Anonymous
2026-09-19 03:57:22
(17 hours ago)
denied traffic to a honeypot network. destination port 27015.
Port Scan
Hacking
Anonymous
2026-09-13 20:37:45
(6 days ago)
59742/udp (1 or more attempts)
Port Scan
Anonymous
2026-09-12 03:11:52
(1 week ago)
denied traffic to a non-approved destination port. destination port 59111.
Port Scan
Anonymous
2026-07-13 06:45:06
(2 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 06:17:14
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 02:17:07.582290 2026] [security2:error] [pid 22377:tid 22377] [client 84.15.188.149:23276] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 84.15.188.149 (+1 hits since last alert)|braintechsoftwaresolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "braintechsoftwaresolutions.com"] [uri "/xmlrpc.php"] [unique_id "alSC42hKVvUHbXuuwG754gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 05:45:57
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 01:45:49.008066 2026] [security2:error] [pid 28124:tid 28124] [client 84.15.188.149:52685] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 84.15.188.149 (+1 hits since last alert)|helloauto.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "helloauto.net"] [uri "/xmlrpc.php"] [unique_id "alR7jYX9k2k_n7lQ1D0M7gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-12 11:52:18
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 07:52:14.956468 2026] [security2:error] [pid 14056:tid 14056] [client 84.15.188.149:53113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 84.15.188.149 (+1 hits since last alert)|frelsburg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "frelsburg.com"] [uri "/xmlrpc.php"] [unique_id "alN_7ojpCTpVzjZCcpDuDgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-12 11:50:16
(2 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
LT/Republic of Lithuania/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-12 10:49:56
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 06:49:52.822474 2026] [security2:error] [pid 16029:tid 16029] [client 84.15.188.149:42030] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 84.15.188.149 (+1 hits since last alert)|tomartsmedia.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tomartsmedia.org"] [uri "/xmlrpc.php"] [unique_id "alNxUPTWHNLQ8MS_AoalZwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-12 10:49:43
(2 months ago)
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-07-12 08:36:24
(2 months ago)
(wordpress) Failed wordpress login from 84.15.188.149 (LT/Lithuania/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-12 08:06:39
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 04:06:34.429143 2026] [security2:error] [pid 6107:tid 6107] [client 84.15.188.149:7444] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 84.15.188.149 (+1 hits since last alert)|fattoria-rendena.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fattoria-rendena.it"] [uri "/xmlrpc.php"] [unique_id "alNLCh2xbOGp9WWixB3Q3AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-11 16:05:10
(2 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
jsjdmediallc
2026-07-11 08:20:07
(2 months ago)
Auto-blocked: score 626 (threshold 10). Tier: HIGH. Hits: 124. Flags: xmlrpc, xmlrpc-burst, single-p ...
show more
Auto-blocked: score 626 (threshold 10). Tier: HIGH. Hits: 124. Flags: xmlrpc, xmlrpc-burst, single-path-flood. Paths: /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 07:27:41
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 84.15.188.149 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 03:27:36.706360 2026] [security2:error] [pid 17069:tid 17094] [client 84.15.188.149:24441] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 84.15.188.149 (+1 hits since last alert)|wedgwoodclub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wedgwoodclub.com"] [uri "/xmlrpc.php"] [unique_id "alHwaC7DGuPEgXXlS6eYdQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack