🇨🇦
Anytech
2026-08-14 11:26:23
(4 weeks ago)
Blocked by ConnMonitor: forged-browser fingerprint
Bad Web Bot
Hacking
Web App Attack
DDoS Attack
🇪🇸
el-brujo
2026-08-13 16:23:00
(1 month ago)
HTTP DDoS Attack Layer 7
DDoS Attack
🇳🇱
Site.eu
2026-08-12 16:41:14
(1 month ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-08-08 03:23:59
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 160.20.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:23:50.918754 2026] [security2:error] [pid 2862456:tid 2862456] [client 160.20.38.214:56562] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.38.214 (+1 hits since last alert)|cyqci.eu|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cyqci.eu"] [uri "/xmlrpc.php"] [unique_id "anahRsfsx7UpzpJiWLb-rwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 00:58:40
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 160.20.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 20:58:36.900539 2026] [security2:error] [pid 1590709:tid 1590709] [client 160.20.38.214:55100] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.38.214 (+1 hits since last alert)|desertalfas.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "desertalfas.org"] [uri "/xmlrpc.php"] [unique_id "anUtvLxrapOvaw5p86lo2QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
GoodOldTOS
2026-08-04 22:50:57
(1 month ago)
Connection to SSHTarpit
Hacking
SSH
🇵🇱
bmino.pl
2026-08-03 14:35:26
(1 month ago)
Autoban IP(2): 160.20.38.214 - Hostname: PT SAMUDRA DIGITAL NETWORK - City: Indramayu - Region: West ...
show more
Autoban IP(2): 160.20.38.214 - Hostname: PT SAMUDRA DIGITAL NETWORK - City: Indramayu - Region: West Java - Country: Indonesia - Location: - Organization: PT SAMUDRA DIGITAL NETWORK - failed attempts.
show less
Web App Attack
🇺🇸
kosada.com
2026-08-01 03:34:24
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=120; exact paths: /xmlrpc.php
Web App Attack
🇩🇪
ghostwarriors
2026-07-27 03:20:23
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 03:14:06
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 160.20.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 23:14:00.800894 2026] [security2:error] [pid 4135255:tid 4135255] [client 160.20.38.214:51956] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.38.214 (+1 hits since last alert)|schlegelcreative.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "schlegelcreative.com"] [uri "/xmlrpc.php"] [unique_id "ambM-K4LbQYoTdZdEUf3ZQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-07-27 03:10:18
(1 month ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
Anonymous
2026-07-26 15:59:54
(1 month ago)
[redacted] 160.20.38.214 - - [26/Jul/2026:17:59:10 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 160.20.38.214 - - [26/Jul/2026:17:59:10 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.3; http://site44315114.com"
[redacted] 160.20.38.214 - - [26/Jul/2026:17:59:21 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 160.20.38.214 - - [26/Jul/2026:17:59:31 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.3; http://site67939039.com"
[redacted] 160.20.38.214 - - [26/Jul/2026:17:59:42 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 160.20.38.214 - - [26/Jul/2026:17:59:53 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.1; http://site55373271.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-07-26 14:07:04
(1 month ago)
(wordpress) Failed wordpress login from 160.20.38.214 (ID/Indonesia/-)
Brute-Force
🇺🇸
TPI-Abuse
2026-07-25 17:22:21
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 160.20.38.214 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.38.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 13:22:14.761226 2026] [security2:error] [pid 2636487:tid 2636487] [client 160.20.38.214:65498] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.38.214 (+1 hits since last alert)|jdsqrd.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jdsqrd.com"] [uri "/xmlrpc.php"] [unique_id "amTwxuCTdBIUTcYq8FhiFQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack