๐บ๐ธ
TPI-Abuse
2026-07-22 11:11:54
(23 hours ago)
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 07:11:46.520563 2026] [security2:error] [pid 921218:tid 921218] [client 94.51.210.105:1587] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.51.210.105 (+1 hits since last alert)|technesa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "technesa.com"] [uri "/xmlrpc.php"] [unique_id "amClcoxro3nURsdbD0WykgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-22 11:06:25
(23 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 02:47:20
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 22:47:13.164638 2026] [security2:error] [pid 199284:tid 199284] [client 94.51.210.105:5609] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.51.210.105 (+1 hits since last alert)|theopinionatedowl.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theopinionatedowl.com"] [uri "/xmlrpc.php"] [unique_id "amAvMfqwBEEDVv6oVYhUqgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-22 02:46:33
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
tmiland
2026-07-22 00:57:33
(1 day ago)
(wordpress_xmlrpc) WordPress XMLPRC Attack 94.51.210.105 (RU/Russia/-): 3 in the last 3600 secs; IP: ...
show more
(wordpress_xmlrpc) WordPress XMLPRC Attack 94.51.210.105 (RU/Russia/-): 3 in the last 3600 secs; IP: 94.51.210.105; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 94.51.210.105 - - [22/Jul/2026:02:57:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "WordPress.com; https://wordpress.com" 94.51.210.105 - - [22/Jul/2026:02:57:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)" 94.51.210.105 - - [22/Jul/2026:02:57:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-21 23:28:45
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 19:28:36.893423 2026] [security2:error] [pid 14990:tid 14990] [client 94.51.210.105:2435] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.51.210.105 (+1 hits since last alert)|btccasting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "btccasting.com"] [uri "/xmlrpc.php"] [unique_id "amAApMQWjUi1MLxB2zzxlAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 17:50:54
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 13:50:48.402514 2026] [security2:error] [pid 9072:tid 9072] [client 94.51.210.105:8083] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.51.210.105 (+1 hits since last alert)|sutherlandyogastudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sutherlandyogastudio.com"] [uri "/xmlrpc.php"] [unique_id "al-xeJ7aSgjCwzB7P7kPJwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-07-21 17:04:34
(1 day ago)
Failed attempt detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 12:03:02
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:02:55.182333 2026] [security2:error] [pid 24614:tid 24617] [client 94.51.210.105:8067] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.51.210.105 (+1 hits since last alert)|wedgwoodclub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wedgwoodclub.com"] [uri "/xmlrpc.php"] [unique_id "al9f7yPXQ6URBP5WuE91_QAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-07-21 11:34:13
(1 day ago)
(xmlrpc) Failed xmlrpc access from 94.51.210.105 (RU/Russia/-): 5 in the last 3600 secs (0-122)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-21 10:30:27
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 94.51.210.105 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 06:30:22.807606 2026] [security2:error] [pid 19221:tid 19221] [client 94.51.210.105:7101] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.51.210.105 (+1 hits since last alert)|targetbinario.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "targetbinario.com"] [uri "/xmlrpc.php"] [unique_id "al9KPpS4Zs2gjEjuvsgtUAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack