๐บ๐ธ
TPI-Abuse
2026-06-30 18:37:41
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 5.206.29.66 (pool-5-206-29-66.is74.ru): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 5.206.29.66 (pool-5-206-29-66.is74.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 14:37:34.189117 2026] [security2:error] [pid 31632:tid 31632] [client 5.206.29.66:56673] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.206.29.66 (+1 hits since last alert)|roguetechscene.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "roguetechscene.com"] [uri "/xmlrpc.php"] [unique_id "akQM7k5itDPYB641AyqHLQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-30 17:12:33
(18 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-06-30 14:38:10
(20 hours ago)
Attac
Brute-Force
๐ซ๐ท
masterguru
2026-06-30 10:05:06
(1 day ago)
(xmlrpc) Apache: Failed xmlrpc access from 5.206.29.66 (RU/Russia/pool-5-206-29-66.is74.ru): 10 in t ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 5.206.29.66 (RU/Russia/pool-5-206-29-66.is74.ru): 10 in the last 3600 secs (0-201)
show less
Hacking
๐ฆ๐บ
QT
2026-06-29 16:15:27
(1 day ago)
Unauthorised WordPress admin login attempted at 2026-06-30 02:15:26 +1000
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-29 16:01:44
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
dynamix
2026-06-29 16:00:32
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฆ๐บ
QT
2026-06-29 16:00:25
(1 day ago)
Unauthorised WordPress admin login attempted at 2026-06-30 02:00:24 +1000
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-28 21:01:33
(2 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
RU/Russia/pool-5-206-29-66.is74.ru
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 19:21:32
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 5.206.29.66 (pool-5-206-29-66.is74.ru): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 5.206.29.66 (pool-5-206-29-66.is74.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 15:21:24.500083 2026] [security2:error] [pid 24351:tid 24351] [client 5.206.29.66:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.206.29.66 (+1 hits since last alert)|local639.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "local639.com"] [uri "/xmlrpc.php"] [unique_id "akF0NNTMmwRp6hMFi5aGZQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-06-27 00:51:26
(4 days ago)
(wordpress) Failed wordpress login from 5.206.29.66 (RU/Russia/pool-5-206-29-66.is74.ru)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-26 23:23:16
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 5.206.29.66 (pool-5-206-29-66.is74.ru): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 5.206.29.66 (pool-5-206-29-66.is74.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 19:23:09.063222 2026] [security2:error] [pid 591:tid 591] [client 5.206.29.66:58610] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.206.29.66 (+1 hits since last alert)|littlecreekrvranch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "littlecreekrvranch.com"] [uri "/xmlrpc.php"] [unique_id "aj8J3XvRJwM02Jhr1KRMYQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 22:49:34
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 5.206.29.66 (pool-5-206-29-66.is74.ru): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 5.206.29.66 (pool-5-206-29-66.is74.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 18:49:28.733391 2026] [security2:error] [pid 32415:tid 32415] [client 5.206.29.66:63536] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.206.29.66 (+1 hits since last alert)|apuntesdeinversion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "apuntesdeinversion.com"] [uri "/xmlrpc.php"] [unique_id "aj8B-BZWguEzEuFCMOkudgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-26 20:45:50
(4 days ago)
Fail2ban filtered
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 16:43:58
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 5.206.29.66 (pool-5-206-29-66.is74.ru): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 5.206.29.66 (pool-5-206-29-66.is74.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 12:43:51.438023 2026] [security2:error] [pid 32394:tid 32394] [client 5.206.29.66:60125] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.206.29.66 (+1 hits since last alert)|j3pr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "j3pr.com"] [uri "/xmlrpc.php"] [unique_id "aj6sR7_mc2Itwg9pYe74uQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack