8ClSirjeSjGxFtnx6_AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-07-23 15:37:05
(2 days ago)
(xmlrpc) Failed xmlrpc access from 41.90.144.224 (KE/Kenya/-): 5 in the last 3600 secs (0-122)
Hacking