๐ฉ๐ช
BlueWire Hosting
2026-08-25 09:04:07
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-25 07:08:56
(1 day ago)
cloudlinux2 fail2ban: 2026-08-25 09:04:24,755 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-25 09:04:24,755 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 59.98.5.66 - 2026-08-25 09:04:24cloudlinux2 fail2ban: 2026-08-25 09:04:21,753 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 106.198.26.146 - 2026-08-25 09:04:21cloudlinux2 fail2ban: 2026-08-25 09:04:40,296 fail2ban.actions [1464]: NOTICE [plesk-modsecurity] Unban 14.96.134.82cloudlinux2 fail2ban: 2026-08-25 09:05:10,588 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.83.169 - 2026-08-25 09:05:10cloudlinux2 fail2ban: 2026-08-25 09:05:13,555 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.7.77 - 2026-08-25 09:05:13cloudlinux2 fail2ban: 2026-08-25 09:05:09,432 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 195.63.26.196 - 2026-08-25 09:05:09cloudlinux2 fail2ban: 2026-08-25 09:05:15,023 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.71.181 - 2026-08-25 09:05:14cloudlinux2 fail2ban: 2026
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 07:03:44
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 59.98.5.66 (static.bb.rch.59.98.5.66.bsnl.in): ...
show more
(mod_security) mod_security (id:240335) triggered by 59.98.5.66 (static.bb.rch.59.98.5.66.bsnl.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 03:03:41.083537 2026] [security2:error] [pid 31293:tid 31293] [client 59.98.5.66:58109] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.98.5.66 (+1 hits since last alert)|targetbinario.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "targetbinario.com"] [uri "/xmlrpc.php"] [unique_id "ao0-TXCuv4aaS2WmkHsOXwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-08-24 11:27:38
(1 day ago)
59.98.5.66 - - [24/Aug/2026:07:25:07 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; ...
show more
59.98.5.66 - - [24/Aug/2026:07:25:07 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
59.98.5.66 - - [24/Aug/2026:07:25:18 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
59.98.5.66 - - [24/Aug/2026:07:25:52 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
59.98.5.66 - - [24/Aug/2026:07:26:34 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
59.98.5.66 - - [24/Aug/2026:07:27:38 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-24 10:52:07
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 10:36:38
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 59.98.5.66 (static.bb.rch.59.98.5.66.bsnl.in): ...
show more
(mod_security) mod_security (id:240335) triggered by 59.98.5.66 (static.bb.rch.59.98.5.66.bsnl.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 06:36:34.570366 2026] [security2:error] [pid 15914:tid 15914] [client 59.98.5.66:60985] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.98.5.66 (+1 hits since last alert)|furbabieslivesmatter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "furbabieslivesmatter.com"] [uri "/xmlrpc.php"] [unique_id "aowesvpmtxiQJylGBcTu7gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 09:54:14
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 59.98.5.66 (static.bb.rch.59.98.5.66.bsnl.in): ...
show more
(mod_security) mod_security (id:240335) triggered by 59.98.5.66 (static.bb.rch.59.98.5.66.bsnl.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 05:54:07.411620 2026] [security2:error] [pid 19094:tid 19094] [client 59.98.5.66:58088] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.98.5.66 (+1 hits since last alert)|arriagarealestate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "arriagarealestate.com"] [uri "/xmlrpc.php"] [unique_id "aowUvwJvHteWYRyuI-tUSQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 05:50:25
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 59.98.5.66 (static.bb.rch.59.98.5.66.bsnl.in): ...
show more
(mod_security) mod_security (id:240335) triggered by 59.98.5.66 (static.bb.rch.59.98.5.66.bsnl.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 01:50:21.438577 2026] [security2:error] [pid 25635:tid 25708] [client 59.98.5.66:63992] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.98.5.66 (+1 hits since last alert)|trulyoriginalpurpleoctopus.art|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "trulyoriginalpurpleoctopus.art"] [uri "/xmlrpc.php"] [unique_id "aovbnYo8keoO3L2j-a8ffwAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-24 05:16:08
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-08-11 10:11:03
(2 weeks ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-11 09:25:52
(2 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-08-11 09:20:35
(2 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 10:14:47
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 59.98.5.66 (static.bb.rch.59.98.5.66.bsnl.in): ...
show more
(mod_security) mod_security (id:240335) triggered by 59.98.5.66 (static.bb.rch.59.98.5.66.bsnl.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 06:14:38.433989 2026] [security2:error] [pid 1630242:tid 1630242] [client 59.98.5.66:56109] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.98.5.66 (+1 hits since last alert)|drbolen.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "drbolen.com"] [uri "/xmlrpc.php"] [unique_id "amcvjuftHWX6GDysQdKvdgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-24 05:50:56
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 05:41:42
(1 month ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack