๐บ๐ธ
TPI-Abuse
2026-06-18 06:35:28
(19 hours ago)
(mod_security) mod_security (id:240335) triggered by 14.139.60.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 14.139.60.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 02:35:21.759179 2026] [security2:error] [pid 6213:tid 6213] [client 14.139.60.17:64284] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 14.139.60.17 (+1 hits since last alert)|genevaatlantic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "genevaatlantic.com"] [uri "/xmlrpc.php"] [unique_id "ajORqdw5uuY67gG7FIxqUAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-06-18 05:41:10
(20 hours ago)
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 05:03:44
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 14.139.60.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 14.139.60.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 01:03:38.527338 2026] [security2:error] [pid 10591:tid 10591] [client 14.139.60.17:56963] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 14.139.60.17 (+1 hits since last alert)|theyoungstrategist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theyoungstrategist.com"] [uri "/xmlrpc.php"] [unique_id "ajN8KiqaulvOEjLB03ek6QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-18 04:00:50
(21 hours ago)
[redacted] 14.139.60.17 - - [18/Jun/2026:06:00:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 14.139.60.17 - - [18/Jun/2026:06:00:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 14.139.60.17 - - [18/Jun/2026:06:00:14 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 14.139.60.17 - - [18/Jun/2026:06:00:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 14.139.60.17 - - [18/Jun/2026:06:00:35 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.2; http://site50985036.com"
[redacted] 14.139.60.17 - - [18/Jun/2026:06:00:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-17 11:17:29
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-06-17 10:16:13
(1 day ago)
[redacted] 14.139.60.17 - - [17/Jun/2026:12:15:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 14.139.60.17 - - [17/Jun/2026:12:15:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 14.139.60.17 - - [17/Jun/2026:12:15:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.3; http://site29380965.com"
[redacted] 14.139.60.17 - - [17/Jun/2026:12:15:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 14.139.60.17 - - [17/Jun/2026:12:16:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 14.139.60.17 - - [17/Jun/2026:12:16:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.3; http://site17830787.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 06:23:59
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 14.139.60.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 14.139.60.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 02:23:53.464022 2026] [security2:error] [pid 28783:tid 28807] [client 14.139.60.17:51339] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 14.139.60.17 (+1 hits since last alert)|abusaimeh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abusaimeh.com"] [uri "/xmlrpc.php"] [unique_id "ajI9eVdBnOoLiHK7CBfNngAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-16 10:38:13
(2 days ago)
Attac
Brute-Force
๐ฉ๐ช
rh24
2026-06-15 06:59:01
(3 days ago)
(xmlrpc_405) XMLRPC-Bot 405 14.139.60.17 (IN/India/-)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-12 06:03:10
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 14.139.60.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 14.139.60.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 02:03:00.585076 2026] [security2:error] [pid 24345:tid 24360] [client 14.139.60.17:51704] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 14.139.60.17 (+1 hits since last alert)|whitecrosslibrary.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whitecrosslibrary.com"] [uri "/xmlrpc.php"] [unique_id "aiuhFNLhk5gYv8h7wcZwZAAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-12 05:28:52
(6 days ago)
[redacted] 14.139.60.17 - - [12/Jun/2026:07:28:10 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 14.139.60.17 - - [12/Jun/2026:07:28:10 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.2; http://site73237854.com"
[redacted] 14.139.60.17 - - [12/Jun/2026:07:28:20 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 14.139.60.17 - - [12/Jun/2026:07:28:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 14.139.60.17 - - [12/Jun/2026:07:28:41 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 14.139.60.17 - - [12/Jun/2026:07:28:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.2; http://site79915755.com"
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-11 10:50:00
(1 week ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-06-11 07:24:10
(1 week ago)
[osotir.org] httpd-xmlrpc-post: sites=logosparakliseos.gr; logs=/var/log/httpd/domains/logosparaklis ...
show more
[osotir.org] httpd-xmlrpc-post: sites=logosparakliseos.gr; logs=/var/log/httpd/domains/logosparakliseos.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-06-11 07:22:42
(1 week ago)
14.139.60.17 - - [11/Jun/2026:15:22:21 +0800] "POST /xmlrpc.php HTTP/1.1" 200 4491 "-" "Jetpack/12.1 ...
show more
14.139.60.17 - - [11/Jun/2026:15:22:21 +0800] "POST /xmlrpc.php HTTP/1.1" 200 4491 "-" "Jetpack/12.1; WordPress/6.4; http://site77799439.com"
14.139.60.17 - - [11/Jun/2026:15:22:31 +0800] "POST /xmlrpc.php HTTP/1.1" 200 4491 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
14.139.60.17 - - [11/Jun/2026:15:22:42 +0800] "POST /xmlrpc.php HTTP/1.1" 200 4491 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-10 07:27:27
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 14.139.60.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 14.139.60.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 03:27:22.917993 2026] [security2:error] [pid 14940:tid 14940] [client 14.139.60.17:64985] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 14.139.60.17 (+1 hits since last alert)|mundanestudies.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mundanestudies.org"] [uri "/xmlrpc.php"] [unique_id "aikR2hRoFfHAr-FQ43fF6gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack