Anonymous
2026-07-22 11:30:08
(18 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 09:27:28
(21 hours ago)
(mod_security) mod_security (id:240335) triggered by 122.161.53.30 (abts-north-dynamic-030.53.161.12 ...
show more
(mod_security) mod_security (id:240335) triggered by 122.161.53.30 (abts-north-dynamic-030.53.161.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 05:27:23.138334 2026] [security2:error] [pid 1168083:tid 1168083] [client 122.161.53.30:8462] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.161.53.30 (+1 hits since last alert)|peterndudar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "peterndudar.com"] [uri "/xmlrpc.php"] [unique_id "amCM-whWZAOS4pO7aJBjxAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 08:58:36
(21 hours ago)
(mod_security) mod_security (id:240335) triggered by 122.161.53.30 (abts-north-dynamic-030.53.161.12 ...
show more
(mod_security) mod_security (id:240335) triggered by 122.161.53.30 (abts-north-dynamic-030.53.161.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 04:58:28.861186 2026] [security2:error] [pid 5544:tid 5544] [client 122.161.53.30:27074] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.161.53.30 (+1 hits since last alert)|seagrovesrealty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "seagrovesrealty.com"] [uri "/xmlrpc.php"] [unique_id "amCGNFmaO-lawflfN6Kn0QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 08:54:53
(21 hours ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-22 08:43:59
(21 hours ago)
cloudlinux2 fail2ban: 2026-07-22 10:39:00,256 fail2ban.filter [1589]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-22 10:39:00,256 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 59.153.16.97 - 2026-07-22 10:39:00cloudlinux2 fail2ban: 2026-07-22 10:39:11,306 fail2ban.filter [1589]: INFO [plesk-wordpress] Found 172.98.32.49 - 2026-07-22 10:39:10cloudlinux2 fail2ban: 2026-07-22 10:39:30,571 fail2ban.filter [1589]: INFO [recidive] Found 117.238.127.91 - 2026-07-22 10:39:30cloudlinux2 fail2ban: 2026-07-22 10:39:30,202 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 117.238.127.91 - 2026-07-22 10:39:30cloudlinux2 fail2ban: 2026-07-22 10:39:30,565 fail2ban.actions [1589]: NOTICE [plesk-modsecurity] Ban 117.238.127.91cloudlinux2 fail2ban: 2026-07-22 10:39:53,367 fail2ban.filter [1589]: INFO [plesk-modsecurity] Found 122.161.53.30 - 2026-07-22 10:39:53cloudlinux2 fail2ban: 2026-07-22 10:40:03,226 fail2ban.filter [1589]: INFO [recidive] Found 59.153.16.97 - 2026-07-22 10:40:03cloudlinux2 fail2ban: 2026-07-22 10:40:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 07:03:10
(23 hours ago)
(mod_security) mod_security (id:240335) triggered by 122.161.53.30 (abts-north-dynamic-030.53.161.12 ...
show more
(mod_security) mod_security (id:240335) triggered by 122.161.53.30 (abts-north-dynamic-030.53.161.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 03:03:02.574146 2026] [security2:error] [pid 442350:tid 442350] [client 122.161.53.30:20649] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.161.53.30 (+1 hits since last alert)|casadelsolmexico.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "casadelsolmexico.net"] [uri "/xmlrpc.php"] [unique_id "amBrJlMWYoWrNoEIPbp5rAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-07-22 05:23:32
(1 day ago)
(wordpress) Failed wordpress login from 122.161.53.30 (IN/India/abts-north-dynamic-030.53.161.122.ai ...
show more
(wordpress) Failed wordpress login from 122.161.53.30 (IN/India/abts-north-dynamic-030.53.161.122.airtelbroadband.in)
show less
Brute-Force
๐ฉ๐ช
Vegascosmetics
2026-06-29 06:30:37
(3 weeks ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐ฉ๐ช
SMARTNET
2026-05-27 06:03:53
(1 month ago)
Aisuru(Mirai variant) DDoS | Incident ID: 22ada211-5b5c-463a-b46f-60fd11dc639d
DDoS Attack
๐ณ๐ฑ
exxos
2025-08-08 17:06:03
(11 months ago)
HTTP1.x attacks
DDoS Attack
๐ณ๐ฑ
exxos
2025-08-05 22:03:01
(11 months ago)
HTTP1.x attacks
DDoS Attack
๐ณ๐ฑ
exxos
2025-08-05 21:28:04
(11 months ago)
HTTP1.x attacks
DDoS Attack
๐บ๐ธ
antbr.com
2025-08-05 20:21:23
(11 months ago)
AntBR.com: [Web Probe]==> /index2.php?page=tutors%27&p=9
Web App Attack
๐ต๐น
Information Security
2025-08-05 19:03:41
(11 months ago)
Web App Attack
Web App Attack
๐ง๐ช
Ivo Vynckier
2025-04-10 17:31:00
(1 year ago)
122.161.53.30 - - [10/Apr/2025:08:45:53 +0200] "GET /wp-login.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 ...
show more
122.161.53.30 - - [10/Apr/2025:08:45:53 +0200] "GET /wp-login.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
122.161.53.30 - - [10/Apr/2025:08:45:53 +0200] "GET /xmlrpc.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
show less
Web App Attack