๐บ๐ธ
TPI-Abuse
2026-08-01 18:04:56
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 14:04:52.032286 2026] [security2:error] [pid 565830:tid 565830] [client 49.207.145.223:2285] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.207.145.223 (+1 hits since last alert)|fusionrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fusionrep.com"] [uri "/xmlrpc.php"] [unique_id "am41RN6lcEgQQHmLbhKJ4gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 17:33:42
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 13:33:34.750451 2026] [security2:error] [pid 205332:tid 205332] [client 49.207.145.223:1818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.207.145.223 (+1 hits since last alert)|convtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "convtek.com"] [uri "/xmlrpc.php"] [unique_id "am4t7q_6mhDOVLANd-XJIgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-31 17:22:10
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
dynamix
2026-07-31 15:18:39
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-28 16:30:51
(4 days ago)
(wordpress) Failed wordpress login from 49.207.145.223 (IN/India/49.207.145.223.actcorp.in)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 18:10:46
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:10:40.019252 2026] [security2:error] [pid 357491:tid 357491] [client 49.207.145.223:2378] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.207.145.223 (+1 hits since last alert)|high5-vr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "high5-vr.com"] [uri "/xmlrpc.php"] [unique_id "amefIMSmlD4k7-5d7DSfeAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 16:46:47
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 12:46:38.390951 2026] [security2:error] [pid 3716154:tid 3716154] [client 49.207.145.223:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.207.145.223 (+1 hits since last alert)|avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "avaliantlife.com"] [uri "/xmlrpc.php"] [unique_id "ameLbr2X3KIvk5e0w58FAgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-07-27 16:16:26
(5 days ago)
(wordpress) Failed wordpress login from 49.207.145.223 (IN/India/49.207.145.223.actcorp.in)
Brute-Force
๐ณ๐ฑ
Site.eu
2026-07-27 15:14:11
(5 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
LRob
2026-07-27 15:12:43
(5 days ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.co ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.com
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 15:21:09
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 11:21:02.219772 2026] [security2:error] [pid 2922025:tid 2922025] [client 49.207.145.223:2898] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.207.145.223 (+1 hits since last alert)|solporpoise.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solporpoise.com"] [uri "/xmlrpc.php"] [unique_id "amYl3nfDg_zwp_fTbA39nQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-25 17:06:34
(1 week ago)
49.207.145.223 - - [25/Jul/2026:13:04:56 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5539 "-" "WordPress. ...
show more
49.207.145.223 - - [25/Jul/2026:13:04:56 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5539 "-" "WordPress.com; https://wordpress.com"
49.207.145.223 - - [25/Jul/2026:13:05:06 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5539 "-" "WordPress.com; https://wordpress.com"
49.207.145.223 - - [25/Jul/2026:13:05:17 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5539 "-" "WordPress.com; https://wordpress.com"
49.207.145.223 - - [25/Jul/2026:13:06:23 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5539 "-" "WordPress.com; https://wordpress.com"
49.207.145.223 - - [25/Jul/2026:13:06:33 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5539 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
Anonymous
2026-07-21 18:06:04
(1 week ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 17:47:05
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.207.145.223 (49.207.145.223.actcorp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 13:46:57.773632 2026] [security2:error] [pid 7698:tid 7698] [client 49.207.145.223:2927] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.207.145.223 (+1 hits since last alert)|celltechs.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "celltechs.net"] [uri "/xmlrpc.php"] [unique_id "al-wkba-CQXsFIcUp92g0gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-20 17:20:43
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack