πΊπΈ
TPI-Abuse
2026-07-23 23:04:11
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 19:04:06.955693 2026] [security2:error] [pid 2848243:tid 2848243] [client 94.57.98.210:65430] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.210 (+1 hits since last alert)|bonegym.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bonegym.com"] [uri "/xmlrpc.php"] [unique_id "amKd5hTI8UAzRb7pBR-h8QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-23 20:59:59
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 16:59:52.739245 2026] [security2:error] [pid 2771542:tid 2771542] [client 94.57.98.210:63230] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.210 (+1 hits since last alert)|tourissue.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tourissue.com"] [uri "/xmlrpc.php"] [unique_id "amKAyPcvXoJ9dp8xqBtoYgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 20:12:40
(4 hours ago)
(wordpress) Failed wordpress login from 94.57.98.210 (AE/United Arab Emirates/-)
Brute-Force
πΊπΈ
IndigoRidge
2026-07-23 20:05:55
(4 hours ago)
94.57.98.210 - - [23/Jul/2026:16:04:40 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.co ...
show more
94.57.98.210 - - [23/Jul/2026:16:04:40 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.com; https://wordpress.com"
94.57.98.210 - - [23/Jul/2026:16:05:11 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.com; https://wordpress.com"
94.57.98.210 - - [23/Jul/2026:16:05:32 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.com; https://wordpress.com"
94.57.98.210 - - [23/Jul/2026:16:05:43 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.com; https://wordpress.com"
94.57.98.210 - - [23/Jul/2026:16:05:53 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-23 19:00:30
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 15:00:24.278709 2026] [security2:error] [pid 740180:tid 740180] [client 94.57.98.210:53773] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.210 (+1 hits since last alert)|citizensforsanity.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "citizensforsanity.com"] [uri "/xmlrpc.php"] [unique_id "amJkyCwaS3togpM4uudBAwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
alferez
2026-07-23 17:31:22
(7 hours ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-07-23 17:05:22
(7 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
AE/United Arab Emirates/-
Web App Attack
π³π±
Site.eu
2026-07-23 16:13:09
(8 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
π«π·
Kenshin869
2026-07-23 16:12:10
(8 hours ago)
Wordpress unauthorized access attempt
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-23 15:57:41
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.210 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.210 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 11:57:35.485176 2026] [security2:error] [pid 4167681:tid 4167681] [client 94.57.98.210:60101] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.210 (+1 hits since last alert)|solarfarms.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solarfarms.info"] [uri "/xmlrpc.php"] [unique_id "amI571yeN0p0euaACkrkkAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-07-23 13:52:45
(10 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
cwytech
2026-07-23 13:44:10
(11 hours ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-07-23 13:33:16
(11 hours ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
Anonymous
2026-07-23 13:07:59
(11 hours ago)
[redacted] 94.57.98.210 - - [23/Jul/2026:15:07:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Je ...
show more
[redacted] 94.57.98.210 - - [23/Jul/2026:15:07:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
[redacted] 94.57.98.210 - - [23/Jul/2026:15:07:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
[redacted] 94.57.98.210 - - [23/Jul/2026:15:07:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 94.57.98.210 - - [23/Jul/2026:15:07:48 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
[redacted] 94.57.98.210 - - [23/Jul/2026:15:07:58 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
π©πͺ
ghostwarriors
2026-07-23 11:20:36
(13 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack