๐ณ๐ฑ
Site.eu
2026-08-09 08:36:40
(2 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-09 08:07:35
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 41.129.79.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 41.129.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 04:07:28.551486 2026] [security2:error] [pid 2261352:tid 2261352] [client 41.129.79.13:57549] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.129.79.13 (+1 hits since last alert)|rimaine.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rimaine.org"] [uri "/xmlrpc.php"] [unique_id "ang1QPDdhNMCmBxRmroJQAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
ycoskun41
2026-08-08 19:51:34
(2 weeks ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐ง๐ช
cmbplf
2026-08-08 17:44:55
(2 weeks ago)
6.263 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-08 09:59:32
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 41.129.79.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 41.129.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 05:59:25.735799 2026] [security2:error] [pid 21179:tid 21179] [client 41.129.79.13:56541] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.129.79.13 (+1 hits since last alert)|grabagame.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "grabagame.com"] [uri "/xmlrpc.php"] [unique_id "anb9_fITvxkeJ2FOihCjTQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-08-08 09:26:10
(2 weeks ago)
(wordpress) Failed wordpress login from 41.129.79.13 (EG/Egypt/-)
Brute-Force
๐ฉ๐ช
hchristo
2026-08-08 07:54:11
(2 weeks ago)
[Sat Aug 08 09:53:28.448394 2026] [access_compat:error] [pid 5908:tid 5991] [client 41.129.79.13:497 ...
show more
[Sat Aug 08 09:53:28.448394 2026] [access_compat:error] [pid 5908:tid 5991] [client 41.129.79.13:49726] AH01797: client denied by server configuration: /var/www/kd1006/apps/claprocker/xmlrpc.php
[Sat Aug 08 09:53:38.688622 2026] [access_compat:error] [pid 5908:tid 6007] [client 41.129.79.13:25347] AH01797: client denied by server configuration: /var/www/kd1006/apps/claprocker/xmlrpc.php
[Sat Aug 08 09:53:49.274745 2026] [access_compat:error] [pid 5908:tid 5996] [client 41.129.79.13:26059] AH01797: client denied by server configuration: /var/www/kd1006/apps/claprocker/xmlrpc.php
[Sat Aug 08 09:53:59.800386 2026] [access_compat:error] [pid 5908:tid 5984] [client 41.129.79.13:26579] AH01797: client denied by server configuration: /var/www/kd1006/apps/claprocker/xmlrpc.php
[Sat Aug 08 09:54:10.367070 2026] [access_compat:error] [pid 5908:tid 5970] [client 41.129.79.13:51946] AH01797: client denied by server configuration: /var/www/kd1006/apps/claprocker/xmlrpc.php
...
show less
Brute-Force
๐ซ๐ท
dynamix
2026-08-08 07:12:48
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 18:23:57
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 41.129.79.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 41.129.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 14:23:54.415706 2026] [security2:error] [pid 2241129:tid 2241129] [client 41.129.79.13:17575] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.129.79.13 (+1 hits since last alert)|alsetsystems.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "alsetsystems.com"] [uri "/xmlrpc.php"] [unique_id "anYiusksFI_HkLwC8PCkFwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Kenshin869
2026-08-07 17:39:21
(2 weeks ago)
Wordpress unauthorized access attempt
Brute-Force
๐ณ๐ฑ
debestelapp
2026-08-07 17:35:07
(2 weeks ago)
Web App Attack
๐จ๐ญ
4server
2026-08-06 20:24:24
(2 weeks ago)
[ThuAug0622:24:18.5288682026][security2:error][pid3128819:tid3129120][client41.129.79.13:0]ModSecuri ...
show more
[ThuAug0622:24:18.5288682026][security2:error][pid3128819:tid3129120][client41.129.79.13:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"368\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"comarcosa.com\"][uri\"/xmlrpc.php\"][unique_id\"anTtcs9xX0kl5U5NWAhkiAAAAQE\"]
show less
Hacking
Web App Attack
Anonymous
2026-08-06 19:12:16
(2 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 18:13:06
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 41.129.79.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 41.129.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 14:13:02.314893 2026] [security2:error] [pid 2678318:tid 2678318] [client 41.129.79.13:59518] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.129.79.13 (+1 hits since last alert)|clockandnightlight.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "clockandnightlight.com"] [uri "/xmlrpc.php"] [unique_id "anTOrsTDMYUwjh99iYOteQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 15:02:50
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 41.129.79.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 41.129.79.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 11:02:46.658703 2026] [security2:error] [pid 2156234:tid 2156234] [client 41.129.79.13:59708] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.129.79.13 (+1 hits since last alert)|method1.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "method1.net"] [uri "/xmlrpc.php"] [unique_id "anSiFgKUWGh3p7eKY0HdfgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack