๐บ๐ธ
TPI-Abuse
2026-08-14 11:24:12
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 122.172.87.11 (abts-kk-dynamic-011.87.172.122.a ...
show more
(mod_security) mod_security (id:240335) triggered by 122.172.87.11 (abts-kk-dynamic-011.87.172.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 07:24:03.851999 2026] [security2:error] [pid 26808:tid 26808] [client 122.172.87.11:30878] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.172.87.11 (+1 hits since last alert)|boraimpact.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "boraimpact.com"] [uri "/xmlrpc.php"] [unique_id "an7605EQcXmvSfyb8UTEGQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 09:19:22
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 122.172.87.11 (abts-kk-dynamic-011.87.172.122.a ...
show more
(mod_security) mod_security (id:240335) triggered by 122.172.87.11 (abts-kk-dynamic-011.87.172.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 05:19:16.244305 2026] [security2:error] [pid 14655:tid 14658] [client 122.172.87.11:24000] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.172.87.11 (+1 hits since last alert)|designshopadmin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "designshopadmin.com"] [uri "/xmlrpc.php"] [unique_id "an7dlEBXH4LsiaBzCKWv3gAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 08:48:57
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 122.172.87.11 (abts-kk-dynamic-011.87.172.122.a ...
show more
(mod_security) mod_security (id:240335) triggered by 122.172.87.11 (abts-kk-dynamic-011.87.172.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 04:48:51.160001 2026] [security2:error] [pid 30486:tid 30486] [client 122.172.87.11:27154] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.172.87.11 (+1 hits since last alert)|dwightbrown.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dwightbrown.com"] [uri "/xmlrpc.php"] [unique_id "an7Wc8bk9wtPfCvFEIU3GAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-08-14 08:16:07
(1 week ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
IN/India/abts-kk-dynamic-011.87.172.122.airtelbroadband.in
Web App Attack
๐ง๐ช
madeit
2026-08-14 07:34:56
(1 week ago)
Web App Attack
๐ฉ๐ช
4server
2026-08-14 06:06:18
(1 week ago)
[FriAug1408:06:12.7838592026][security2:error][pid1002753:tid1002765][client122.172.87.11:0]ModSecur ...
show more
[FriAug1408:06:12.7838592026][security2:error][pid1002753:tid1002765][client122.172.87.11:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"pluriball.ch\"][uri\"/xmlrpc.php\"][unique_id\"an6wVDoVIxhpUIVntK6icAAAAMk\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-08-14 06:03:03
(1 week ago)
Bot / scanning and/or hacking attempts: GET /wp-json/wp/v2/users?ver=0.43332054446241003 HTTP/1.1, P ...
show more
Bot / scanning and/or hacking attempts: GET /wp-json/wp/v2/users?ver=0.43332054446241003 HTTP/1.1, POST /xmlrpc.php HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
HERA - Operations
2026-08-14 04:57:19
(1 week ago)
sensobox - searching for vulnerable scripts: xmlrpc.php 2026/08/14 06:57:19
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-13 13:46:31
(1 week ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ท
dynamix
2026-08-13 07:57:02
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
maxxsense
2026-08-13 07:13:17
(1 week ago)
(wordpress) Failed wordpress login from 122.172.87.11 (IN/India/abts-kk-dynamic-011.87.172.122.airte ...
show more
(wordpress) Failed wordpress login from 122.172.87.11 (IN/India/abts-kk-dynamic-011.87.172.122.airtelbroadband.in)
show less
Brute-Force
๐บ๐ธ
ersei.net
2026-05-31 10:43:09
(2 months ago)
Web app exploiting
Web App Attack
๐บ๐ธ
MPL
2025-10-25 10:34:15
(9 months ago)
tcp/445 (2 or more attempts)
Port Scan
๐ซ๐ท
sthoyer.de
2025-10-25 06:42:18
(9 months ago)
Oct 25 08:42:17 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f ...
show more
Oct 25 08:42:17 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=122.172.87.11 DST=173.212.223.67 LEN=52 TOS=0x00 PREC=0x00 TTL=118 ID=23439 DF PROTO=TCP SPT=30429 DPT=445 WINDOW=8192 RES=0x00 SYN URGP=0
...
show less
Port Scan
๐ซ๐ท
sthoyer.de
2025-10-25 05:29:24
(9 months ago)
Oct 25 07:29:23 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f ...
show more
Oct 25 07:29:23 sthoyer kernel: [IPTables-Block] IN=eth0 OUT= MAC=00:50:56:43:00:af:c0:69:11:cd:10:f7:08:00 SRC=122.172.87.11 DST=173.212.223.67 LEN=52 TOS=0x00 PREC=0x00 TTL=118 ID=15519 DF PROTO=TCP SPT=19584 DPT=445 WINDOW=8192 RES=0x00 SYN URGP=0
...
show less
Port Scan