๐น๐ท
neron
2026-08-19 04:26:21
(1 week ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-08-11 03:06:50
(2 weeks ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
๐น๐ท
neron
2026-07-30 03:06:20
(4 weeks ago)
CrowdSec blocked: firehol_cruzit_web_attacks detected via OPNsense firewall
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2024-12-27 09:15:33
(1 year ago)
154.221.16.86 - - [27/Dec/2024:11:14:48 +0200] "GET /wp-login.php HTTP/1.1" 404 275 "-" "Apache-Http ...
show more
154.221.16.86 - - [27/Dec/2024:11:14:48 +0200] "GET /wp-login.php HTTP/1.1" 404 275 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)"
154.221.16.86 - - [27/Dec/2024:11:15:32 +0200] "GET /xmlrpc.php HTTP/1.1" 404 275 "-" "Apache-HttpClient/4.5.2 (Java/1.8.0_161)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-26 05:53:34
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 26 00:53:27.833386 2024] [security2:error] [pid 24040:tid 24052] [client 154.221.16.86:49972] [client 154.221.16.86] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.221.16.86 (+1 hits since last alert)|property-management-companies-chicago.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "property-management-companies-chicago.com"] [uri "/xmlrpc.php"] [unique_id "Z2zvVxOHk_gAil3fEwzCWgAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2024-08-23 08:55:23
(2 years ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-08-11 19:58:53
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 11 15:58:47.373401 2024] [security2:error] [pid 28006:tid 28006] [client 154.221.16.86:53134] [client 154.221.16.86] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.221.16.86 (+1 hits since last alert)|www.kathydumesnilart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.kathydumesnilart.com"] [uri "/xmlrpc.php"] [unique_id "ZrkX9zUlDmw50X4cglrZZQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2024-08-10 17:17:00
(2 years ago)
Probes for xmlrpc.php files and inexistent URLs
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-10 01:59:29
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 21:59:23.383526 2024] [security2:error] [pid 16883:tid 16883] [client 154.221.16.86:62138] [client 154.221.16.86] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.221.16.86 (+1 hits since last alert)|www.nekstlevel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.nekstlevel.com"] [uri "/xmlrpc.php"] [unique_id "ZrbJeyzjkXOXoGXckRdoyAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-09 17:35:52
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 09 13:35:47.201117 2024] [security2:error] [pid 649472:tid 649472] [client 154.221.16.86:61539] [client 154.221.16.86] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.221.16.86 (+1 hits since last alert)|citrineartstudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "citrineartstudio.com"] [uri "/xmlrpc.php"] [unique_id "ZrZTcwlgKn2jcQ5yLtTM5gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2024-08-06 14:47:55
(2 years ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 154.221.16.86 (US/United States/-): ( ...
show more
(wordpress-user-enum) Failed wordpress-user-enum trigger from 154.221.16.86 (US/United States/-): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2024-08-05 07:51:47
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 05 03:51:39.243063 2024] [security2:error] [pid 30060:tid 30110] [client 154.221.16.86:60607] [client 154.221.16.86] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.221.16.86 (+1 hits since last alert)|www.dontbeajerklikeyourwork.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dontbeajerklikeyourwork.com"] [uri "/xmlrpc.php"] [unique_id "ZrCEi-DLtv5513f7R4e5pgAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2024-08-04 21:25:55
(2 years ago)
1.000 requests to */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2024-07-30 08:11:33
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.221.16.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 30 04:11:29.099337 2024] [security2:error] [pid 29633:tid 29633] [client 154.221.16.86:53501] [client 154.221.16.86] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.221.16.86 (+1 hits since last alert)|www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.vangentholding.com"] [uri "/xmlrpc.php"] [unique_id "ZqigMXCmIZg0CIakyPWJAwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Dolphi
2024-07-29 02:40:08
(2 years ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack