๐ง๐ช
cmbplf
2026-07-30 07:28:27
(12 hours ago)
7.957 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ซ๐ท
dynamix
2026-07-30 05:14:17
(14 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-07-30 04:45:09
(14 hours ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 03:55:56
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 61.2.48.209 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 61.2.48.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 23:55:49.020318 2026] [security2:error] [pid 400109:tid 400109] [client 61.2.48.209:59567] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.2.48.209 (+1 hits since last alert)|gaeltv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gaeltv.com"] [uri "/xmlrpc.php"] [unique_id "amrLRSjsq-lVv-Tj2CDjFwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
n2nguyenn2nguyen
2026-07-30 03:22:23
(16 hours ago)
Blocked by YFC Security on https://fencingforward.com โ type: xmlrpc_attempts
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2026-07-30 03:16:13
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 61.2.48.209 (IN/India/-): 5 in the last 300 sec ...
show more
(mod_security) mod_security (id:240335) triggered by 61.2.48.209 (IN/India/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-07-30 02:11:31
(17 hours ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 20:29:22
(23 hours ago)
(mod_security) mod_security (id:240335) triggered by 61.2.48.209 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 61.2.48.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 16:29:16.691907 2026] [security2:error] [pid 322741:tid 322741] [client 61.2.48.209:52020] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.2.48.209 (+1 hits since last alert)|bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bernsteinip.com"] [uri "/xmlrpc.php"] [unique_id "ampinB6h_0IoNj4i18ZdVgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-07-29 16:39:21
(1 day ago)
Fail2ban at churndash Reports Abuse.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 15:27:43
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 61.2.48.209 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 61.2.48.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 11:27:38.947678 2026] [security2:error] [pid 2710493:tid 2710516] [client 61.2.48.209:50132] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.2.48.209 (+1 hits since last alert)|ianajewellery.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ianajewellery.com"] [uri "/xmlrpc.php"] [unique_id "amob6vlTmODk6iF0eQ0w_QAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 15:09:29
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 61.2.48.209 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 61.2.48.209 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 11:09:22.677957 2026] [security2:error] [pid 3914342:tid 3914342] [client 61.2.48.209:61736] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.2.48.209 (+1 hits since last alert)|adona.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "adona.org"] [uri "/xmlrpc.php"] [unique_id "amoXouvFzJrr79E8QlIRuwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack