๐บ๐ธ
TPI-Abuse
2026-05-12 19:59:30
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 15:59:25.775452 2026] [security2:error] [pid 28216:tid 28216] [client 103.178.77.68:54297] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.178.77.68 (+1 hits since last alert)|arthuryeung.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "arthuryeung.net"] [uri "/xmlrpc.php"] [unique_id "agOGnTUFLFsO-rq1__aSlQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-05-12 16:01:53
(3 weeks ago)
trying wp-login.php/xmlrpc.php 31 times in 1 minutes
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 15:50:34
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 11:50:27.516980 2026] [security2:error] [pid 18157:tid 18157] [client 103.178.77.68:60324] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.178.77.68 (+1 hits since last alert)|d-sinema.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "d-sinema.com"] [uri "/xmlrpc.php"] [unique_id "agNMQzJGDf5FMwBQTMgUwAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 15:20:39
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 11:20:31.152509 2026] [security2:error] [pid 11140:tid 11162] [client 103.178.77.68:51098] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.178.77.68 (+1 hits since last alert)|hearthandhomestudio.art|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hearthandhomestudio.art"] [uri "/xmlrpc.php"] [unique_id "agNFP134yWhc52xZmi9o1AAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-12 08:30:41
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 04:30:33.340656 2026] [security2:error] [pid 4999:tid 4999] [client 103.178.77.68:64044] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.178.77.68 (+1 hits since last alert)|studioyau.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "studioyau.com"] [uri "/xmlrpc.php"] [unique_id "agLlKWNzoIZUDERtTc8zKgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-12 08:29:16
(3 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-05-12 05:43:09
(3 weeks ago)
[redacted] 103.178.77.68 - - [12/May/2026:07:42:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "J ...
show more
[redacted] 103.178.77.68 - - [12/May/2026:07:42:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 103.178.77.68 - - [12/May/2026:07:42:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 103.178.77.68 - - [12/May/2026:07:42:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
[redacted] 103.178.77.68 - - [12/May/2026:07:42:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/12.0; WordPress/6.1; http://site58759810.com"
[redacted] 103.178.77.68 - - [12/May/2026:07:43:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 19:35:23
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 15:35:16.222351 2026] [security2:error] [pid 18572:tid 18572] [client 103.178.77.68:53842] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.178.77.68 (+1 hits since last alert)|midcityrotary.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "midcityrotary.org"] [uri "/xmlrpc.php"] [unique_id "agIvdJCoowKc83F6qurNEgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 09:28:03
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 05:27:59.769709 2026] [security2:error] [pid 5101:tid 5101] [client 103.178.77.68:50360] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.178.77.68 (+1 hits since last alert)|souldata.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "souldata.com"] [uri "/xmlrpc.php"] [unique_id "agGhH-tHHQBktqJwf-laiwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 08:28:33
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 04:28:26.201859 2026] [security2:error] [pid 30698:tid 30698] [client 103.178.77.68:58056] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.178.77.68 (+1 hits since last alert)|nearfieldchrist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nearfieldchrist.com"] [uri "/xmlrpc.php"] [unique_id "agGTKu9chG7-N2JfBg6RcgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Paulo Henrique dos Santos Nichio
2026-05-11 07:19:54
(3 weeks ago)
(ls_brute) LiteSpeed Brute Force Attack 103.178.77.68 (IN/India/-): 3 in the last 600 secs; Ports: * ...
show more
(ls_brute) LiteSpeed Brute Force Attack 103.178.77.68 (IN/India/-): 3 in the last 600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026-05-11 04:19:28.700461 [WARN] [147413] [T0] [103.178.77.68:60326-28#APVH_www.zanula.com.br:443] Brute force detected for IP [103.178.77.68], throttle.
2026-05-11 04:19:39.716785 [WARN] [147413] [T0] [103.178.77.68:60326-29#APVH_www.zanula.com.br:443] Brute force detected for IP [103.178.77.68], throttle.
2026-05-11 04:19:50.701478 [WARN] [147413] [T0] [103.178.77.68:60326-30#APVH_www.zanula.com.br:443] Brute force detected for IP [103.178.77.68], throttle.
show less
Port Scan
๐ณ๐ฑ
Site.eu
2026-05-11 04:39:07
(3 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-05-10 18:08:45
(3 weeks ago)
WordPress Brute Force
Brute-Force
๐ซ๐ท
/dev/null
2026-05-10 18:03:56
(3 weeks ago)
Brute-Force Logins
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 16:43:00
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.178.77.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 12:42:54.083986 2026] [security2:error] [pid 29722:tid 29722] [client 103.178.77.68:61217] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.178.77.68 (+1 hits since last alert)|prayers4america.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "prayers4america.com"] [uri "/xmlrpc.php"] [unique_id "agC1jiVMmakF5K4a83u9AgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack