๐ฉ๐ช
konseptit
2026-07-31 16:24:06
(45 minutes ago)
(wordpress) Failed wordpress login from 154.178.227.191 (EG/Egypt/-)
Brute-Force
๐ฆ๐บ
screwlooseit.com.au
2026-07-31 13:08:21
(4 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
EG/Egypt/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 11:38:15
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 154.178.227.191 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.178.227.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 07:38:08.876674 2026] [security2:error] [pid 626058:tid 626058] [client 154.178.227.191:47715] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.178.227.191 (+1 hits since last alert)|fernfield.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fernfield.com"] [uri "/xmlrpc.php"] [unique_id "amyJIAC1Sj7MPGr-ymMongAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-07-30 22:09:23
(18 hours ago)
(wordpress) Failed wordpress login from 154.178.227.191 (EG/Egypt/-)
Brute-Force
๐บ๐ธ
integrantservices.com
2026-07-29 19:02:34
(1 day ago)
(wordpress) Failed wordpress login from 154.178.227.191 (EG/Egypt/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-29 17:31:28
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 154.178.227.191 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.178.227.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 13:31:20.253583 2026] [security2:error] [pid 1728132:tid 1728132] [client 154.178.227.191:40383] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.178.227.191 (+1 hits since last alert)|isslv.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "isslv.net"] [uri "/xmlrpc.php"] [unique_id "amo46FHZJlUL0G1Ba2cYWwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-07-29 17:31:05
(1 day ago)
(wordpress) Failed wordpress login from 154.178.227.191 (EG/Egypt/-): (CF_ENABLE)
Brute-Force
๐ฉ๐ช
LRob
2026-07-29 15:47:58
(2 days ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.co ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-29 14:46:21
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 12:37:35
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 154.178.227.191 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.178.227.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 08:37:27.331876 2026] [security2:error] [pid 2717034:tid 2717034] [client 154.178.227.191:47996] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.178.227.191 (+1 hits since last alert)|legacy-insight.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "legacy-insight.com"] [uri "/xmlrpc.php"] [unique_id "amn0B4WG-hh280P8_oz3VQAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 21:46:42
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 154.178.227.191 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.178.227.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 17:46:37.651592 2026] [security2:error] [pid 3817731:tid 3817731] [client 154.178.227.191:49389] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.178.227.191 (+1 hits since last alert)|towlesilvapsychotherapy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "towlesilvapsychotherapy.com"] [uri "/xmlrpc.php"] [unique_id "amkjPe4R9b6h8WuDD1OrZgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-28 21:17:27
(2 days ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 08:41:51
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 154.178.227.191 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.178.227.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 04:41:43.910346 2026] [security2:error] [pid 3169471:tid 3169471] [client 154.178.227.191:43109] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.178.227.191 (+1 hits since last alert)|pathpa.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pathpa.org"] [uri "/xmlrpc.php"] [unique_id "amhrRxn0-T1Jzr0JMhEIBQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack