๐บ๐ธ
TPI-Abuse
2026-05-16 23:32:50
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 64.49.38.57 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 64.49.38.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 19:32:41.724588 2026] [security2:error] [pid 7109:tid 7109] [client 64.49.38.57:54933] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Ashton II Recliner/Havana Brown/Thumbs.db"] [unique_id "agj-mbhOhS6EOw5YGIuG0gAAAA4"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Ashton%20II%20Recliner/Havana%20Brown/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-16 09:17:02
(2 weeks ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-13 20:43:15
(3 weeks ago)
(mod_security) mod_security (id:211030) triggered by 64.49.38.57 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:211030) triggered by 64.49.38.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 16:43:05.742876 2026] [security2:error] [pid 9814:tid 9814] [client 64.49.38.57:9373] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at ARGS. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "17"] [id "211030"] [rev "3"] [msg "COMODO WAF: LDAP Injection Attack||www.genesis-castle.com|F|2"] [data "Matched Data: (%'%~%'%|%|%( found within ARGS: 0"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "www.genesis-castle.com"] [uri "/gallery/index.php"] [unique_id "agTiWegfvCSrktscIa7m5AAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-04-09 05:24:11
(1 month ago)
1.000 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
[email protected]
2026-03-26 11:04:20
(2 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-03-26T11:04:19Z
Brute-Force
๐บ๐ธ
[email protected]
2026-03-26 10:48:22
(2 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-03-26T10:48:22Z
Brute-Force
๐บ๐ธ
[email protected]
2026-03-26 10:03:46
(2 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-03-26T10:03:46Z
Brute-Force
๐ช๐ธ
el-brujo
2026-03-24 13:45:59
(2 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: AppleWe ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: AppleWebKit/535.35 (KHTML, like Gecko111) Action: managed_challenge Source: firewallManaged ASN Description: PUREVOLTAGE-INC - PureVoltage Hosting Inc. Country: US Method: POST Timestamp: 2026-03-24T13:45:59Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ช๐ธ
el-brujo
2026-03-24 13:39:51
(2 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:145.0) Gecko/20100101 Firefox/145.0 Action: managed_challenge Source: firewallManaged ASN Description: PUREVOLTAGE-INC - PureVoltage Hosting Inc. Country: US Method: POST Timestamp: 2026-03-24T13:39:51Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-03-20 14:33:53
(2 months ago)
XML RPC Scan Activities: "2026-03-20T21:33:53.693+07:00" "/xmlrpc.php" "64.49.38.57" "Chrome/92.2 Sa ...
show more
XML RPC Scan Activities: "2026-03-20T21:33:53.693+07:00" "/xmlrpc.php" "64.49.38.57" "Chrome/92.2 Safari/532.52"
show less
Web App Attack
Brute-Force
๐ฉ๐ช
MusicLibrary
2026-03-16 04:00:55
(2 months ago)
Attempted access to non existent wordpress urls
Bad Web Bot
๐ช๐ธ
el-brujo
2026-03-15 20:02:44
(2 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Chrome/ ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Chrome/97.7 Safari/537.57 Action: managed_challenge Source: firewallManaged ASN Description: PUREVOLTAGE-INC - PureVoltage Hosting Inc. Country: US Method: GET Timestamp: 2026-03-15T20:02:44Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
Anonymous
2026-03-15 10:36:43
(2 months ago)
"GET /xmlrpc.php HTTP/1.1"
Hacking
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-03-14 10:21:55
(2 months ago)
XML RPC Scan Activities: "2026-03-14T17:21:55.782+07:00" "/xmlrpc.php" "64.49.38.57" "Mozilla/5.0 (M ...
show more
XML RPC Scan Activities: "2026-03-14T17:21:55.782+07:00" "/xmlrpc.php" "64.49.38.57" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:145.0) Gecko/20100101 Firefox/145.0"
show less
Web App Attack
Brute-Force
๐ง๐ช
voormedia
2026-03-09 12:39:47
(2 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack