๐บ๐ธ
TPI-Abuse
2026-07-31 10:46:37
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 06:46:31.400466 2026] [security2:error] [pid 418659:tid 418659] [client 5.38.115.56:65154] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.38.115.56 (+1 hits since last alert)|yerevanpress.am|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yerevanpress.am"] [uri "/xmlrpc.php"] [unique_id "amx9B6QvRULJwDGhBw5-ZQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 08:30:39
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 04:30:33.426766 2026] [security2:error] [pid 122982:tid 122982] [client 5.38.115.56:59256] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.38.115.56 (+1 hits since last alert)|texascottagebakers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "texascottagebakers.com"] [uri "/xmlrpc.php"] [unique_id "amxdKTiI3OrlmhUO4CHUYAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 07:28:53
(4 hours ago)
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 03:28:45.221269 2026] [security2:error] [pid 125427:tid 125427] [client 5.38.115.56:59021] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.38.115.56 (+1 hits since last alert)|theamarals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theamarals.com"] [uri "/xmlrpc.php"] [unique_id "amxOrbjhxeQeA191F_05jgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 06:58:58
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 02:58:51.653638 2026] [security2:error] [pid 2534770:tid 2534785] [client 5.38.115.56:27816] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.38.115.56 (+1 hits since last alert)|iancaird.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iancaird.com"] [uri "/xmlrpc.php"] [unique_id "amxHq-uXOcgRYEQsCphoAAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 05:55:30
(6 hours ago)
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 01:55:25.691859 2026] [security2:error] [pid 2049157:tid 2049179] [client 5.38.115.56:52006] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.38.115.56 (+1 hits since last alert)|bortec-corp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bortec-corp.com"] [uri "/xmlrpc.php"] [unique_id "amw4zepnCg756hnWcyL3lwAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-07-31 05:40:05
(6 hours ago)
Web App Attack
๐ซ๐ท
dynamix
2026-07-31 02:28:45
(9 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 00:58:11
(11 hours ago)
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 20:58:04.388266 2026] [security2:error] [pid 3951951:tid 3951982] [client 5.38.115.56:58799] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.38.115.56 (+1 hits since last alert)|gryphix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gryphix.com"] [uri "/xmlrpc.php"] [unique_id "amvzHJqQ8Rn-7X8NInebygAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-07-30 23:48:31
(12 hours ago)
5.054 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ซ๐ฎ
YF
2026-07-30 22:30:23
(13 hours ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-30 22:10:43
(14 hours ago)
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 18:10:39.768570 2026] [security2:error] [pid 444406:tid 444406] [client 5.38.115.56:1033] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.38.115.56 (+1 hits since last alert)|d365geek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "d365geek.com"] [uri "/xmlrpc.php"] [unique_id "amvL32Jg7ipFdzyCZlgcxwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-07-30 18:35:19
(17 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
Anonymous
2026-07-30 18:20:05
(17 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฆ๐บ
rubixstudios
2026-07-30 16:51:02
(19 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 14:32:23
(21 hours ago)
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 5.38.115.56 (gprs-emirnet4882.emirates.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 10:32:16.658097 2026] [security2:error] [pid 1284223:tid 1284223] [client 5.38.115.56:53279] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.38.115.56 (+1 hits since last alert)|forefrontmusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "forefrontmusic.com"] [uri "/xmlrpc.php"] [unique_id "amtgcMA-Mr9pQ6qyXUKxvwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack