๐ซ๐ท
dynamix
2026-07-23 01:47:52
(4 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
dynamix
2026-07-22 11:35:13
(18 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 11:50:00
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 07:49:55.273167 2026] [security2:error] [pid 11010:tid 11010] [client 49.151.230.91:34683] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.151.230.91 (+1 hits since last alert)|zeetec.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "zeetec.nl"] [uri "/xmlrpc.php"] [unique_id "al4LY1xvxDbpSc9THIwAIgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-20 10:50:43
(2 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 10:45:36
(2 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 08:35:00
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 04:34:56.064401 2026] [security2:error] [pid 5670:tid 5670] [client 49.151.230.91:4171] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.151.230.91 (+1 hits since last alert)|winnindustries.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "winnindustries.com"] [uri "/xmlrpc.php"] [unique_id "al3dsHcClU5OT__c3L9GZAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 08:03:32
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 04:03:27.158501 2026] [security2:error] [pid 11650:tid 11650] [client 49.151.230.91:65478] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.151.230.91 (+1 hits since last alert)|stop902.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "stop902.org"] [uri "/xmlrpc.php"] [unique_id "al3WT-Dxv-ebFfKwjO9d-QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-26 07:42:11
(3 weeks ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-25 10:10:42
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 06:10:33.817610 2026] [security2:error] [pid 23968:tid 23968] [client 49.151.230.91:61988] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.151.230.91 (+1 hits since last alert)|innovacionesnimba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "innovacionesnimba.com"] [uri "/xmlrpc.php"] [unique_id "ajz-mYGpzME8w56yCC5qrAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-25 07:54:14
(3 weeks ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=hacm.gr; logs=/var/log/httpd/domains/hacm.gr.log; samples=/ ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=hacm.gr; logs=/var/log/httpd/domains/hacm.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ฉ๐ช
reznekcs
2026-06-24 16:04:03
(4 weeks ago)
F2B wordpress ban. Logs: 49.151.230.91 - - [24/Jun/2026:18:03:52 +0200] "POST /xmlrpc.php HTTP/1.1" ...
show more
F2B wordpress ban. Logs: 49.151.230.91 - - [24/Jun/2026:18:03:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 458 "-" "Jetpack/12.0; WordPress/6.2; http://site47593246.com"
49.151.230.91 - - [24/Jun/2026:18:04:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 458 "-" "WordPress.com; https://wordpress.com"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 10:58:56
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 06:58:50.912271 2026] [security2:error] [pid 12978:tid 12978] [client 49.151.230.91:44191] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.151.230.91 (+1 hits since last alert)|airdriedrivingschool.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "airdriedrivingschool.com"] [uri "/xmlrpc.php"] [unique_id "aju4arqYtSsD2VpKnyF1QgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 10:28:07
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.151.230.91 (dsl.49.151.230.91.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 06:28:03.672948 2026] [security2:error] [pid 20463:tid 20463] [client 49.151.230.91:22193] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.151.230.91 (+1 hits since last alert)|canebrakes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "canebrakes.com"] [uri "/xmlrpc.php"] [unique_id "ajuxM2_2fQwFHOUPzP3rpwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-24 09:56:25
(4 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ณ๐ฑ
ConsulHosting
2026-06-24 07:07:55
(4 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack