๐บ๐ธ
TPI-Abuse
2026-07-24 22:15:15
(2 hours ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 18:15:04.865414 2026] [security2:error] [pid 88818:tid 88818] [client 124.158.42.43:38442] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.43 (+1 hits since last alert)|madisonmedia.ai|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "madisonmedia.ai"] [uri "/xmlrpc.php"] [unique_id "amPj6C4vsfLjVcRvjqRlTQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-24 11:49:26
(12 hours ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 12:19:18
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 08:19:05.269839 2026] [security2:error] [pid 852180:tid 852180] [client 124.158.42.43:57640] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.43 (+1 hits since last alert)|capriexpress.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "capriexpress.com"] [uri "/xmlrpc.php"] [unique_id "amC1OR5a9eS9pW26NsonywAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 12:43:57
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:43:46.075093 2026] [security2:error] [pid 7859:tid 7859] [client 124.158.42.43:17073] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.43 (+1 hits since last alert)|tcomputerguy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tcomputerguy.com"] [uri "/xmlrpc.php"] [unique_id "al9pgqBF9FgrHsEGU41koAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-07-21 09:10:05
(3 days ago)
Wordfence waf block on flintlocal432
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 07:01:32
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 03:01:22.189874 2026] [security2:error] [pid 19574:tid 19574] [client 124.158.42.43:38382] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.43 (+1 hits since last alert)|rodandreelpiercam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rodandreelpiercam.com"] [uri "/xmlrpc.php"] [unique_id "al8ZQlZgcB1qu6eysB0rSwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-21 04:53:56
(3 days ago)
cloudlinux2 fail2ban: 2026-07-21 06:49:56,471 fail2ban.filter [1927]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-21 06:49:56,471 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 124.158.42.43 - 2026-07-21 06:49:56cloudlinux2 fail2ban: 2026-07-21 06:50:05,595 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 180.153.236.227 - 2026-07-21 06:50:05cloudlinux2 fail2ban: 2026-07-21 06:51:10,450 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 124.158.42.43 - 2026-07-21 06:51:10cloudlinux2 fail2ban: 2026-07-21 06:51:10,845 fail2ban.actions [1927]: NOTICE [plesk-modsecurity] Ban 124.158.42.43cloudlinux2 fail2ban: 2026-07-21 06:51:10,851 fail2ban.filter [1927]: INFO [recidive] Found 124.158.42.43 - 2026-07-21 06:51:10cloudlinux2 fail2ban: 2026-07-21 06:52:17,633 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 45.3.37.113 - 2026-07-21 06:52:17cloudlinux2 fail2ban: 2026-07-21 06:52:32,066 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 195.178.110.223 - 2026-07-21 06:52:32cloudlinux2 fail2ban: 2026
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-20 23:15:45
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:15:33.554095 2026] [security2:error] [pid 3184223:tid 3184223] [client 124.158.42.43:22796] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.43 (+1 hits since last alert)|solarfarms.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solarfarms.info"] [uri "/xmlrpc.php"] [unique_id "al6sFQ7y6d9ZLtc0b1TBRQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 11:44:44
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 07:44:34.188182 2026] [security2:error] [pid 4006736:tid 4006736] [client 124.158.42.43:55742] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.43 (+1 hits since last alert)|cynosurehomeservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cynosurehomeservices.com"] [uri "/xmlrpc.php"] [unique_id "al4KIiQNPgOBmhtgiGlbZgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-17 21:04:38
(1 week ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack