๐บ๐ธ
TPI-Abuse
2026-08-22 13:05:38
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 105.120.129.116 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 105.120.129.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:05:30.368292 2026] [security2:error] [pid 29290:tid 29301] [client 105.120.129.116:29996] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 105.120.129.116 (+1 hits since last alert)|annacaird.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "annacaird.com"] [uri "/xmlrpc.php"] [unique_id "aomemiO577SXz-3mo_L4egAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-22 12:33:41
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ณ๐ฑ
maxxsense
2026-08-22 10:19:36
(1 day ago)
(wordpress) Failed wordpress login from 105.120.129.116 (NG/Nigeria/-)
Brute-Force
๐ฉ๐ช
ghostwarriors
2026-08-22 00:20:45
(1 day ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-08-22 00:13:45
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
NG/Nigeria/-
Web App Attack
Anonymous
2026-08-22 00:13:14
(1 day ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 20:13:54
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 105.120.129.116 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 105.120.129.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 16:13:51.075551 2026] [security2:error] [pid 20053:tid 20053] [client 105.120.129.116:34074] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 105.120.129.116 (+1 hits since last alert)|smilingorc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "smilingorc.com"] [uri "/xmlrpc.php"] [unique_id "aoixf0bLvI08K7WxdMxZ9AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-08-21 18:43:21
(2 days ago)
(wordpress) Failed wordpress login from 105.120.129.116 (NG/Nigeria/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-21 17:40:09
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 105.120.129.116 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 105.120.129.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 13:39:58.138868 2026] [security2:error] [pid 14679:tid 14679] [client 105.120.129.116:30470] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 105.120.129.116 (+1 hits since last alert)|adlc18.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "adlc18.org"] [uri "/xmlrpc.php"] [unique_id "aoiNbjvybKu1_3hRjgW2iQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-21 17:16:49
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 16:04:26
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 105.120.129.116 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 105.120.129.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 12:04:21.548271 2026] [security2:error] [pid 21043:tid 21043] [client 105.120.129.116:38883] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 105.120.129.116 (+1 hits since last alert)|caquintet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "caquintet.com"] [uri "/xmlrpc.php"] [unique_id "aoh3BQwGwk4RB6zsjXWlVgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-08-21 14:42:55
(2 days ago)
Wordpress Vunerability attack
Web App Attack
๐ธ๐ช
ljo
2026-08-21 14:12:58
(2 days ago)
105.120.129.116 - - [21/Aug/2026:16:11:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5269 "-" "Jetpack/1 ...
show more
105.120.129.116 - - [21/Aug/2026:16:11:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5269 "-" "Jetpack/12.5; WordPress/6.4; http://site87313038.com"
105.120.129.116 - - [21/Aug/2026:16:11:28 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5269 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
105.120.129.116 - - [21/Aug/2026:16:11:39 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5269 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
105.120.129.116 - - [21/Aug/2026:16:11:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5269 "-" "Jetpack/12.5; WordPress/6.2; http://site73962301.com"
105.120.129.116 - - [21/Aug/2026:16:12:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5269 "-" "Jetpack by WordPress.com"
105.120.129.116 - - [21/Aug/2026:16:12:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5269 "-" "WordPress.com; https://wordpress.com"
105.120.129.116 - - [21/Aug/2026:16:12:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5269 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
105.120.129.116 - - [21
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 10:59:27
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 105.120.129.116 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 105.120.129.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 06:59:20.858417 2026] [security2:error] [pid 27104:tid 27104] [client 105.120.129.116:30377] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 105.120.129.116 (+1 hits since last alert)|helloauto.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "helloauto.net"] [uri "/xmlrpc.php"] [unique_id "aogviGARmRZCkZK_GqULcwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
vtchost.com
2026-03-22 12:50:03
(5 months ago)
Mar 22 13:50:02 vtchost kernel: [127357.546564] PORTSCAN: IN=eth0 OUT= MAC=00:50:56:41:75:31:c0:69:1 ...
show more
Mar 22 13:50:02 vtchost kernel: [127357.546564] PORTSCAN: IN=eth0 OUT= MAC=00:50:56:41:75:31:c0:69:11:cd:2a:b3:08:00 SRC=105.120.129.116 DST=161.97.181.152 LEN=52 TOS=0x00 PREC=0x20 TTL=111 ID=23262 DF PROTO=TCP SPT=55271 DPT=445 WINDOW=8192 RES=0x00 SYN URGP=0
...
show less
Port Scan