๐บ๐ธ
TPI-Abuse
2026-07-28 22:04:13
(49 minutes ago)
(mod_security) mod_security (id:240335) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 18:03:56.677794 2026] [security2:error] [pid 1521675:tid 1521675] [client 49.36.177.145:18721] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.36.177.145 (+1 hits since last alert)|madisonmedia.ai|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "madisonmedia.ai"] [uri "/xmlrpc.php"] [unique_id "amknTJAQ9Ia6Zxxe_D9ZRwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-07-28 20:36:18
(2 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 19:38:40
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 15:38:30.655198 2026] [security2:error] [pid 3550886:tid 3550886] [client 49.36.177.145:29281] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.36.177.145 (+1 hits since last alert)|frogdesignmexico.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "frogdesignmexico.com"] [uri "/xmlrpc.php"] [unique_id "amkFNgGLf3VUVqoYyr_0hAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-07-28 19:24:28
(3 hours ago)
(wordpress) Failed wordpress login from 49.36.177.145 (IN/India/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-28 19:23:26
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 15:23:15.008784 2026] [security2:error] [pid 3664305:tid 3664305] [client 49.36.177.145:45539] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.36.177.145 (+1 hits since last alert)|fishleadership.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fishleadership.org"] [uri "/xmlrpc.php"] [unique_id "amkBo2lIOw6FTzbXFzzBwgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-07-28 18:08:01
(4 hours ago)
(xmlrpc) Failed xmlrpc access from 49.36.177.145 (IN/India/-): 5 in the last 3600 secs (0-122)
Hacking
๐บ๐ธ
WeekendWeb
2026-07-28 17:48:06
(5 hours ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 16:26:38
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 12:26:25.161467 2026] [security2:error] [pid 2594958:tid 2594958] [client 49.36.177.145:56577] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||partnershipsbydesign.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "partnershipsbydesign.net"] [uri "/wp-json/wp/v2/users"] [unique_id "amjYMQAL3Ep8TTeR_7dOPwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 15:10:04
(7 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 13:38:27
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 09:38:13.934097 2026] [security2:error] [pid 27707:tid 27707] [client 49.36.177.145:5025] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.36.177.145 (+1 hits since last alert)|metcomarine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "metcomarine.com"] [uri "/xmlrpc.php"] [unique_id "amiwxQemUd_3yIWpP0GZtQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 11:51:57
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 49.36.177.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 07:51:47.190707 2026] [security2:error] [pid 823248:tid 823248] [client 49.36.177.145:19361] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dwightbrown.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dwightbrown.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amiX08tUqyQfl2fNwnveBwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-07-28 06:01:39
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.36.177.145 (IN/India/-): 5 in the last 300 s ...
show more
(mod_security) mod_security (id:240335) triggered by 49.36.177.145 (IN/India/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-07-28 04:56:29
(17 hours ago)
(xmlrpc) Apache: Failed xmlrpc access from 49.36.177.145 (IN/India/-): 10 in the last 3600 secs (0-2 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 49.36.177.145 (IN/India/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐บ๐ธ
factor1
2026-07-28 02:09:56
(20 hours ago)
Fail2ban at churndash Reports Abuse.
Brute-Force
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-28 00:42:05
(22 hours ago)
49.36.177.145 - - [27/Jul/2026:20:40:08 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5279 "-" "WordPress.c ...
show more
49.36.177.145 - - [27/Jul/2026:20:40:08 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5279 "-" "WordPress.com; https://wordpress.com"
49.36.177.145 - - [27/Jul/2026:20:40:18 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5279 "-" "WordPress.com; https://wordpress.com"
49.36.177.145 - - [27/Jul/2026:20:40:29 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5279 "-" "WordPress.com; https://wordpress.com"
49.36.177.145 - - [27/Jul/2026:20:40:50 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5279 "-" "WordPress.com; https://wordpress.com"
49.36.177.145 - - [27/Jul/2026:20:42:05 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5279 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack