Anonymous
2026-05-13 07:29:03
(3 months ago)
Unauthorized connection attempt on Port 23
Port Scan
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-05-04 11:48:03
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 07:47:54.537550 2026] [security2:error] [pid 8411:tid 8411] [client 49.148.22.200:43836] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.148.22.200 (+1 hits since last alert)|major33.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "major33.com"] [uri "/xmlrpc.php"] [unique_id "afiHaiyXN9teJHtK0jjXywAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-05-03 12:41:59
(4 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
PH/Philippines/dsl.49.148.22.200.pldt.net
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 07:18:07
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 03:17:59.428053 2026] [security2:error] [pid 27780:tid 27791] [client 49.148.22.200:34120] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.148.22.200 (+1 hits since last alert)|inal.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "inal.org"] [uri "/xmlrpc.php"] [unique_id "afb2p6L1lPN12PQyvU2jwwAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-01 12:50:01
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 08:49:55.629542 2026] [security2:error] [pid 2513:tid 2513] [client 49.148.22.200:50301] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.148.22.200 (+1 hits since last alert)|alejandrogorsse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "alejandrogorsse.com"] [uri "/xmlrpc.php"] [unique_id "afShc2t3A5U_nzlohISbhwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-05-01 11:48:29
(4 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-01 11:26:54
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 07:26:50.743152 2026] [security2:error] [pid 29838:tid 29838] [client 49.148.22.200:7918] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.148.22.200 (+1 hits since last alert)|saynotoofland.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "saynotoofland.org"] [uri "/xmlrpc.php"] [unique_id "afSN-hnTZ5Ov3Kz-vLt77wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
knock
2026-05-01 05:21:54
(4 months ago)
Knock-Knock honeypot brute-force: Telnet (4 total hits)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-27 08:15:05
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 04:14:54.488023 2026] [security2:error] [pid 27371:tid 27371] [client 49.148.22.200:16942] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.148.22.200 (+1 hits since last alert)|gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gonzalez.com"] [uri "/xmlrpc.php"] [unique_id "ae8a_mAaXKWnQfrddM8aMAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-04-26 02:00:47
(4 months ago)
(wordpress) Failed wordpress login from 49.148.22.200 (PH/Philippines/dsl.49.148.22.200.pldt.net): ...
show more
(wordpress) Failed wordpress login from 49.148.22.200 (PH/Philippines/dsl.49.148.22.200.pldt.net): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-23 11:52:48
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.148.22.200 (dsl.49.148.22.200.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 23 07:52:40.254008 2026] [security2:error] [pid 28172:tid 28172] [client 49.148.22.200:20479] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.148.22.200 (+1 hits since last alert)|fusteriafontane.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fusteriafontane.com"] [uri "/xmlrpc.php"] [unique_id "aeoICBVjKYPTF_Pbq3rjiQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
NicoID
2026-04-23 00:15:49
(4 months ago)
49.148.22.200 - - [22/Apr/2026:06:31:41 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3234 "-" "WordPress.c ...
show more
49.148.22.200 - - [22/Apr/2026:06:31:41 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3234 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
๐ฉ๐ช
rh24
2026-04-20 09:53:40
(4 months ago)
(wordpress) Failed wordpress login from 49.148.22.200 (PH/Philippines/dsl.49.148.22.200.pldt.net): ...
show more
(wordpress) Failed wordpress login from 49.148.22.200 (PH/Philippines/dsl.49.148.22.200.pldt.net): (CF_ENABLE)
show less
Brute-Force
๐ณ๐ฑ
Site.eu
2026-04-18 08:33:57
(4 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-04-16 13:06:22
(4 months ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (11/60 min)'; Requests=11
Port Scan