🇺🇸
kosada.com
2026-08-25 03:59:29
(1 week ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-05-14 13:57:41
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 09:57:34.936751 2026] [security2:error] [pid 3582:tid 3592] [client 49.145.219.123:16689] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.219.123 (+1 hits since last alert)|daraluz.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "daraluz.net"] [uri "/xmlrpc.php"] [unique_id "agXUzn4H_fj_n731eBBEJAAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-05-13 07:56:13
(3 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-13 03:14:32
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 23:14:28.681357 2026] [security2:error] [pid 18251:tid 18251] [client 49.145.219.123:14868] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.219.123 (+1 hits since last alert)|rockinr.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rockinr.org"] [uri "/xmlrpc.php"] [unique_id "agPslDQNgYTvrQw8BH-1wwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-12 15:34:03
(3 months ago)
[redacted] 49.145.219.123 - - [12/May/2026:17:33:21 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 49.145.219.123 - - [12/May/2026:17:33:21 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.4; http://site78665326.com"
[redacted] 49.145.219.123 - - [12/May/2026:17:33:31 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 49.145.219.123 - - [12/May/2026:17:33:41 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 49.145.219.123 - - [12/May/2026:17:33:51 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 49.145.219.123 - - [12/May/2026:17:34:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-05-12 14:35:45
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 10:35:39.328041 2026] [security2:error] [pid 27123:tid 27123] [client 49.145.219.123:13993] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.219.123 (+1 hits since last alert)|michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "michelehoop.com"] [uri "/xmlrpc.php"] [unique_id "agM6u4l_OfoiFHUz7C_lVgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-12 13:24:12
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 09:24:04.126192 2026] [security2:error] [pid 6390:tid 6390] [client 49.145.219.123:16585] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.219.123 (+1 hits since last alert)|eta-mct.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eta-mct.com"] [uri "/xmlrpc.php"] [unique_id "agMp9FFLfxfeMKYrx9JMqgAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-11 09:26:04
(3 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-05-11 08:07:09
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 04:07:02.980953 2026] [security2:error] [pid 22343:tid 22343] [client 49.145.219.123:13340] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.219.123 (+1 hits since last alert)|avalderlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "avalderlaw.com"] [uri "/xmlrpc.php"] [unique_id "agGOJvA5TQbnoyufVZmMOQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-11 00:06:04
(3 months ago)
Trying to access config files
Web App Attack
Anonymous
2026-05-09 13:22:52
(3 months ago)
[redacted] 49.145.219.123 - - [09/May/2026:15:22:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 49.145.219.123 - - [09/May/2026:15:22:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 49.145.219.123 - - [09/May/2026:15:22:18 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
[redacted] 49.145.219.123 - - [09/May/2026:15:22:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
[redacted] 49.145.219.123 - - [09/May/2026:15:22:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 49.145.219.123 - - [09/May/2026:15:22:51 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.3; http://site71709527.com"
...
show less
Hacking
Web App Attack
🇺🇸
jya
2026-05-08 12:42:00
(3 months ago)
Failed WordPress log-in attempts.
Hacking
🇬🇧
Apache
2026-05-07 14:51:57
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (PH/Philippines/dsl.49.145.219.1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (PH/Philippines/dsl.49.145.219.123.pldt.net): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-06 05:49:07
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 01:48:59.841919 2026] [security2:error] [pid 21293:tid 21293] [client 49.145.219.123:15904] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.219.123 (+1 hits since last alert)|theamarals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theamarals.com"] [uri "/xmlrpc.php"] [unique_id "afrWS4VhEuBus_TPJ_jt9AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-05 13:22:33
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.219.123 (dsl.49.145.219.123.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 05 09:22:30.241840 2026] [security2:error] [pid 17426:tid 17426] [client 49.145.219.123:17268] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.219.123 (+1 hits since last alert)|marianozaro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "marianozaro.com"] [uri "/xmlrpc.php"] [unique_id "afnvFr6ycl-I6NH_8OVMYAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack