πΊπΈ
TPI-Abuse
2026-08-24 07:40:33
(6 hours ago)
(mod_security) mod_security (id:240335) triggered by 154.141.138.41 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 154.141.138.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:40:25.853879 2026] [security2:error] [pid 14365:tid 14365] [client 154.141.138.41:3674] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.141.138.41 (+1 hits since last alert)|comicpreservation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "comicpreservation.com"] [uri "/xmlrpc.php"] [unique_id "aov1aftEX4lLX1n49hT7IgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-24 07:21:53
(6 hours ago)
(mod_security) mod_security (id:240335) triggered by 154.141.138.41 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 154.141.138.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:21:47.103281 2026] [security2:error] [pid 11508:tid 11508] [client 154.141.138.41:3604] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.141.138.41 (+1 hits since last alert)|azcrittergetter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "azcrittergetter.com"] [uri "/xmlrpc.php"] [unique_id "aovxCxPERQdmtVtdoX4A0wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
applemooz
2026-08-24 07:07:29
(6 hours ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
πΊπΈ
n2nguyenn2nguyen
2026-08-24 06:47:36
(7 hours ago)
Blocked by YFC Security on https://fencingforward.com β type: xmlrpc_attempts
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 21:29:22
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 154.141.138.41 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 154.141.138.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 17:29:13.559719 2026] [security2:error] [pid 9945:tid 9945] [client 154.141.138.41:3597] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.141.138.41 (+1 hits since last alert)|bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bernsteinip.com"] [uri "/xmlrpc.php"] [unique_id "aotmKcihJgS0nR-_np6BiQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-08-23 20:13:59
(17 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
π§πͺ
cmbplf
2026-08-23 13:29:21
(1 day ago)
7.082 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-08-23 13:10:06
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 154.141.138.41 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 154.141.138.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 09:09:57.348307 2026] [security2:error] [pid 6444:tid 6452] [client 154.141.138.41:3463] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.141.138.41 (+1 hits since last alert)|inal.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "inal.org"] [uri "/xmlrpc.php"] [unique_id "aorxJfcR_MXpgcUlC0Bb7wAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 12:38:24
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 154.141.138.41 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 154.141.138.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:38:19.266643 2026] [security2:error] [pid 24314:tid 24314] [client 154.141.138.41:3773] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.141.138.41 (+1 hits since last alert)|coolcustomweddingproducts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "coolcustomweddingproducts.com"] [uri "/xmlrpc.php"] [unique_id "aorpu7-W8jAa0d1rSJGQEgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 12:36:50
(1 day ago)
[redacted] 154.141.138.41 - - [23/Aug/2026:14:36:07 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 154.141.138.41 - - [23/Aug/2026:14:36:07 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 154.141.138.41 - - [23/Aug/2026:14:36:18 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 154.141.138.41 - - [23/Aug/2026:14:36:28 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.3; http://site10751014.com"
[redacted] 154.141.138.41 - - [23/Aug/2026:14:36:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 154.141.138.41 - - [23/Aug/2026:14:36:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack