๐บ๐ธ
TPI-Abuse
2026-06-13 12:48:00
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.12 ...
show more
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 08:47:54.308433 2026] [security2:error] [pid 2433:tid 2433] [client 122.180.84.151:62230] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.180.84.151 (+1 hits since last alert)|jessicalevant.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jessicalevant.com"] [uri "/xmlrpc.php"] [unique_id "ai1RennpD2Pvr9S4cmv7MAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-13 12:47:49
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-13 07:09:02
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
masterguru
2026-06-13 03:21:46
(1 day ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-12 23:48:07
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.12 ...
show more
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 19:48:01.825378 2026] [security2:error] [pid 5181:tid 5181] [client 122.180.84.151:55511] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.180.84.151 (+1 hits since last alert)|papapizza.pizza|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "papapizza.pizza"] [uri "/xmlrpc.php"] [unique_id "aiyasQHH-Ec3TfHfDsb4UgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
applemooz
2026-06-12 23:14:58
(2 days ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 22:16:19
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.12 ...
show more
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 18:16:14.272130 2026] [security2:error] [pid 11600:tid 11625] [client 122.180.84.151:60244] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.180.84.151 (+1 hits since last alert)|grupojdg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "grupojdg.com"] [uri "/xmlrpc.php"] [unique_id "aiyFLtA28b1VHgZHRbJ6TAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 19:42:33
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.12 ...
show more
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 15:42:26.361049 2026] [security2:error] [pid 2832:tid 2832] [client 122.180.84.151:55945] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.180.84.151 (+1 hits since last alert)|blacktieokc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "blacktieokc.com"] [uri "/xmlrpc.php"] [unique_id "aixhIsp6L3QAH0SiX3xYOQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 17:01:13
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.12 ...
show more
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 13:01:08.575292 2026] [security2:error] [pid 15139:tid 15139] [client 122.180.84.151:50886] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.180.84.151 (+1 hits since last alert)|gracebaptisthartsville.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gracebaptisthartsville.com"] [uri "/xmlrpc.php"] [unique_id "aiw7VPeAnA8N9l-nx92utwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 11:51:56
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.12 ...
show more
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 07:51:51.860098 2026] [security2:error] [pid 3855:tid 3975] [client 122.180.84.151:53227] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.180.84.151 (+1 hits since last alert)|theyogicat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theyogicat.com"] [uri "/xmlrpc.php"] [unique_id "aivy165CzqplRYlVmV3W0QAAAsU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-12 11:36:10
(2 days ago)
trying wp-login.php/xmlrpc.php 34 times in 1 minutes
Brute-Force
Web App Attack
Anonymous
2026-06-12 10:46:21
(2 days ago)
Fail2Ban - Wordpress brute-force
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 09:48:06
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.12 ...
show more
(mod_security) mod_security (id:240335) triggered by 122.180.84.151 (abts-north-static-151.84.180.122.airtelbroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 05:48:02.648441 2026] [security2:error] [pid 3963:tid 3963] [client 122.180.84.151:50932] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 122.180.84.151 (+1 hits since last alert)|d-sinema.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "d-sinema.com"] [uri "/xmlrpc.php"] [unique_id "aivV0qt5uEwL2yMeO9b9vwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-12 09:14:34
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
WeekendWeb
2026-06-12 09:14:28
(2 days ago)
Wordpress Vunerability attack
Web App Attack