๐บ๐ธ
TPI-Abuse
2026-07-24 18:01:06
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 114.130.156.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 114.130.156.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 14:01:02.924973 2026] [security2:error] [pid 603349:tid 603349] [client 114.130.156.175:38050] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.130.156.175 (+1 hits since last alert)|nypatriotcards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nypatriotcards.com"] [uri "/xmlrpc.php"] [unique_id "amOoXnbrVXM_yFJzfw3ngQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 17:55:54
(1 day ago)
(wordpress) Failed wordpress login from 114.130.156.175 (BD/Bangladesh/-)
Brute-Force
Anonymous
2026-07-24 15:21:44
(1 day ago)
[redacted] 114.130.156.175 - - [24/Jul/2026:17:21:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" ...
show more
[redacted] 114.130.156.175 - - [24/Jul/2026:17:21:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
[redacted] 114.130.156.175 - - [24/Jul/2026:17:21:14 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
[redacted] 114.130.156.175 - - [24/Jul/2026:17:21:21 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/13.0; WordPress/6.3; http://site83481006.com"
[redacted] 114.130.156.175 - - [24/Jul/2026:17:21:32 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 114.130.156.175 - - [24/Jul/2026:17:21:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 22:11:02
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 114.130.156.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 114.130.156.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 18:10:57.921002 2026] [security2:error] [pid 3623249:tid 3623249] [client 114.130.156.175:15540] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.130.156.175 (+1 hits since last alert)|kavahawaii.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kavahawaii.com"] [uri "/xmlrpc.php"] [unique_id "amKRccQQ-XRBNkPEeRcABQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 21:32:31
(2 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 21:05:58
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 114.130.156.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 114.130.156.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 17:05:52.940791 2026] [security2:error] [pid 2779270:tid 2779270] [client 114.130.156.175:15584] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.130.156.175 (+1 hits since last alert)|ucommsi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ucommsi.com"] [uri "/xmlrpc.php"] [unique_id "amKCMPO8LzN5etmzbDM6sgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
gigatech
2026-07-23 18:40:02
(2 days ago)
Webserver Probing
Web App Attack
Anonymous
2026-07-23 17:14:22
(2 days ago)
[redacted] 114.130.156.175 - - [23/Jul/2026:19:13:40 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6642 "-" ...
show more
[redacted] 114.130.156.175 - - [23/Jul/2026:19:13:40 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6642 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
[redacted] 114.130.156.175 - - [23/Jul/2026:19:13:50 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6597 "-" "WordPress.com; https://wordpress.com"
[redacted] 114.130.156.175 - - [23/Jul/2026:19:14:00 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6597 "-" "WordPress.com; https://wordpress.com"
[redacted] 114.130.156.175 - - [23/Jul/2026:19:14:13 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6597 "-" "WordPress.com; https://wordpress.com"
[redacted] 114.130.156.175 - - [23/Jul/2026:19:14:21 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6597 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 16:39:23
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 114.130.156.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 114.130.156.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 12:39:15.989391 2026] [security2:error] [pid 2508278:tid 2508278] [client 114.130.156.175:16013] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.130.156.175 (+1 hits since last alert)|gaeltv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gaeltv.com"] [uri "/xmlrpc.php"] [unique_id "amJDs0b5tTF4sLakZv7VyQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-23 13:58:47
(3 days ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.co ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.com
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-23 13:29:30
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 09:25:24
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 114.130.156.175 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 114.130.156.175 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:25:18.511032 2026] [security2:error] [pid 2585269:tid 2585269] [client 114.130.156.175:45205] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 114.130.156.175 (+1 hits since last alert)|saynotoofland.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "saynotoofland.org"] [uri "/xmlrpc.php"] [unique_id "amHd_hgpL8qt5UjjJFHzdQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-07-11 06:05:20
(2 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-07-09 04:23:38
(2 weeks ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐ซ๐ท
bigorre.org
2026-07-06 10:19:26
(2 weeks ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot