πΊπΈ
TPI-Abuse
2026-08-25 09:51:07
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:50:59.235731 2026] [security2:error] [pid 31418:tid 31449] [client 36.50.148.93:64029] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.93 (+1 hits since last alert)|leaderoftheopposition.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "leaderoftheopposition.com"] [uri "/xmlrpc.php"] [unique_id "ao1lg6cRiTL8I3UepOof8gAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2026-08-25 07:20:49
(1 week ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 07:08:11
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 03:08:05.080353 2026] [security2:error] [pid 8230:tid 8230] [client 36.50.148.93:58234] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.93 (+1 hits since last alert)|zost.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "zost.net"] [uri "/xmlrpc.php"] [unique_id "aof5Va0kGWeFxXyXDbVkkgAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-08-06 14:58:11
(3 weeks ago)
CrowdSec: REPEAT OFFENDER (previously banned, came back) - distributed L7 HTTP flood on WordPress 'T ...
show more
CrowdSec: REPEAT OFFENDER (previously banned, came back) - distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/time_limit~1763161200/cat_ids~134,649,361,144/tag_ids~329,609,593,224,558,574,581/request_format~json/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/104.0.0.0 Safari/537.36
show less
DDoS Attack
Web App Attack
π©πͺ
LRob
2026-08-03 13:51:55
(4 weeks ago)
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_forma ...
show more
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/cat_ids~630,140,143,207/tag_ids~290,565,447,478,701,619/request_format~json/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
DDoS Attack
Web App Attack
πΊπΈ
kosada.com
2026-08-02 23:35:41
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-07-23 09:38:13
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:38:05.412067 2026] [security2:error] [pid 2701889:tid 2701889] [client 36.50.148.93:61453] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.93 (+1 hits since last alert)|oakvillenaturopathicclinic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "oakvillenaturopathicclinic.com"] [uri "/xmlrpc.php"] [unique_id "amHg_S2p5le9gk-w4QaBPQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-07-17 09:08:12
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-17 08:39:49
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 04:39:44.191835 2026] [security2:error] [pid 545861:tid 545861] [client 36.50.148.93:56988] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.93 (+1 hits since last alert)|36sovereignchambers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "36sovereignchambers.com"] [uri "/xmlrpc.php"] [unique_id "alnqUFdD_-5BT9H68ovcGgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-07-13 09:06:12
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-09 09:44:33
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.93 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.93 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 09 05:44:29.591110 2026] [security2:error] [pid 17185:tid 17257] [client 36.50.148.93:56185] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.93 (+1 hits since last alert)|illianapartyrentals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "illianapartyrentals.com"] [uri "/xmlrpc.php"] [unique_id "ak9tfZ4FaY_COxl3XlSSegAAAYY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-07-06 06:34:06
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
jsjdmediallc
2026-07-03 09:40:05
(1 month ago)
Auto-blocked: score 331 (threshold 10). Tier: HIGH. Hits: 65. Flags: xmlrpc, xmlrpc-burst, single-pa ...
show more
Auto-blocked: score 331 (threshold 10). Tier: HIGH. Hits: 65. Flags: xmlrpc, xmlrpc-burst, single-path-flood. Paths: /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php
show less
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-07-03 05:09:56
(1 month ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
πΊπΈ
kosada.com
2026-06-29 09:53:51
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot