πΊπΈ
TPI-Abuse
2026-07-30 03:26:27
(4 hours ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 23:26:23.311332 2026] [security2:error] [pid 2873736:tid 2873736] [client 94.57.98.29:59436] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.29 (+1 hits since last alert)|talentstar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "talentstar.com"] [uri "/xmlrpc.php"] [unique_id "amrEXx8n8jGLT_c-BVHYsAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 23:21:32
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 19:21:26.886543 2026] [security2:error] [pid 7681:tid 7681] [client 94.57.98.29:64235] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.29 (+1 hits since last alert)|celebritybikinigossip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "celebritybikinigossip.com"] [uri "/xmlrpc.php"] [unique_id "amqK9oyelppWIhO5PNgnygAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 22:16:31
(9 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π³π±
Site.eu
2026-07-29 22:12:11
(10 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
π³π±
ConsulHosting
2026-07-29 21:34:12
(10 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 19:46:49
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 15:46:41.512882 2026] [security2:error] [pid 350084:tid 350084] [client 94.57.98.29:62285] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.29 (+1 hits since last alert)|rotentendales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rotentendales.com"] [uri "/xmlrpc.php"] [unique_id "ampYoW5qwjh25vA_5x9YBgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-07-29 19:29:08
(12 hours ago)
9.273 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
π¦πΊ
screwlooseit.com.au
2026-07-29 19:14:10
(12 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
AE/United Arab Emirates/-
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 18:45:26
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 14:45:22.184624 2026] [security2:error] [pid 1220894:tid 1220922] [client 94.57.98.29:58551] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.29 (+1 hits since last alert)|datuinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "datuinc.com"] [uri "/xmlrpc.php"] [unique_id "ampKQqFcGHj5PMFinDBKVwAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-07-29 18:01:24
(14 hours ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
π²πΎ
Rizzy
2026-07-29 17:41:13
(14 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-29 17:01:41
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 13:01:36.183365 2026] [security2:error] [pid 7021:tid 7021] [client 94.57.98.29:64077] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.29 (+1 hits since last alert)|freemanfoundationcle.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "freemanfoundationcle.org"] [uri "/xmlrpc.php"] [unique_id "amox8AC6PiLoECwhETByHAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 17:01:23
(15 hours ago)
(wordpress) Failed wordpress login from 94.57.98.29 (AE/United Arab Emirates/-)
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-29 14:59:31
(17 hours ago)
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 94.57.98.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 10:59:24.524248 2026] [security2:error] [pid 1485189:tid 1485189] [client 94.57.98.29:56095] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.57.98.29 (+1 hits since last alert)|jeffmasonmusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jeffmasonmusic.com"] [uri "/xmlrpc.php"] [unique_id "amoVTPtBB3HqJYV-eLYvFwAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 12:53:14
(19 hours ago)
[redacted] 94.57.98.29 - - [29/Jul/2026:14:52:32 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jet ...
show more
[redacted] 94.57.98.29 - - [29/Jul/2026:14:52:32 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack/13.0; WordPress/6.2; http://site60271213.com"
[redacted] 94.57.98.29 - - [29/Jul/2026:14:52:42 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack/12.0; WordPress/6.1; http://site51665380.com"
[redacted] 94.57.98.29 - - [29/Jul/2026:14:52:52 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack/12.1; WordPress/6.4; http://site94939553.com"
[redacted] 94.57.98.29 - - [29/Jul/2026:14:53:03 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 94.57.98.29 - - [29/Jul/2026:14:53:13 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack