๐บ๐ธ
TPI-Abuse
2026-06-16 14:18:23
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 154.100.2.240 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.100.2.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 10:18:15.198715 2026] [security2:error] [pid 16934:tid 16934] [client 154.100.2.240:41930] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.100.2.240 (+1 hits since last alert)|wurkroom.biz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wurkroom.biz"] [uri "/xmlrpc.php"] [unique_id "ajFbJ7LFKOmgty-q3U6G_wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Kenshin869
2026-06-16 13:39:55
(20 hours ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-16 12:10:35
(22 hours ago)
(mod_security) mod_security (id:240335) triggered by 154.100.2.240 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.100.2.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 08:10:30.789783 2026] [security2:error] [pid 2081:tid 2101] [client 154.100.2.240:63801] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.100.2.240 (+1 hits since last alert)|tkfay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tkfay.com"] [uri "/xmlrpc.php"] [unique_id "ajE9Nond0QX78iFCicLh0wAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-16 08:04:35
(1 day ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ฉ๐ช
Marc
2026-06-15 16:19:40
(1 day ago)
154.100.2.240 - - [15/Jun/2026:18:19:18 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3466 "-" "Jetpack/13. ...
show more
154.100.2.240 - - [15/Jun/2026:18:19:18 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3466 "-" "Jetpack/13.0; WordPress/6.1; http://site54597286.com" 154.100.2.240 - - [15/Jun/2026:18:19:28 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3467 "-" "Jetpack by WordPress.com" 154.100.2.240 - - [15/Jun/2026:18:19:39 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3465 "-" "Jetpack by WordPress.com"
show less
Brute-Force
Web App Attack
Anonymous
2026-06-15 13:38:28
(1 day ago)
WordPress Brute Force
Brute-Force
Anonymous
2026-06-15 11:32:59
(1 day ago)
154.100.2.240 - - [15/Jun/2026:13:32:39 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by W ...
show more
154.100.2.240 - - [15/Jun/2026:13:32:39 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
154.100.2.240 - - [15/Jun/2026:13:32:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
154.100.2.240 - - [15/Jun/2026:13:32:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
154.100.2.240 - - [15/Jun/2026:13:32:48 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
154.100.2.240 - - [15/Jun/2026:13:32:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-15 10:48:42
(1 day ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-15 10:39:09
(1 day ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐ฌ๐ง
noise.agency
2026-06-15 07:50:48
(2 days ago)
(wordpress) Failed wordpress login from 154.100.2.240 (SD/Sudan/-)
Brute-Force
๐ซ๐ท
SpaceHost-Server
2026-06-10 22:27:05
(6 days ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 13:34:45
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 154.100.2.240 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.100.2.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 09:34:39.213348 2026] [security2:error] [pid 29002:tid 29002] [client 154.100.2.240:53765] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.100.2.240 (+1 hits since last alert)|pulleasy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pulleasy.com"] [uri "/xmlrpc.php"] [unique_id "ailn76p2XX0T9EZb2Be-twAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-10 13:25:10
(6 days ago)
Attac
Brute-Force
๐ฉ๐ช
rh24
2026-06-10 13:13:31
(6 days ago)
(wordpress) Failed wordpress login from 154.100.2.240 (SD/Sudan/-): (CF_ENABLE)
Brute-Force
Anonymous
2026-06-10 11:32:42
(6 days ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=weihnachtsbasar-athen.gr; logs=/var/log/httpd/domains/weihna ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=weihnachtsbasar-athen.gr; logs=/var/log/httpd/domains/weihnachtsbasar-athen.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack