๐บ๐ธ
TPI-Abuse
2026-07-19 09:40:43
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 120.56.172.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.172.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 05:40:37.785496 2026] [security2:error] [pid 1338:tid 1338] [client 120.56.172.129:55996] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.172.129 (+1 hits since last alert)|ucommsi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ucommsi.com"] [uri "/xmlrpc.php"] [unique_id "alybla4ptJZLZMArPJgnfgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-07-19 08:55:38
(4 days ago)
Wordpress Vunerability attack
Web App Attack
๐ฌ๐ง
Apache
2026-07-19 06:20:45
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 120.56.172.129 (IN/India/-): 5 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.172.129 (IN/India/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 05:34:11
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 120.56.172.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.172.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 01:34:05.148538 2026] [security2:error] [pid 30860:tid 30860] [client 120.56.172.129:49856] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.172.129 (+1 hits since last alert)|baselinesc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "baselinesc.com"] [uri "/xmlrpc.php"] [unique_id "alxhzekS79rVI_jF6H8zLgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-07-19 03:04:25
(4 days ago)
Web App Attack
๐ช๐ธ
masterguru
2026-07-19 01:14:36
(4 days ago)
(xmlrpc) Failed xmlrpc access from 120.56.172.129 (IN/India/-): 5 in the last 3600 secs (0-122)
Hacking
๐บ๐ธ
TAY
2026-07-19 00:28:59
(4 days ago)
120.56.172.129 - - [19/Jul/2026:08:28:38 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "Jetpack by ...
show more
120.56.172.129 - - [19/Jul/2026:08:28:38 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "Jetpack by WordPress.com"
120.56.172.129 - - [19/Jul/2026:08:28:48 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "Jetpack by WordPress.com"
120.56.172.129 - - [19/Jul/2026:08:28:59 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-18 23:29:27
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 120.56.172.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.172.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 19:29:20.416071 2026] [security2:error] [pid 32568:tid 32568] [client 120.56.172.129:58271] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.172.129 (+1 hits since last alert)|lemoulinavent.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lemoulinavent.org"] [uri "/xmlrpc.php"] [unique_id "alwMUIIwchide0SGjQBMdgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-18 22:56:04
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
tecnicorioja
2026-07-18 22:00:45
(4 days ago)
POST /xmlrpc.php [18/Jul/2026:16:20:23
Brute-Force
Web App Attack
๐ณ๐ฑ
debestelapp
2026-07-18 20:30:07
(4 days ago)
Web App Attack
Anonymous
2026-07-18 18:49:03
(4 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-18 17:20:20
(5 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-18 16:59:47
(5 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 16:16:59
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 120.56.172.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.172.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 12:16:52.077655 2026] [security2:error] [pid 605829:tid 605829] [client 120.56.172.129:54073] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.172.129 (+1 hits since last alert)|jellisonrepair.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jellisonrepair.com"] [uri "/xmlrpc.php"] [unique_id "alum9Fvt_Bq_HdSNKDhDIAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack