Anonymous
2026-08-21 05:28:20
(1 day ago)
denied traffic to a honeypot network. destination port 23.
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-11 11:54:24
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 61.9.8.38 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:240335) triggered by 61.9.8.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 07:54:10.066512 2026] [security2:error] [pid 4032702:tid 4032702] [client 61.9.8.38:4699] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.9.8.38 (+1 hits since last alert)|activethinkers.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "activethinkers.net"] [uri "/xmlrpc.php"] [unique_id "ansNYn2F2tTmrH2b67x2SQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-11 06:37:39
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-10 17:29:54
(1 week ago)
WordPress login brute-force | req: /xmlrpc.php | UA: Jetpack/13.0; WordPress/6.1; http://site8472918 ...
show more
WordPress login brute-force | req: /xmlrpc.php | UA: Jetpack/13.0; WordPress/6.1; http://site84729183.com
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-10 14:23:33
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 61.9.8.38 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:240335) triggered by 61.9.8.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 10:23:23.436855 2026] [security2:error] [pid 3621011:tid 3621011] [client 61.9.8.38:65535] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.9.8.38 (+1 hits since last alert)|hodlmoser.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hodlmoser.com"] [uri "/xmlrpc.php"] [unique_id "anne2_87yDKei7Z-iygGQwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-08 18:20:06
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-08 17:52:40
(2 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 07:46:49
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 61.9.8.38 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:240335) triggered by 61.9.8.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 03:46:35.528402 2026] [security2:error] [pid 13621:tid 13796] [client 61.9.8.38:25276] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.9.8.38 (+1 hits since last alert)|maryschalkdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "maryschalkdesign.com"] [uri "/xmlrpc.php"] [unique_id "anbe283vNnm-aJbtcgQQLQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 03:29:04
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 61.9.8.38 (-): 1 in the last 300 secs; Ports: * ...
show more
(mod_security) mod_security (id:240335) triggered by 61.9.8.38 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:28:53.809424 2026] [security2:error] [pid 4101969:tid 4101989] [client 61.9.8.38:32562] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.9.8.38 (+1 hits since last alert)|georgementz.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "georgementz.org"] [uri "/xmlrpc.php"] [unique_id "anaidQz2yfKCfOaF9c6pygAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-08-07 11:35:09
(2 weeks ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-08-07 05:49:07
(2 weeks ago)
(xmlrpc) Failed xmlrpc access from 61.9.8.38 (PH/Philippines/-): 5 in the last 3600 secs (0-122)
Hacking
๐ฆ๐บ
screwlooseit.com.au
2026-08-06 12:09:41
(2 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
PH/Philippines/-
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-04 15:50:13
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 15:23:10
(2 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-08-04 14:15:02
(2 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
PH/Philippines/-
Web App Attack