๐จ๐ฆ
Dolphi
2026-05-10 12:30:02
(4 months ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 12:23:56
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 49.204.164.100 (49.204.164.100.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.204.164.100 (49.204.164.100.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 08:23:53.232417 2026] [security2:error] [pid 31186:tid 31206] [client 49.204.164.100:25101] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.204.164.100 (+1 hits since last alert)|duplexgoldmine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "duplexgoldmine.com"] [uri "/xmlrpc.php"] [unique_id "agB42bUPL0-lSfGxePrFtAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 11:52:30
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 49.204.164.100 (49.204.164.100.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.204.164.100 (49.204.164.100.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 07:52:24.109422 2026] [security2:error] [pid 5492:tid 5492] [client 49.204.164.100:24142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.204.164.100 (+1 hits since last alert)|fractalsky.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fractalsky.com"] [uri "/xmlrpc.php"] [unique_id "agBxeDy4k9-vn5FTFnjcbQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 08:37:50
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 49.204.164.100 (49.204.164.100.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.204.164.100 (49.204.164.100.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 04:37:41.326461 2026] [security2:error] [pid 5378:tid 5378] [client 49.204.164.100:24097] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.204.164.100 (+1 hits since last alert)|citrineartstudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "citrineartstudio.com"] [uri "/xmlrpc.php"] [unique_id "agBD1RUq1HTpW969Vn9JsAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-10 06:32:55
(4 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-05-10 03:09:39
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 49.204.164.100 (49.204.164.100.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 49.204.164.100 (49.204.164.100.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 23:09:33.591703 2026] [security2:error] [pid 5469:tid 5469] [client 49.204.164.100:25167] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||legacy-insight.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "legacy-insight.com"] [uri "/wp-json/wp/v2/users"] [unique_id "af_27dzo9EThm_mq215sdgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 17:32:58
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 49.204.164.100 (49.204.164.100.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.204.164.100 (49.204.164.100.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 13:32:49.849311 2026] [security2:error] [pid 7577:tid 7577] [client 49.204.164.100:24067] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.204.164.100 (+1 hits since last alert)|market1st.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "market1st.com"] [uri "/xmlrpc.php"] [unique_id "af9vwTypw-YygZkmPfiNmwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-04 16:02:20
(4 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
yvoictra
2026-04-24 12:00:46
(4 months ago)
49.204.164.100 - - [24/Apr/2026:13:59:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack/12. ...
show more
49.204.164.100 - - [24/Apr/2026:13:59:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack/12.1; WordPress/6.1; http://site46341349.com"
49.204.164.100 - - [24/Apr/2026:13:59:53 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "WordPress.com; https://wordpress.com"
49.204.164.100 - - [24/Apr/2026:14:00:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack/12.0; WordPress/6.4; http://site75801317.com"
49.204.164.100 - - [24/Apr/2026:14:00:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
49.204.164.100 - - [24/Apr/2026:14:00:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "WordPress.com; https://wordpress.com"
49.204.164.100 - - [24/Apr/2026:14:00:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack/12.1; WordPress/6.2; http://site74888140.com"
...
show less
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-04-24 05:57:06
(4 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-24 00:30:24
(4 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
WeekendWeb
2026-04-18 09:46:09
(4 months ago)
Wordpress Vunerability attack
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-04-17 21:57:41
(4 months ago)
Unauthorized access to webpage admin
Web App Attack
๐ฉ๐ช
LRob
2026-04-16 15:45:06
(4 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ซ๐ท
polido
2026-04-14 22:05:18
(4 months ago)
Unauthorized connection attempt to port 443 from 49.204.164.100
Port Scan