๐บ๐ธ
WeekendWeb
2025-12-30 05:06:59
(7 months ago)
Wordpress Vunerability attack
Web App Attack
๐ฆ๐น
Markus Woegerbauer
2025-12-30 03:13:03
(7 months ago)
(wordpress) Failed wordpress login from 153.122.206.1 (JP/Japan/gw.shared-server.net)
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-30 02:30:49
(7 months ago)
(mod_security) mod_security (id:240335) triggered by 153.122.206.1 (gw.shared-server.net): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 153.122.206.1 (gw.shared-server.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 21:30:42.524313 2025] [security2:error] [pid 14227:tid 14227] [client 153.122.206.1:52350] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.122.206.1 (+1 hits since last alert)|bluemarineboats.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bluemarineboats.com"] [uri "/xmlrpc.php"] [unique_id "aVM5UovTgX0bGnNg3LkZxAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-30 00:45:06
(7 months ago)
(mod_security) mod_security (id:240335) triggered by 153.122.206.1 (gw.shared-server.net): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 153.122.206.1 (gw.shared-server.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 19:45:01.635579 2025] [security2:error] [pid 14489:tid 14538] [client 153.122.206.1:56214] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.122.206.1 (+1 hits since last alert)|hmpdecors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hmpdecors.com"] [uri "/xmlrpc.php"] [unique_id "aVMgjUi4j_6OLeivcc4KmgAAAgE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
maxxsense
2025-12-29 20:55:44
(7 months ago)
(wordpress) Failed wordpress login from 153.122.206.1 (JP/Japan/gw.shared-server.net)
Brute-Force
Anonymous
2025-12-29 20:51:50
(7 months ago)
(wordpress) Failed wordpress login from 153.122.206.1 (JP/Japan/gw.shared-server.net)
Brute-Force
๐น๐ท
rtbh.com.tr
2025-12-29 20:10:43
(7 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-29 15:32:20
(7 months ago)
(mod_security) mod_security (id:240335) triggered by 153.122.206.1 (gw.shared-server.net): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 153.122.206.1 (gw.shared-server.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 10:32:14.456920 2025] [security2:error] [pid 28308:tid 28308] [client 153.122.206.1:48016] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.122.206.1 (+1 hits since last alert)|walterceron.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "walterceron.com"] [uri "/xmlrpc.php"] [unique_id "aVKe_mMtzd5IYvE6NIh2CgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-12-29 14:32:20
(7 months ago)
2.654 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ง๐พ
lns.bz
2025-12-29 12:17:15
(7 months ago)
Banned for trying to access xmlrpc [BY]
Web App Attack
๐ฆ๐บ
clapper
2025-12-29 11:20:37
(7 months ago)
(mod_security) mod_security (id:949110) triggered by 153.122.206.1 (JP/Japan/gw.shared-server.net): ...
show more
(mod_security) mod_security (id:949110) triggered by 153.122.206.1 (JP/Japan/gw.shared-server.net): 5 in the last 3600 secs; ID: rub
show less
Brute-Force
Bad Web Bot
๐ฆ๐บ
weblite
2025-12-29 11:13:02
(7 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 09:16:46
(7 months ago)
(mod_security) mod_security (id:240335) triggered by 153.122.206.1 (gw.shared-server.net): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 153.122.206.1 (gw.shared-server.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 04:16:42.623306 2025] [security2:error] [pid 4735:tid 4735] [client 153.122.206.1:34504] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.122.206.1 (+1 hits since last alert)|prcomputersolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "prcomputersolutions.com"] [uri "/xmlrpc.php"] [unique_id "aVJG-rfQM71vVQbgGDGsuQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 08:16:06
(7 months ago)
(mod_security) mod_security (id:240335) triggered by 153.122.206.1 (gw.shared-server.net): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 153.122.206.1 (gw.shared-server.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 03:15:59.858875 2025] [security2:error] [pid 2714:tid 2714] [client 153.122.206.1:60666] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 153.122.206.1 (+1 hits since last alert)|aemcmullin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aemcmullin.com"] [uri "/xmlrpc.php"] [unique_id "aVI4v7nIlyV0MZ0PjVTGvwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2025-12-29 05:43:25
(7 months ago)
153.122.206.1 - - [29/Dec/2025:06:43:19 +0100] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Mozilla/5.0 ...
show more
153.122.206.1 - - [29/Dec/2025:06:43:19 +0100] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Mozilla/5.0 (Linux; Android 10; SM-N960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36"
153.122.206.1 - - [29/Dec/2025:06:43:22 +0100] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Mozilla/5.0 (Linux; Android 10; SM-N960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36"
153.122.206.1 - - [29/Dec/2025:06:43:24 +0100] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Mozilla/5.0 (Linux; Android 10; SM-N960U) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/91.0.4472.114 Mobile Safari/537.36"
show less
Hacking
Web App Attack