๐บ๐ธ
TPI-Abuse
2026-06-22 04:51:16
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 102.209.109.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 102.209.109.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 00:51:08.892960 2026] [security2:error] [pid 15781:tid 15817] [client 102.209.109.175:6243] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.209.109.175 (+1 hits since last alert)|rawhabitat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rawhabitat.com"] [uri "/xmlrpc.php"] [unique_id "aji_PJrf-uYO0in_MiPcSwAAAcc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 01:37:50
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 102.209.109.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 102.209.109.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 21:37:43.869756 2026] [security2:error] [pid 8694:tid 8694] [client 102.209.109.175:7039] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.209.109.175 (+1 hits since last alert)|convtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "convtek.com"] [uri "/xmlrpc.php"] [unique_id "ajiR59VP8SH2Tdzvob3b8AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-21 23:22:04
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 15:14:01
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 102.209.109.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 102.209.109.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 11:13:56.465568 2026] [security2:error] [pid 3653:tid 3653] [client 102.209.109.175:18680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.209.109.175 (+1 hits since last alert)|harwoodmechanical.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "harwoodmechanical.com"] [uri "/xmlrpc.php"] [unique_id "ajf_tL8uaS2PhGI7cA1YZgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 13:07:40
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 102.209.109.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 102.209.109.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 09:07:35.254501 2026] [security2:error] [pid 4613:tid 4613] [client 102.209.109.175:10571] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.209.109.175 (+1 hits since last alert)|advantagept.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "advantagept.org"] [uri "/xmlrpc.php"] [unique_id "ajfiF-nMZJ3ii1y-e361KAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 23:39:37
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 102.209.109.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 102.209.109.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 19:39:33.369466 2026] [security2:error] [pid 25822:tid 25822] [client 102.209.109.175:54030] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.209.109.175 (+1 hits since last alert)|assheton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "assheton.com"] [uri "/xmlrpc.php"] [unique_id "ajcktcX127d8kLV9piP84AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-20 21:12:04
(2 days ago)
trying wp-login.php/xmlrpc.php 32 times in 1 minutes
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-20 20:18:54
(2 days ago)
(wordpress) Failed wordpress login from 102.209.109.175 (UG/Uganda/-)
Brute-Force
Anonymous
2026-06-20 18:47:41
(2 days ago)
[redacted] 102.209.109.175 - - [20/Jun/2026:20:46:58 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 102.209.109.175 - - [20/Jun/2026:20:46:58 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 102.209.109.175 - - [20/Jun/2026:20:47:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.4; http://site71234874.com"
[redacted] 102.209.109.175 - - [20/Jun/2026:20:47:18 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.209.109.175 - - [20/Jun/2026:20:47:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 102.209.109.175 - - [20/Jun/2026:20:47:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
grassau.com
2026-06-20 08:01:04
(3 days ago)
(wordpress) Failed wordpress login from 102.209.109.175 (UG/Uganda/Kampala District/Kampala/-)
Brute-Force
Anonymous
2026-04-20 08:11:33
(2 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐ฎ๐ช
RoboSOC
2026-04-06 10:51:41
(2 months ago)
DLink DSL Remote OS Command Injection Vulnerability , PTR: PTR record not found
IoT Targeted
๐ง๐ท
SOC PR
2026-04-06 08:54:42
(2 months ago)
Attack detected: Comtrend Command Injection (CVE-2020-10173).
Web App Attack
Anonymous
2026-04-03 01:23:23
(2 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐ฉ๐ช
SMARTNET
2025-11-30 18:38:00
(6 months ago)
Aisuru(Mirai variant) DDoS
DDoS Attack