πΊπΈ
TPI-Abuse
2026-08-24 14:39:54
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co ...
show more
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co.th): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 10:39:48.449003 2026] [security2:error] [pid 21957:tid 21957] [client 49.48.43.192:60710] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.48.43.192 (+1 hits since last alert)|pakistanvision.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pakistanvision.com"] [uri "/xmlrpc.php"] [unique_id "aoxXtExtlWpgSuOXzlW4WAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-08-24 14:07:33
(14 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-08-24 12:36:36
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co ...
show more
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co.th): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 08:36:30.629242 2026] [security2:error] [pid 2761:tid 2761] [client 49.48.43.192:64923] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.48.43.192 (+1 hits since last alert)|batesstrategygroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "batesstrategygroup.com"] [uri "/xmlrpc.php"] [unique_id "aow6zl6Sx5XLeerAh-AhjwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 09:15:59
(19 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co ...
show more
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co.th): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 05:15:54.217101 2026] [security2:error] [pid 23205:tid 23205] [client 49.48.43.192:52289] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.48.43.192 (+1 hits since last alert)|newcitypark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "newcitypark.com"] [uri "/xmlrpc.php"] [unique_id "aowLyrvtDEizZw3YBZx6-gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 07:41:50
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co ...
show more
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co.th): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:41:43.543733 2026] [security2:error] [pid 28238:tid 28238] [client 49.48.43.192:50375] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.48.43.192 (+1 hits since last alert)|gpusa-ca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gpusa-ca.com"] [uri "/xmlrpc.php"] [unique_id "aov1t_lauN3NCbIHu930kwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 04:06:45
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co ...
show more
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co.th): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 00:06:37.686477 2026] [security2:error] [pid 1267:tid 1267] [client 49.48.43.192:52800] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.48.43.192 (+1 hits since last alert)|superzilla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "superzilla.com"] [uri "/xmlrpc.php"] [unique_id "aovDTVSygSXdpGzBNn2ezwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 16:58:10
(1 day ago)
(wordpress) Failed wordpress login from 49.48.43.192 (TH/Thailand/Chon Buri/Bang Lamung/mx-ll-49.48. ...
show more
(wordpress) Failed wordpress login from 49.48.43.192 (TH/Thailand/Chon Buri/Bang Lamung/mx-ll-49.48.43-192.dynamic.3bb.co.th/[redacted])
show less
Brute-Force
Anonymous
2026-08-23 16:13:51
(1 day ago)
[redacted] 49.48.43.192 - - [23/Aug/2026:18:13:09 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 49.48.43.192 - - [23/Aug/2026:18:13:09 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.4; http://site96966072.com"
[redacted] 49.48.43.192 - - [23/Aug/2026:18:13:19 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.3; http://site81709814.com"
[redacted] 49.48.43.192 - - [23/Aug/2026:18:13:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 49.48.43.192 - - [23/Aug/2026:18:13:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 49.48.43.192 - - [23/Aug/2026:18:13:51 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
...
show less
Hacking
Web App Attack
π©πͺ
ghostwarriors
2026-08-23 10:20:57
(1 day ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 09:58:59
(1 day ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-08-23 08:58:35
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
πΊπΈ
cwytech
2026-08-23 08:18:28
(1 day ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 10:30:36
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co ...
show more
(mod_security) mod_security (id:240335) triggered by 49.48.43.192 (mx-ll-49.48.43-192.dynamic.3bb.co.th): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:30:26.807368 2026] [security2:error] [pid 23576:tid 23576] [client 49.48.43.192:56937] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.48.43.192 (+1 hits since last alert)|rimaine.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rimaine.org"] [uri "/xmlrpc.php"] [unique_id "aol6QoO2wVyPd8xMyA9CtgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-08-22 10:28:58
(2 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
TH/Thailand/mx-ll-49.48.43-192.dynamic.3bb.co.th
Web App Attack
πΊπΈ
IndigoRidge
2026-08-22 09:48:17
(2 days ago)
49.48.43.192 - - [22/Aug/2026:05:45:25 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5545 "-" "WordPress.co ...
show more
49.48.43.192 - - [22/Aug/2026:05:45:25 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5545 "-" "WordPress.com; https://wordpress.com"
49.48.43.192 - - [22/Aug/2026:05:46:08 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5545 "-" "WordPress.com; https://wordpress.com"
49.48.43.192 - - [22/Aug/2026:05:46:50 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5545 "-" "WordPress.com; https://wordpress.com"
49.48.43.192 - - [22/Aug/2026:05:47:01 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5545 "-" "WordPress.com; https://wordpress.com"
49.48.43.192 - - [22/Aug/2026:05:48:16 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5545 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack