πΈπ¬
naveeddaros
2026-08-23 19:31:52
(1 day ago)
HTTP Flood DDoS attack detected
Brute-Force
Bad Web Bot
π©πͺ
ghostwarriors
2026-07-10 10:21:34
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-08 06:29:42
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 94.203.128.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 94.203.128.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 08 02:29:36.886198 2026] [security2:error] [pid 18716:tid 18716] [client 94.203.128.42:54634] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.203.128.42 (+1 hits since last alert)|aandbnaturalfoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aandbnaturalfoods.com"] [uri "/xmlrpc.php"] [unique_id "ak3uUHfjp0wf_RSunHbPwQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-07 13:40:24
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 94.203.128.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 94.203.128.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 07 09:40:20.109648 2026] [security2:error] [pid 22869:tid 22881] [client 94.203.128.42:64158] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.203.128.42 (+1 hits since last alert)|reghay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "reghay.com"] [uri "/xmlrpc.php"] [unique_id "ak0BxCrwHO5JfT74Rnpx-AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-07-04 11:25:39
(1 month ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
AE/United Arab Emirates/-
Web App Attack
π«π·
SpaceHost-Server
2026-06-04 22:32:41
(2 months ago)
Brute-Force
Web App Attack
πΊπΈ
integrantservices.com
2026-06-03 10:41:23
(2 months ago)
(wordpress) Failed wordpress login from 94.203.128.42 (AE/United Arab Emirates/-)
Brute-Force
π«π·
SpaceHost-Server
2026-06-02 22:36:25
(2 months ago)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 13:37:27
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 94.203.128.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 94.203.128.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 09:37:20.083198 2026] [security2:error] [pid 3841:tid 3841] [client 94.203.128.42:52099] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.203.128.42 (+1 hits since last alert)|ixd.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ixd.net"] [uri "/xmlrpc.php"] [unique_id "ah7ckFDaFe5TFBp1n2bsWQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 12:06:50
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 94.203.128.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 94.203.128.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 08:06:46.146975 2026] [security2:error] [pid 13502:tid 13524] [client 94.203.128.42:54443] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.203.128.42 (+1 hits since last alert)|piazza9.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "piazza9.com"] [uri "/xmlrpc.php"] [unique_id "ah7HVvvRESGIVOQYgcSwnAAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 10:52:16
(2 months ago)
Attac
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-02 10:47:45
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 94.203.128.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 94.203.128.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 06:47:39.337566 2026] [security2:error] [pid 23643:tid 23643] [client 94.203.128.42:62946] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.203.128.42 (+1 hits since last alert)|joeordie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "joeordie.com"] [uri "/xmlrpc.php"] [unique_id "ah60y9rJGuboODEGZ_XZ5QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-06-02 09:19:27
(2 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
π«π·
SpaceHost-Server
2026-06-02 09:03:48
(2 months ago)
94.203.128.42 - - [02/Jun/2026:11:03:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Jetpack by ...
show more
94.203.128.42 - - [02/Jun/2026:11:03:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
94.203.128.42 - - [02/Jun/2026:11:03:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Jetpack/13.0; WordPress/6.2; http://site87247193.com"
94.203.128.42 - - [02/Jun/2026:11:03:47 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
show less
Hacking
Web App Attack
π«π·
SpaceHost-Server
2026-06-02 08:48:28
(2 months ago)
94.203.128.42 - - [02/Jun/2026:10:48:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Jetpack/12. ...
show more
94.203.128.42 - - [02/Jun/2026:10:48:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Jetpack/12.1; WordPress/6.4; http://site30138304.com"
94.203.128.42 - - [02/Jun/2026:10:48:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Jetpack by WordPress.com"
94.203.128.42 - - [02/Jun/2026:10:48:27 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
show less
Hacking
Web App Attack