๐บ๐ธ
TPI-Abuse
2026-06-08 13:55:42
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 43.241.66.87 (87.66.241.43-in-addr.arpa-mithril ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.66.87 (87.66.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 09:55:35.738603 2026] [security2:error] [pid 2826:tid 2826] [client 43.241.66.87:28399] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.66.87 (+1 hits since last alert)|deltasouls.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "deltasouls.com"] [uri "/xmlrpc.php"] [unique_id "aibJ13BgRvwPJ194LtrMzAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-06-08 12:47:54
(9 hours ago)
(xmlrpc_405) XMLRPC-Bot 405 43.241.66.87 (IN/India/87.66.241.43-in-addr.arpa-mithriltele.net)
Hacking
๐ฉ๐ช
grassau.com
2026-06-08 10:24:09
(11 hours ago)
(wordpress) Failed wordpress login from 43.241.66.87 (IN/India/Telangana/Hyderabad/87.66.241.43-in-a ...
show more
(wordpress) Failed wordpress login from 43.241.66.87 (IN/India/Telangana/Hyderabad/87.66.241.43-in-addr.arpa-mithriltele.net)
show less
Brute-Force
๐ซ๐ฎ
YF
2026-06-08 10:00:54
(12 hours ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐ซ๐ท
dynamix
2026-06-08 07:38:21
(14 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 06:45:49
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 43.241.66.87 (87.66.241.43-in-addr.arpa-mithril ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.66.87 (87.66.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 02:45:43.776369 2026] [security2:error] [pid 29562:tid 29562] [client 43.241.66.87:29126] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.66.87 (+1 hits since last alert)|webuychesterfieldhouses.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "webuychesterfieldhouses.com"] [uri "/xmlrpc.php"] [unique_id "aiZlF8gzRgz-JObq_vRcwwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 06:08:11
(15 hours ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 04:37:12
(17 hours ago)
(mod_security) mod_security (id:240335) triggered by 43.241.66.87 (87.66.241.43-in-addr.arpa-mithril ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.66.87 (87.66.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 00:37:07.224867 2026] [security2:error] [pid 6157:tid 6259] [client 43.241.66.87:29153] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.66.87 (+1 hits since last alert)|danelandia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "danelandia.com"] [uri "/xmlrpc.php"] [unique_id "aiZG81GveICYieqSmKERfwAAAcw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
maxxsense
2026-03-14 04:39:16
(2 months ago)
(wordpress) Failed wordpress login from 43.241.66.87 (IN/India/87.66.241.43-in-addr.arpa-mithriltele ...
show more
(wordpress) Failed wordpress login from 43.241.66.87 (IN/India/87.66.241.43-in-addr.arpa-mithriltele.net)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-12 11:43:08
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 43.241.66.87 (87.66.241.43-in-addr.arpa-mithril ...
show more
(mod_security) mod_security (id:225170) triggered by 43.241.66.87 (87.66.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 07:43:01.287010 2026] [security2:error] [pid 7939:tid 7939] [client 43.241.66.87:29166] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nuewines.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nuewines.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abKmxemOqpDU2MOKJuGGbAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-12 05:07:02
(2 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฆ๐บ
QT
2026-03-11 13:09:44
(2 months ago)
Unauthorised WordPress admin login attempted at 2026-03-11 23:09:39 +1000
Web App Attack
๐ฉ๐ช
LRob.fr
2026-03-11 09:00:54
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
Anonymous
2026-03-11 04:47:28
(2 months ago)
Fail2ban filtered
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-11 04:43:11
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 43.241.66.87 (87.66.241.43-in-addr.arpa-mithril ...
show more
(mod_security) mod_security (id:225170) triggered by 43.241.66.87 (87.66.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 00:43:03.410495 2026] [security2:error] [pid 28884:tid 28884] [client 43.241.66.87:29209] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newcitypark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newcitypark.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abDy19pMv_RTWcWb0x9DvAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack