๐ฎ๐น
CoreTech srl
2026-08-26 22:28:57
(2 hours ago)
cloudlinux2 fail2ban: 2026-08-27 00:24:14,953 fail2ban.filter [1775]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-27 00:24:14,953 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 109.71.72.250 - 2026-08-27 00:24:14cloudlinux2 fail2ban: 2026-08-27 00:26:25,193 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 27.74.251.194 - 2026-08-27 00:26:24cloudlinux2 fail2ban: 2026-08-27 00:27:59,597 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Unban 34.63.217.74cloudlinux2 fail2ban: 2026-08-27 00:28:00,085 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 94.129.197.116 - 2026-08-27 00:27:59cloudlinux2 fail2ban: 2026-08-27 00:28:12,435 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.78.151.67 - 2026-08-27 00:28:12cloudlinux2 fail2ban: 2026-08-27 00:28:12,420 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.78.151.67 - 2026-08-27 00:28:12cloudlinux2 fail2ban: 2026-08-27 00:28:12,443 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.78.151.67 - 2026-08-27 00:28:12cloudlinux2 fail2ban: 20
show less
Web App Attack
๐บ๐ธ
WeekendWeb
2026-08-26 10:19:27
(14 hours ago)
Wordpress Vunerability attack
Web App Attack
๐ฉ๐ช
abdubhai
2026-08-26 04:29:14
(20 hours ago)
94.129.197.116 - - [26/Aug/2026:
...
Brute-Force
๐ธ๐ช
ljo
2026-08-25 18:16:16
(1 day ago)
94.129.197.116 - - [25/Aug/2026:20:14:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "Jetpack by ...
show more
94.129.197.116 - - [25/Aug/2026:20:14:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
94.129.197.116 - - [25/Aug/2026:20:14:39 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "WordPress.com; https://wordpress.com"
94.129.197.116 - - [25/Aug/2026:20:14:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "Jetpack by WordPress.com"
94.129.197.116 - - [25/Aug/2026:20:15:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "Jetpack/12.1; WordPress/6.3; http://site41825345.com"
94.129.197.116 - - [25/Aug/2026:20:15:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "WordPress.com; https://wordpress.com"
94.129.197.116 - - [25/Aug/2026:20:15:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
94.129.197.116 - - [25/Aug/2026:20:15:33 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "WordPress.com; https://wordpress.com"
94.129.197.116 - - [25/Aug/2026:20:15:43 +0200] "POST /xmlrpc.ph
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 14:35:19
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 10:35:11.784700 2026] [security2:error] [pid 15784:tid 15784] [client 94.129.197.116:7541] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.129.197.116 (+1 hits since last alert)|amywoodruff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "amywoodruff.com"] [uri "/xmlrpc.php"] [unique_id "ao2oH03BdzWeVd9J-vqtHQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 11:28:34
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 07:28:27.712206 2026] [security2:error] [pid 10609:tid 10609] [client 94.129.197.116:18538] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.129.197.116 (+1 hits since last alert)|fishleadership.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fishleadership.org"] [uri "/xmlrpc.php"] [unique_id "ao18Wz2H4fe66Fivwk70uQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 10:40:47
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:40:41.615123 2026] [security2:error] [pid 27782:tid 27782] [client 94.129.197.116:5079] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.129.197.116 (+1 hits since last alert)|fractalsky.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fractalsky.com"] [uri "/xmlrpc.php"] [unique_id "ao1xKcYNFIlOrnVG87RSjQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-25 09:44:02
(1 day ago)
(wordpress) Failed wordpress login from 94.129.197.116 (KW/Kuwait/Al Asimah/Kuwait City/-/[redacted] ...
show more
(wordpress) Failed wordpress login from 94.129.197.116 (KW/Kuwait/Al Asimah/Kuwait City/-/[redacted])
show less
Brute-Force
๐ณ๐ฑ
ConsulHosting
2026-08-25 09:20:06
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 07:55:56
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 03:55:47.522642 2026] [security2:error] [pid 32025:tid 32025] [client 94.129.197.116:43753] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.129.197.116 (+1 hits since last alert)|roguetechscene.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "roguetechscene.com"] [uri "/xmlrpc.php"] [unique_id "ao1Kg_BmMuKJEVN1kI-wkwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 03:25:23
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 23:25:16.683268 2026] [security2:error] [pid 3724:tid 3724] [client 94.129.197.116:35016] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.129.197.116 (+1 hits since last alert)|thepercussionworks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thepercussionworks.com"] [uri "/xmlrpc.php"] [unique_id "ao0LHEd2cfmYXm5X1shP9gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-25 00:20:04
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-08-25 00:19:03
(2 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 21:16:24
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 17:16:16.294619 2026] [security2:error] [pid 6003:tid 6003] [client 94.129.197.116:16291] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.129.197.116 (+1 hits since last alert)|themadwriter.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "themadwriter.us"] [uri "/xmlrpc.php"] [unique_id "aoy0oHs3k5da-vB-N7ALmQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 20:48:49
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 94.129.197.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 16:48:41.400089 2026] [security2:error] [pid 1270:tid 1270] [client 94.129.197.116:14626] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.129.197.116 (+1 hits since last alert)|mkdesignndetailing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mkdesignndetailing.com"] [uri "/xmlrpc.php"] [unique_id "aoyuKWkCrchDoZhJXNKRTwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack