๐บ๐ธ
TPI-Abuse
2026-08-21 23:14:12
(4 hours ago)
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke) ...
show more
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 19:14:05.640279 2026] [security2:error] [pid 27641:tid 27641] [client 102.211.146.121:53657] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.211.146.121 (+1 hits since last alert)|whodatnation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whodatnation.com"] [uri "/xmlrpc.php"] [unique_id "aojbveX_U3TRPJk47vQGpwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 21:11:08
(6 hours ago)
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke) ...
show more
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 17:11:03.319562 2026] [security2:error] [pid 26420:tid 26448] [client 102.211.146.121:61349] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.211.146.121 (+1 hits since last alert)|councilofforeignministers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "councilofforeignministers.com"] [uri "/xmlrpc.php"] [unique_id "aoi-58OCnGPUM3Y5v5oqgQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-08-21 17:59:05
(9 hours ago)
102.211.146.121 - - [21/Aug/2026:13:56:16 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5765 "-" "WordPress ...
show more
102.211.146.121 - - [21/Aug/2026:13:56:16 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5765 "-" "WordPress.com; https://wordpress.com"
102.211.146.121 - - [21/Aug/2026:13:57:20 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5765 "-" "WordPress.com; https://wordpress.com"
102.211.146.121 - - [21/Aug/2026:13:58:02 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5765 "-" "WordPress.com; https://wordpress.com"
102.211.146.121 - - [21/Aug/2026:13:58:44 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5765 "-" "WordPress.com; https://wordpress.com"
102.211.146.121 - - [21/Aug/2026:13:59:05 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5765 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 14:00:32
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke) ...
show more
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 10:00:29.353668 2026] [security2:error] [pid 5379:tid 5379] [client 102.211.146.121:55735] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.211.146.121 (+1 hits since last alert)|capriexpress.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "capriexpress.com"] [uri "/xmlrpc.php"] [unique_id "aohZ_XjcmH6hH1f-8qGwQwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-21 07:06:40
(20 hours ago)
POST /xmlrpc.php HTTP/1.1
...
Brute-Force
๐ซ๐ท
dynamix
2026-08-20 21:37:35
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 19:09:24
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke) ...
show more
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 15:09:18.482030 2026] [security2:error] [pid 6609:tid 6609] [client 102.211.146.121:58770] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.211.146.121 (+1 hits since last alert)|feiz.church|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "feiz.church"] [uri "/xmlrpc.php"] [unique_id "aodQ3u4MoP8xdIuRHRkffwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 18:05:19
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke) ...
show more
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 14:05:12.567154 2026] [security2:error] [pid 29744:tid 29744] [client 102.211.146.121:59035] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.211.146.121 (+1 hits since last alert)|iplantotravel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iplantotravel.com"] [uri "/xmlrpc.php"] [unique_id "aodB2LduXnYtyQF761ucRAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-08-20 18:00:40
(1 day ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-20 16:00:35
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke) ...
show more
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 12:00:27.248378 2026] [security2:error] [pid 7728:tid 7728] [client 102.211.146.121:64699] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.211.146.121 (+1 hits since last alert)|xyncom.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "xyncom.com"] [uri "/xmlrpc.php"] [unique_id "aockm4SCenbEVL_neQZQJwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-20 14:27:45
(1 day ago)
[redacted] 102.211.146.121 - - [20/Aug/2026:16:27:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 102.211.146.121 - - [20/Aug/2026:16:27:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.211.146.121 - - [20/Aug/2026:16:27:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.211.146.121 - - [20/Aug/2026:16:27:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
[redacted] 102.211.146.121 - - [20/Aug/2026:16:27:34 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.4; http://site70906335.com"
[redacted] 102.211.146.121 - - [20/Aug/2026:16:27:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-08-20 11:47:39
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
102.211.146.121.unwired.co.ke
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 09:05:50
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke) ...
show more
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 05:05:42.832358 2026] [security2:error] [pid 5195:tid 5331] [client 102.211.146.121:62972] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.211.146.121 (+1 hits since last alert)|captechinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "captechinc.com"] [uri "/xmlrpc.php"] [unique_id "aobDZgPDLpp7REg-QHwrFwAAAhY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 13:59:10
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke) ...
show more
(mod_security) mod_security (id:240335) triggered by 102.211.146.121 (102.211.146.121.unwired.co.ke): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 09:59:03.242569 2026] [security2:error] [pid 32467:tid 32467] [client 102.211.146.121:62185] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.211.146.121 (+1 hits since last alert)|solarfarms.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solarfarms.info"] [uri "/xmlrpc.php"] [unique_id "aoW2pyknQxWaYLZBd72qpAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
INTEQ
2026-08-05 06:48:46
(2 weeks ago)
Web attack from 102.211.146.121
Web App Attack