Anonymous
2026-07-23 11:32:10
(2 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 11:29:28
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 59.98.121.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 59.98.121.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 07:29:21.152612 2026] [security2:error] [pid 648750:tid 648750] [client 59.98.121.85:53423] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.98.121.85 (+1 hits since last alert)|desertautoworks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "desertautoworks.com"] [uri "/xmlrpc.php"] [unique_id "amH7Eep7ZvwV2A8wlGR7kgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-23 11:08:34
(2 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 10:58:32
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 59.98.121.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 59.98.121.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 06:58:27.366754 2026] [security2:error] [pid 4158247:tid 4158247] [client 59.98.121.85:22662] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.98.121.85 (+1 hits since last alert)|starsmogsandiego.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "starsmogsandiego.com"] [uri "/xmlrpc.php"] [unique_id "amHz08d35byTqHG69TGUPwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 09:54:53
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 59.98.121.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 59.98.121.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:54:48.582606 2026] [security2:error] [pid 2088012:tid 2088012] [client 59.98.121.85:64612] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.98.121.85 (+1 hits since last alert)|centrodentalsindolor.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "centrodentalsindolor.com"] [uri "/xmlrpc.php"] [unique_id "amHk6L6cyX7YQU6nc3XahwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-23 07:19:06
(2 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐ณ๐ฑ
maxxsense
2026-07-23 06:39:35
(2 days ago)
(PERMBLOCK) 59.98.121.85 (IN/India/-) has had more than 4 temp blocks
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-23 06:26:23
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 59.98.121.85 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 59.98.121.85 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 02:26:18.487473 2026] [security2:error] [pid 2406242:tid 2406242] [client 59.98.121.85:12300] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.98.121.85 (+1 hits since last alert)|kadinisi.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kadinisi.org"] [uri "/xmlrpc.php"] [unique_id "amG0ChZuevv9MuCsKL0cUQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
maxxsense
2026-07-23 06:24:20
(2 days ago)
(wordpress) Failed wordpress login from 59.98.121.85 (IN/India/-)
Brute-Force
๐ฉ๐ช
ghostwarriors
2026-07-23 05:50:26
(2 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 05:38:56
(2 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ฌ๐ง
gigatech
2026-07-23 05:30:03
(2 days ago)
Webserver Probing
Web App Attack
Anonymous
2026-05-11 05:30:49
(2 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
Anonymous
2025-04-03 01:16:14
(1 year ago)
Unauthorized connection to Telnet port 23
Port Scan
๐ซ๐ท
security.rdmc.fr
2024-08-03 12:00:43
(1 year ago)
Port Scan Attack proto:TCP src:49930 dst:23
Port Scan