๐ซ๐ท
dynamix
2026-07-20 22:48:39
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 01:30:27
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 66.9.161.101 (customer.bgtacol1.isp.starlink.co ...
show more
(mod_security) mod_security (id:240335) triggered by 66.9.161.101 (customer.bgtacol1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 21:30:23.801249 2026] [security2:error] [pid 26847:tid 26847] [client 66.9.161.101:57923] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 66.9.161.101 (+1 hits since last alert)|savingspools.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "savingspools.com"] [uri "/xmlrpc.php"] [unique_id "al16L-DqOH1cGZ-0wOXP0gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-20 00:57:50
(1 week ago)
(wordpress) Failed wordpress login from 66.9.161.101 (VE/Venezuela/customer.bgtacol1.isp.starlink.co ...
show more
(wordpress) Failed wordpress login from 66.9.161.101 (VE/Venezuela/customer.bgtacol1.isp.starlink.com)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-19 23:46:50
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 66.9.161.101 (customer.bgtacol1.isp.starlink.co ...
show more
(mod_security) mod_security (id:240335) triggered by 66.9.161.101 (customer.bgtacol1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 19:46:43.128660 2026] [security2:error] [pid 31488:tid 31488] [client 66.9.161.101:65244] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 66.9.161.101 (+1 hits since last alert)|blacksheepoffroad.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "blacksheepoffroad.com"] [uri "/xmlrpc.php"] [unique_id "al1h43CPuiZcC4iG111GzgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-19 21:50:27
(1 week ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-19 21:39:19
(1 week ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-07-16 13:42:01
(1 week ago)
block ruleset Badbot using very old user-agents 5CF3CDB778C7D82564405B86B9242E612F378C68
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-16 02:09:42
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 66.9.161.101 (customer.bgtacol1.isp.starlink.co ...
show more
(mod_security) mod_security (id:240335) triggered by 66.9.161.101 (customer.bgtacol1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 22:09:38.361555 2026] [security2:error] [pid 30341:tid 30341] [client 66.9.161.101:13260] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 66.9.161.101 (+1 hits since last alert)|eileensharaga.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eileensharaga.com"] [uri "/xmlrpc.php"] [unique_id "alg9YvLf4JPlIY8AN-q_IgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 01:06:07
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 66.9.161.101 (customer.bgtacol1.isp.starlink.co ...
show more
(mod_security) mod_security (id:240335) triggered by 66.9.161.101 (customer.bgtacol1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 21:06:01.476421 2026] [security2:error] [pid 1495460:tid 1495460] [client 66.9.161.101:6611] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 66.9.161.101 (+1 hits since last alert)|nordicbuilders.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nordicbuilders.net"] [uri "/xmlrpc.php"] [unique_id "algueUOWTOXi3eioL2MMygAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
NordhTech
2026-06-30 06:15:23
(4 weeks ago)
More than 3 malicious connection attempts, trying port(s) 51718/tcp, then blocked from services ...
Port Scan
Hacking
๐บ๐ธ
kosada.com
2026-06-29 14:17:09
(4 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-06-29 13:28:03
(4 weeks ago)
Port scan on ports 3124/UDP, 6370/UDP, 23299/UDP, 50750/UDP to unused IP
Port Scan
Anonymous
2026-06-28 23:16:36
(4 weeks ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-06-16 15:45:21
(1 month ago)
(mod_security) mod_security (id:210381) triggered by 66.9.161.101 (customer.bgtacol1.isp.starlink.co ...
show more
(mod_security) mod_security (id:210381) triggered by 66.9.161.101 (customer.bgtacol1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 11:45:17.297293 2026] [security2:error] [pid 8581:tid 8606] [client 66.9.161.101:45937] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/louisianabextralawyer/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/louisianabextralawyer/%url%"] [unique_id "ajFvjS-FG-GeI5M5k5LWMgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack