๐ง๐ช
madeit
2026-08-24 10:17:44
(9 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 06:43:44
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 02:43:37.670675 2026] [security2:error] [pid 3030:tid 3030] [client 94.57.98.110:56887] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.110 (+1 hits since last alert)|capriexpress.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "capriexpress.com"] [uri "/xmlrpc.php"] [unique_id "aovoGQ06s8L5kIWwjTEPpwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 04:37:46
(14 hours ago)
[redacted] 94.57.98.110 - - [24/Aug/2026:06:37:02 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 94.57.98.110 - - [24/Aug/2026:06:37:02 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 94.57.98.110 - - [24/Aug/2026:06:37:13 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 94.57.98.110 - - [24/Aug/2026:06:37:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 94.57.98.110 - - [24/Aug/2026:06:37:34 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.3; http://site57467215.com"
[redacted] 94.57.98.110 - - [24/Aug/2026:06:37:45 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.4; http://site22814262.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 12:00:07
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:59:59.496485 2026] [security2:error] [pid 5708:tid 5708] [client 94.57.98.110:54228] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.110 (+1 hits since last alert)|engineeringarts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "engineeringarts.com"] [uri "/xmlrpc.php"] [unique_id "aorgvxcdHoBr8_NjWYSpLQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 09:30:07
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 05:30:00.707665 2026] [security2:error] [pid 488:tid 488] [client 94.57.98.110:61284] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.110 (+1 hits since last alert)|t9teamsportinggoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "t9teamsportinggoods.com"] [uri "/xmlrpc.php"] [unique_id "aoq9mAKdKITUYvn2PIFshgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-23 06:00:09
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-08-21 07:06:06
(3 days ago)
[redacted] 94.57.98.110 - - [21/Aug/2026:09:05:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Je ...
show more
[redacted] 94.57.98.110 - - [21/Aug/2026:09:05:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack/12.0; WordPress/6.1; http://site15603751.com"
[redacted] 94.57.98.110 - - [21/Aug/2026:09:05:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 94.57.98.110 - - [21/Aug/2026:09:05:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 94.57.98.110 - - [21/Aug/2026:09:05:33 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack/12.0; WordPress/6.1; http://site59642194.com"
[redacted] 94.57.98.110 - - [21/Aug/2026:09:05:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 94.57.98.110 - - [21/Aug/2026:09:05:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 94.57.98.110 - - [21/Aug/2026:09:05:51 +0200] "POST /xmlrpc.php H
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 10:52:17
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 06:52:12.577794 2026] [security2:error] [pid 26229:tid 26275] [client 94.57.98.110:64131] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.110 (+1 hits since last alert)|jpdesign.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jpdesign.us"] [uri "/xmlrpc.php"] [unique_id "aoWK3FLccR-LvhSkaP4HAgAAAcI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-19 09:53:57
(5 days ago)
cloudlinux2 fail2ban: 2026-08-19 11:51:42,582 fail2ban.filter [1468]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-19 11:51:42,582 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 94.57.98.110 - 2026-08-19 11:51:42cloudlinux2 fail2ban: 2026-08-19 11:52:14,132 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 94.57.98.110 - 2026-08-19 11:52:14cloudlinux2 fail2ban: 2026-08-19 11:52:45,907 fail2ban.filter [1468]: INFO [recidive] Found 94.57.98.110 - 2026-08-19 11:52:45cloudlinux2 fail2ban: 2026-08-19 11:52:45,794 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 94.57.98.110 - 2026-08-19 11:52:45cloudlinux2 fail2ban: 2026-08-19 11:52:45,902 fail2ban.actions [1468]: NOTICE [plesk-modsecurity] Ban 94.57.98.110cloudlinux2 fail2ban: 2026-08-19 11:53:33,364 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 35.190.160.56 - 2026-08-19 11:53:32cloudlinux2 fail2ban: 2026-08-19 11:53:33,379 fail2ban.filter [1468]: INFO [plesk-modsecurity] Found 35.190.160.56 - 2026-08-19 11:53:33cloudlinux2 fail2ban: 2026-08-19
show less
Brute-Force
๐ฉ๐ช
usc-IPDB
2026-08-19 09:18:17
(5 days ago)
94.57.98.110 - - [19/Aug/2026:11:17:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack by Wo ...
show more
94.57.98.110 - - [19/Aug/2026:11:17:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
94.57.98.110 - - [19/Aug/2026:11:18:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12.0; WordPress/6.1; http://site19812466.com"
94.57.98.110 - - [19/Aug/2026:11:18:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12.1; WordPress/6.1; http://site91545682.com"
...
show less
Port Scan
Anonymous
2026-08-19 04:56:03
(5 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 11:43:36
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 07:43:29.901446 2026] [security2:error] [pid 22272:tid 22272] [client 94.57.98.110:53270] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.110 (+1 hits since last alert)|cosplayculture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cosplayculture.com"] [uri "/xmlrpc.php"] [unique_id "aoRFYViv-gfrBU2NOi8r8AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-18 11:42:54
(6 days ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=www.crisis-management2017.eu; logs=/var/log/httpd/domains/c ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=www.crisis-management2017.eu; logs=/var/log/httpd/domains/crisis-management2017.eu.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 05:22:30
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.110 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 01:22:24.228318 2026] [security2:error] [pid 19138:tid 19138] [client 94.57.98.110:56797] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.110 (+1 hits since last alert)|rkhindustries.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rkhindustries.com"] [uri "/xmlrpc.php"] [unique_id "aoPsEBgFoCi84f4MWJeoZAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-17 09:37:04
(1 week ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH