๐บ๐ธ
TPI-Abuse
2026-06-28 11:32:13
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 46.36.75.138 (ip-75-138.rev.kli.lt): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 46.36.75.138 (ip-75-138.rev.kli.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 07:32:06.404433 2026] [security2:error] [pid 11954:tid 11954] [client 46.36.75.138:53937] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.36.75.138 (+1 hits since last alert)|integrabroadcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "integrabroadcast.com"] [uri "/xmlrpc.php"] [unique_id "akEGNhm5zZAqX4LMujnYTAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Mario Bretscher
2026-06-28 09:19:12
(12 hours ago)
Jun 28 11:18:56 beat-band.ch Cerber(beat-band.ch)[401221]: Authentication failure for beat-band from ...
show more
Jun 28 11:18:56 beat-band.ch Cerber(beat-band.ch)[401221]: Authentication failure for beat-band from 46.36.75.138
Jun 28 11:19:10 beat-band.ch Cerber(beat-band.ch)[402707]: Authentication failure for beat-band from 46.36.75.138
...
show less
Web Spam
๐บ๐ธ
Jason Howell
2026-06-28 04:48:22
(16 hours ago)
46.36.75.138 - - [27/Jun/2026:23:21:40 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4761 "-" "Jetpack/12.5 ...
show more
46.36.75.138 - - [27/Jun/2026:23:21:40 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4761 "-" "Jetpack/12.5; WordPress/6.4; http://site53350617.com"
46.36.75.138 - - [27/Jun/2026:23:25:00 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4762 "-" "Jetpack by WordPress.com"
46.36.75.138 - - [27/Jun/2026:23:29:23 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4762 "-" "Jetpack/13.0; WordPress/6.4; http://site61790996.com"
46.36.75.138 - - [27/Jun/2026:23:35:37 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4761 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
46.36.75.138 - - [27/Jun/2026:23:48:22 -0500] "POST /xmlrpc.php HTTP/1.1" 200 4760 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 16:04:10
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 46.36.75.138 (ip-75-138.rev.kli.lt): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 46.36.75.138 (ip-75-138.rev.kli.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 12:04:04.412908 2026] [security2:error] [pid 21491:tid 21491] [client 46.36.75.138:52810] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.36.75.138 (+1 hits since last alert)|nessmonsters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nessmonsters.com"] [uri "/xmlrpc.php"] [unique_id "aj_0dIU77stxQLCceCPKewAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 15:31:06
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 46.36.75.138 (ip-75-138.rev.kli.lt): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 46.36.75.138 (ip-75-138.rev.kli.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 11:30:59.379120 2026] [security2:error] [pid 30160:tid 30160] [client 46.36.75.138:55743] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.36.75.138 (+1 hits since last alert)|directcch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "directcch.com"] [uri "/xmlrpc.php"] [unique_id "aj_ss1jx_4yZZUKJoou5NAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-27 14:57:32
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
LT/Republic of Lithuania/ip-75-138.rev.kli.lt
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 15:41:19
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 46.36.75.138 (ip-75-138.rev.kli.lt): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 46.36.75.138 (ip-75-138.rev.kli.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 11:41:15.941484 2026] [security2:error] [pid 20747:tid 20747] [client 46.36.75.138:52252] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.36.75.138 (+1 hits since last alert)|jonasrimkunas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jonasrimkunas.com"] [uri "/xmlrpc.php"] [unique_id "aj6dm-Cl_GqrdYu76YwR7wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 13:08:01
(2 weeks ago)
46.36.75.138 - - [14/Jun/2026:15:07:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com ...
show more
46.36.75.138 - - [14/Jun/2026:15:07:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com; https://wordpress.com"
46.36.75.138 - - [14/Jun/2026:15:07:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 798 "-" "WordPress.com; https://wordpress.com"
46.36.75.138 - - [14/Jun/2026:15:07:48 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com; https://wordpress.com"
46.36.75.138 - - [14/Jun/2026:15:07:47 +0200] "POST /xmlrpc.php HTTP/1.1" 200 798 "-" "WordPress.com; https://wordpress.com"
46.36.75.138 - - [14/Jun/2026:15:07:59 +0200] "POST /xmlrpc.php HTTP/1.1" 200 798 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-14 08:39:08
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-06-14 06:39:19
(2 weeks ago)
3.525 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ซ๐ท
Lunix
2026-06-13 12:52:12
(2 weeks ago)
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-06-12 03:26:21
(2 weeks ago)
Hacking
Exploited Host
Web App Attack
๐ฆ๐น
neo72
2026-03-15 10:54:26
(3 months ago)
Detected malicious activity - bulk block
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 18:46:13
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 46.36.75.138 (ip-75-138.rev.kli.lt): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 46.36.75.138 (ip-75-138.rev.kli.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 14:46:08.344406 2026] [security2:error] [pid 21732:tid 21732] [client 46.36.75.138:58509] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||citrineartstudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "citrineartstudio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abWs8DMgt_skEDjWA7yz8gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack