๐บ๐ธ
TPI-Abuse
2026-06-04 14:26:20
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 49.43.133.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.43.133.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 10:26:09.348050 2026] [security2:error] [pid 22962:tid 22962] [client 49.43.133.164:55613] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.43.133.164 (+1 hits since last alert)|briannalls.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "briannalls.com"] [uri "/xmlrpc.php"] [unique_id "aiGLAWTD-P2C9z8CBz0ZhwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 06:03:54
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 49.43.133.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.43.133.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 02:03:43.429702 2026] [security2:error] [pid 19766:tid 19766] [client 49.43.133.164:52985] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.43.133.164 (+1 hits since last alert)|honigcpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "honigcpa.com"] [uri "/xmlrpc.php"] [unique_id "aiEVP1iEw1NFjys05JErxgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 05:15:25
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 49.43.133.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.43.133.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 01:15:11.481295 2026] [security2:error] [pid 28760:tid 28867] [client 49.43.133.164:55746] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.43.133.164 (+1 hits since last alert)|whatismetamodern.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whatismetamodern.com"] [uri "/xmlrpc.php"] [unique_id "aiEJ30hvfmd5W_VLWGcAFQAAAhE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Martin Lundstrom
2026-06-04 04:18:59
(4 days ago)
https://www.eagleeye-intelligence.com โ WordPress attack. Automatically detected and blocked.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 12:43:25
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 49.43.133.164 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 49.43.133.164 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 08:43:12.230336 2026] [security2:error] [pid 10633:tid 10633] [client 49.43.133.164:54984] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||market1st.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "market1st.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiAhYIEVSdsS1CQSDT4SPAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 10:49:45
(5 days ago)
[redacted] 49.43.133.164 - - [03/Jun/2026:12:49:03 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "J ...
show more
[redacted] 49.43.133.164 - - [03/Jun/2026:12:49:03 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack/12.1; WordPress/6.2; http://site34510621.com"
[redacted] 49.43.133.164 - - [03/Jun/2026:12:49:13 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "WordPress.com; https://wordpress.com"
[redacted] 49.43.133.164 - - [03/Jun/2026:12:49:24 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "WordPress.com; https://wordpress.com"
[redacted] 49.43.133.164 - - [03/Jun/2026:12:49:34 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
[redacted] 49.43.133.164 - - [03/Jun/2026:12:49:44 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack/12.1; WordPress/6.2; http://site69029733.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-02 14:41:29
(5 days ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=inoxal.gr; logs=/var/log/httpd/domains/inoxal.gr.log; sample ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=inoxal.gr; logs=/var/log/httpd/domains/inoxal.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-02 14:40:33
(5 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 49.43.133.164 (IN/India/-): 10 in the last 3600 secs (0-2 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 49.43.133.164 (IN/India/-): 10 in the last 3600 secs (0-201)
show less
Hacking
Anonymous
2026-06-02 14:26:26
(5 days ago)
Attac
Brute-Force
Anonymous
2026-06-02 09:02:18
(6 days ago)
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2026-06-02 06:04:28
(6 days ago)
49.43.133.164 - - [02/Jun/2026:00:55:56 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3371 "-" "Jetpack by ...
show more
49.43.133.164 - - [02/Jun/2026:00:55:56 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3371 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
49.43.133.164 - - [02/Jun/2026:00:58:05 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3371 "-" "WordPress.com; https://wordpress.com"
49.43.133.164 - - [02/Jun/2026:01:00:13 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3372 "-" "Jetpack by WordPress.com"
49.43.133.164 - - [02/Jun/2026:01:02:20 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3371 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
49.43.133.164 - - [02/Jun/2026:01:04:27 -0500] "POST /xmlrpc.php HTTP/1.1" 200 3372 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
...
show less
Web App Attack
๐ฉ๐ช
konseptit
2026-06-01 14:16:56
(6 days ago)
(wordpress) Failed wordpress login from 49.43.133.164 (IN/India/-)
Brute-Force
Anonymous
2026-06-01 13:38:26
(1 week ago)
Attac
Brute-Force
Anonymous
2026-06-01 08:31:35
(1 week ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (149/60 min)'; Requests=149
Port Scan
Anonymous
2026-05-31 03:22:21
(1 week ago)
[redacted] 49.43.133.164 - - [31/May/2026:05:21:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 49.43.133.164 - - [31/May/2026:05:21:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
[redacted] 49.43.133.164 - - [31/May/2026:05:21:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 49.43.133.164 - - [31/May/2026:05:21:56 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
[redacted] 49.43.133.164 - - [31/May/2026:05:22:07 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.3; http://site73851144.com"
[redacted] 49.43.133.164 - - [31/May/2026:05:22:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.1; http://site28302151.com"
...
show less
Hacking
Web App Attack