🇺🇸
TPI-Abuse
2026-06-07 22:17:02
(7 hours ago)
(mod_security) mod_security (id:240335) triggered by 45.235.16.71 (45-235-16-71.acessoline.net.br): ...
show more
(mod_security) mod_security (id:240335) triggered by 45.235.16.71 (45-235-16-71.acessoline.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 18:16:57.048616 2026] [security2:error] [pid 12233:tid 12233] [client 45.235.16.71:56482] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.235.16.71 (+1 hits since last alert)|texascottagebakers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "texascottagebakers.com"] [uri "/xmlrpc.php"] [unique_id "aiXt2XL3gqRzH7-ICjc7vgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-07 22:00:35
(7 hours ago)
(mod_security) mod_security (id:240335) triggered by 45.235.16.71 (45-235-16-71.acessoline.net.br): ...
show more
(mod_security) mod_security (id:240335) triggered by 45.235.16.71 (45-235-16-71.acessoline.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 18:00:30.475470 2026] [security2:error] [pid 3857:tid 3857] [client 45.235.16.71:57312] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.235.16.71 (+1 hits since last alert)|telecompros.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "telecompros.net"] [uri "/xmlrpc.php"] [unique_id "aiXp_uIPKUFmh11yRuhMggAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-07 13:57:10
(16 hours ago)
Attac
Brute-Force
🇺🇸
lostswordfish.com
2026-06-07 12:36:05
(17 hours ago)
Wordfence waf block on taussigtravel
Web App Attack
🇺🇸
TPI-Abuse
2026-06-07 11:55:53
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 45.235.16.71 (45-235-16-71.acessoline.net.br): ...
show more
(mod_security) mod_security (id:240335) triggered by 45.235.16.71 (45-235-16-71.acessoline.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 07:55:45.485042 2026] [security2:error] [pid 31425:tid 31459] [client 45.235.16.71:57259] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.235.16.71 (+1 hits since last alert)|teritemme.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "teritemme.com"] [uri "/xmlrpc.php"] [unique_id "aiVcQc4Y1xhW0ofYovhvxQAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-06 22:26:14
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 45.235.16.71 (45-235-16-71.acessoline.net.br): ...
show more
(mod_security) mod_security (id:240335) triggered by 45.235.16.71 (45-235-16-71.acessoline.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 18:26:06.706795 2026] [security2:error] [pid 9323:tid 9323] [client 45.235.16.71:56546] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.235.16.71 (+1 hits since last alert)|mobileonlinecasinos.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mobileonlinecasinos.co"] [uri "/xmlrpc.php"] [unique_id "aiSefl_iAIjgfmBxegCPzwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
DZBOT
2026-04-24 09:44:41
(1 month ago)
DZBOT: [MTA] Brute-force users
Brute-Force
🇺🇸
OceanTreasure
2026-03-10 21:45:13
(2 months ago)
tcp/443; WordPress XML-RPC brute force attempt: "POST /xmlrpc.php" @ 2026-03-10T21:43:52Z [proxy]
Brute-Force
🇩🇪
LRob.fr
2026-03-10 20:30:09
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-03-08 20:08:32
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
myagent.site
2026-03-07 22:58:47
(3 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
🇩🇪
big-cloud.nl
2026-03-07 22:44:07
(3 months ago)
Try to access /xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-03-04 01:57:57
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 45.235.16.71 (45-235-16-71.acessoline.net.br): ...
show more
(mod_security) mod_security (id:225170) triggered by 45.235.16.71 (45-235-16-71.acessoline.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 03 20:57:53.215148 2026] [security2:error] [pid 20511:tid 20511] [client 45.235.16.71:54169] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||livingminimal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "livingminimal.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aaeRoYaDN1-9FmnBfPuW9wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob.fr
2026-03-02 00:45:04
(3 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-03-01 18:35:10
(3 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack