๐บ๐ธ
WeekendWeb
2026-07-26 17:53:24
(1 hour ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TAY
2026-07-26 17:53:19
(1 hour ago)
49.228.41.99 - - [27/Jul/2026:01:52:57 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "Jetpack by W ...
show more
49.228.41.99 - - [27/Jul/2026:01:52:57 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "Jetpack by WordPress.com"
49.228.41.99 - - [27/Jul/2026:01:53:08 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "Jetpack by WordPress.com"
49.228.41.99 - - [27/Jul/2026:01:53:18 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
๐บ๐ธ
integrantservices.com
2026-07-26 15:28:11
(4 hours ago)
(wordpress) Failed wordpress login from 49.228.41.99 (TH/Thailand/49-228-41-0.24.nat.sila1-cgn02.mya ...
show more
(wordpress) Failed wordpress login from 49.228.41.99 (TH/Thailand/49-228-41-0.24.nat.sila1-cgn02.myaisfibre.com)
show less
Brute-Force
๐ฉ๐ช
ghostwarriors
2026-07-26 14:20:25
(5 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-26 14:13:43
(5 hours ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-26 13:01:02
(6 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 08:46:59
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.my ...
show more
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.myaisfibre.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 04:46:53.330266 2026] [security2:error] [pid 2267297:tid 2267297] [client 49.228.41.99:1725] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.228.41.99 (+1 hits since last alert)|theamarals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theamarals.com"] [uri "/xmlrpc.php"] [unique_id "amXJfWY37AXE3JrSWHKveAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
akasolutions.de
2026-07-26 08:01:43
(11 hours ago)
(wordpress) Failed wordpress login from 49.228.41.99 (TH/Thailand/49-228-41-0.24.nat.sila1-cgn02.mya ...
show more
(wordpress) Failed wordpress login from 49.228.41.99 (TH/Thailand/49-228-41-0.24.nat.sila1-cgn02.myaisfibre.com)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-26 03:25:21
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.my ...
show more
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.myaisfibre.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 23:25:15.353935 2026] [security2:error] [pid 1052038:tid 1052038] [client 49.228.41.99:54266] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.228.41.99 (+1 hits since last alert)|mikedeutsch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mikedeutsch.com"] [uri "/xmlrpc.php"] [unique_id "amV-G7BK6k6EJBCTZTybVQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-25 23:32:05
(20 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 21:05:31
(22 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.my ...
show more
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.myaisfibre.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 17:05:27.558534 2026] [security2:error] [pid 2185991:tid 2185991] [client 49.228.41.99:44505] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.228.41.99 (+1 hits since last alert)|clockandnightlight.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "clockandnightlight.com"] [uri "/xmlrpc.php"] [unique_id "amUlFw2FnA3sz5-szf1G5QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 20:05:04
(23 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.my ...
show more
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.myaisfibre.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 16:04:54.417693 2026] [security2:error] [pid 601089:tid 601089] [client 49.228.41.99:36263] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.228.41.99 (+1 hits since last alert)|odysseydogasporlari.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "odysseydogasporlari.com"] [uri "/xmlrpc.php"] [unique_id "amUW5qw_PquVAtLwVOP9VwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 17:30:38
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.my ...
show more
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.myaisfibre.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 13:30:32.561666 2026] [security2:error] [pid 31085:tid 31206] [client 49.228.41.99:5199] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.228.41.99 (+1 hits since last alert)|maroontribe.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "maroontribe.com"] [uri "/xmlrpc.php"] [unique_id "amTyuM2nPQxQaa_B_aHGPwAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-07-25 17:00:37
(1 day ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-25 15:56:12
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.my ...
show more
(mod_security) mod_security (id:240335) triggered by 49.228.41.99 (49-228-41-0.24.nat.sila1-cgn02.myaisfibre.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 11:56:07.772955 2026] [security2:error] [pid 2748592:tid 2748592] [client 49.228.41.99:37206] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.228.41.99 (+1 hits since last alert)|denkyusalesca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "denkyusalesca.com"] [uri "/xmlrpc.php"] [unique_id "amTclyhtKPIGoUV6sM-zgQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack