๐บ๐ธ
kosada.com
2026-08-31 12:58:33
(1 week ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-18 09:35:55
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 43.242.176.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.242.176.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 05:35:47.560969 2026] [security2:error] [pid 30549:tid 30549] [client 43.242.176.14:25515] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.242.176.14 (+1 hits since last alert)|mchen-arch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mchen-arch.com"] [uri "/xmlrpc.php"] [unique_id "aoQncxsYGGJsFH3SS0hs8wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-08-18 09:26:56
(3 weeks ago)
{"ClientAddr":"43.242.176.14:25508","ClientHost":"43.242.176.14","ClientPort":"25508","ClientUsernam ...
show more
{"ClientAddr":"43.242.176.14:25508","ClientHost":"43.242.176.14","ClientPort":"25508","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":450124097,"OriginContentSize":418,"OriginDuration":446380485,"OriginStatus":403,"Overhead":3743612,"RequestAddr":"www.cleveradmin.de","RequestContentSize":714,"RequestCount":4183152,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-08-18T11:26:37.957208203+02:00","StartUTC":"2026-08-18T09:26:37.957208203Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-08-18T11:26:38+02:00"}
{"ClientAddr":"43.242.176.14:25508","ClientHost":"43.242.176.14","
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 08:32:34
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 43.242.176.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.242.176.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 04:32:30.465275 2026] [security2:error] [pid 2425:tid 2425] [client 43.242.176.14:25430] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.242.176.14 (+1 hits since last alert)|lawrencehale.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lawrencehale.net"] [uri "/xmlrpc.php"] [unique_id "aoQYntxGlbC3FF1MXs7rcAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-18 07:49:40
(3 weeks ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 07:01:34
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 43.242.176.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.242.176.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 03:01:25.107365 2026] [security2:error] [pid 17278:tid 17278] [client 43.242.176.14:25993] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.242.176.14 (+1 hits since last alert)|savingspools.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "savingspools.com"] [uri "/xmlrpc.php"] [unique_id "aoQDRdz3KIHMD4C9DoA1ngAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-17 15:21:15
(3 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 14:39:55
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 43.242.176.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.242.176.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 10:39:48.422992 2026] [security2:error] [pid 24255:tid 24255] [client 43.242.176.14:25829] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.242.176.14 (+1 hits since last alert)|salernospizza.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "salernospizza.com"] [uri "/xmlrpc.php"] [unique_id "aoHLtB_2mkB1WOw4aNTuRwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-08-16 14:30:58
(3 weeks ago)
43.242.176.14 - - [16/Aug/2026:16:30:36 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4842 "-" "Jetpack by ...
show more
43.242.176.14 - - [16/Aug/2026:16:30:36 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4842 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)" 43.242.176.14 - - [16/Aug/2026:16:30:46 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4842 "-" "WordPress.com; https://wordpress.com" 43.242.176.14 - - [16/Aug/2026:16:30:57 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4840 "-" "WordPress.com; https://wordpress.com"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-16 10:50:19
(3 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 10:31:27
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 43.242.176.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.242.176.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 06:31:18.678582 2026] [security2:error] [pid 15165:tid 15165] [client 43.242.176.14:25103] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.242.176.14 (+1 hits since last alert)|pearlhomesfw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pearlhomesfw.com"] [uri "/xmlrpc.php"] [unique_id "aoGRdu3KfWjOzJskD4tuWQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-16 10:23:52
(3 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-01 08:59:05
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2026-06-29 16:21:53
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ณ๐ฑ
exxos
2025-09-02 17:03:01
(1 year ago)
Attacks with Bad user agents
Hacking