Anonymous
2026-07-29 07:00:00
(12 hours ago)
Automated Apache web application probing in selected 24h window; attempts=21, unique_paths=1, error_ ...
show more
Automated Apache web application probing in selected 24h window; attempts=21, unique_paths=1, error_responses=15; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(12 hours ago)
Apache probe; attempts=21; exact paths: /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 22:57:54
(21 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.147.239.118 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.147.239.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 18:57:46.444075 2026] [security2:error] [pid 1520400:tid 1520400] [client 103.147.239.118:54862] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.147.239.118 (+1 hits since last alert)|drjasonkolber.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "drjasonkolber.com"] [uri "/xmlrpc.php"] [unique_id "amkz6oEl9-LDudUKwrF4YgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-28 22:30:44
(21 hours ago)
103.147.239.118 - - [28/Jul/2026:18:27:45 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "WordPress ...
show more
103.147.239.118 - - [28/Jul/2026:18:27:45 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "WordPress.com; https://wordpress.com"
103.147.239.118 - - [28/Jul/2026:18:28:06 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "WordPress.com; https://wordpress.com"
103.147.239.118 - - [28/Jul/2026:18:29:19 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "WordPress.com; https://wordpress.com"
103.147.239.118 - - [28/Jul/2026:18:30:12 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "WordPress.com; https://wordpress.com"
103.147.239.118 - - [28/Jul/2026:18:30:43 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5092 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 18:54:54
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.147.239.118 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.147.239.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 14:54:49.572048 2026] [security2:error] [pid 1411:tid 1411] [client 103.147.239.118:54388] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.147.239.118 (+1 hits since last alert)|lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lysedzija.com"] [uri "/xmlrpc.php"] [unique_id "amj6-QGLX-5nNqiXVCANQgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 18:21:24
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.147.239.118 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.147.239.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 14:21:18.292823 2026] [security2:error] [pid 1533353:tid 1533353] [client 103.147.239.118:64551] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.147.239.118 (+1 hits since last alert)|batesstrategygroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "batesstrategygroup.com"] [uri "/xmlrpc.php"] [unique_id "amjzHrDyic3CW7Fn4u50YwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-07-28 14:20:04
(1 day ago)
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-07-28 14:13:06
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 13:27:49
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.147.239.118 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.147.239.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 09:27:45.082777 2026] [security2:error] [pid 1855478:tid 1855478] [client 103.147.239.118:64673] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.147.239.118 (+1 hits since last alert)|lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lahamradio.com"] [uri "/xmlrpc.php"] [unique_id "amiuUQATx8-FWYPb2NNNvgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 12:57:51
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.147.239.118 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.147.239.118 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 08:57:43.830541 2026] [security2:error] [pid 1863302:tid 1863302] [client 103.147.239.118:52828] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.147.239.118 (+1 hits since last alert)|guarinofurnituredesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "guarinofurnituredesigns.com"] [uri "/xmlrpc.php"] [unique_id "aminR0Ork-72sfZ9ule22AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-28 12:37:33
(1 day ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐ช๐ธ
alferez
2026-07-28 12:29:26
(1 day ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack