πΊπΈ
TPI-Abuse
2026-06-17 14:13:12
(29 minutes ago)
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 10:13:07.708273 2026] [security2:error] [pid 29911:tid 29911] [client 103.141.5.34:51713] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.141.5.34 (+1 hits since last alert)|cycontechnology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cycontechnology.com"] [uri "/xmlrpc.php"] [unique_id "ajKrc9Xlz_y6WJbfpRh6JQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-16 13:03:27
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 09:03:19.422637 2026] [security2:error] [pid 14195:tid 14195] [client 103.141.5.34:61390] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.141.5.34 (+1 hits since last alert)|bigholegolf.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bigholegolf.com"] [uri "/xmlrpc.php"] [unique_id "ajFJl2btSduJJL9dQ0_WBwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Kenshin869
2026-06-16 08:14:48
(1 day ago)
Wordpress unauthorized access attempt
Brute-Force
Anonymous
2026-06-15 17:26:44
(1 day ago)
[redacted] 103.141.5.34 - - [15/Jun/2026:19:25:59 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Wo ...
show more
[redacted] 103.141.5.34 - - [15/Jun/2026:19:25:59 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 103.141.5.34 - - [15/Jun/2026:19:26:10 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
[redacted] 103.141.5.34 - - [15/Jun/2026:19:26:21 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 103.141.5.34 - - [15/Jun/2026:19:26:32 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 103.141.5.34 - - [15/Jun/2026:19:26:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-15 14:41:54
(2 days ago)
[redacted] 103.141.5.34 - - [15/Jun/2026:16:41:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 103.141.5.34 - - [15/Jun/2026:16:41:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 103.141.5.34 - - [15/Jun/2026:16:41:22 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 103.141.5.34 - - [15/Jun/2026:16:41:32 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 103.141.5.34 - - [15/Jun/2026:16:41:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 103.141.5.34 - - [15/Jun/2026:16:41:53 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
π©πͺ
Marc
2026-06-12 18:27:20
(4 days ago)
103.141.5.34 - - [12/Jun/2026:20:26:48 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3296 "-" "Jetpack/13.0 ...
show more
103.141.5.34 - - [12/Jun/2026:20:26:48 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3296 "-" "Jetpack/13.0; WordPress/6.1; http://site45999637.com" 103.141.5.34 - - [12/Jun/2026:20:27:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3294 "-" "Jetpack/12.1; WordPress/6.4; http://site43371131.com" 103.141.5.34 - - [12/Jun/2026:20:27:19 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3295 "-" "Jetpack/12.0; WordPress/6.2; http://site53588313.com"
show less
Brute-Force
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-06-11 09:09:18
(6 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
PK/Pakistan/-
Web App Attack
π«π·
Kenshin869
2026-06-05 17:00:41
(1 week ago)
Wordpress unauthorized access attempt
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-05 16:08:52
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 12:08:44.712288 2026] [security2:error] [pid 5281:tid 5281] [client 103.141.5.34:56532] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.141.5.34 (+1 hits since last alert)|warpedweed.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "warpedweed.com"] [uri "/xmlrpc.php"] [unique_id "aiL0jHhRmS2PolzS-ZFKEQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-05 13:37:14
(1 week ago)
Attac
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-05 12:32:39
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 08:32:32.714533 2026] [security2:error] [pid 7326:tid 7332] [client 103.141.5.34:63992] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.141.5.34 (+1 hits since last alert)|teritemme.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "teritemme.com"] [uri "/xmlrpc.php"] [unique_id "aiLB4EQ0S0GCxcIk02HyQwAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-05 09:46:45
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 05:46:38.293999 2026] [security2:error] [pid 17751:tid 17751] [client 103.141.5.34:52110] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.141.5.34 (+1 hits since last alert)|persnicketyinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "persnicketyinc.com"] [uri "/xmlrpc.php"] [unique_id "aiKa_oBg95ZhE45UCdsAZgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
lostswordfish.com
2026-06-02 20:32:04
(2 weeks ago)
Wordfence waf block on lostswordfish
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 17:39:06
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.141.5.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:39:02.374911 2026] [security2:error] [pid 4111:tid 4111] [client 103.141.5.34:51704] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.141.5.34 (+1 hits since last alert)|yanlidesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yanlidesign.com"] [uri "/xmlrpc.php"] [unique_id "ah8VNpuvEQNvuGEAsA8DngAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 07:58:13
(2 weeks ago)
Attac
Brute-Force