๐ซ๐ท
dynamix
2026-07-21 09:14:02
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฌ๐ง
gigatech
2026-07-21 07:55:03
(3 days ago)
Webserver Probing
Web App Attack
๐ซ๐ฎ
YF
2026-07-21 03:00:23
(3 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-21 00:42:29
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 154.227.131.209 (209-131-227-154.r.airtel.ug): ...
show more
(mod_security) mod_security (id:240335) triggered by 154.227.131.209 (209-131-227-154.r.airtel.ug): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 20:42:25.250646 2026] [security2:error] [pid 16738:tid 16738] [client 154.227.131.209:23014] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.227.131.209 (+1 hits since last alert)|huntingforebears.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "huntingforebears.com"] [uri "/xmlrpc.php"] [unique_id "al7Accnk0G16oDPcGHdwGAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:08:49
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 154.227.131.209 (209-131-227-154.r.airtel.ug): ...
show more
(mod_security) mod_security (id:240335) triggered by 154.227.131.209 (209-131-227-154.r.airtel.ug): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:08:43.190833 2026] [security2:error] [pid 13992:tid 14011] [client 154.227.131.209:24799] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.227.131.209 (+1 hits since last alert)|managementlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "managementlaw.com"] [uri "/xmlrpc.php"] [unique_id "al6qe2JDwmrzN4tgCZcDhQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-07-20 20:03:42
(3 days ago)
Probing websites for vulnerabilities
Web App Attack
Anonymous
2026-07-20 17:00:19
(3 days ago)
(wordpress) Failed wordpress login from 154.227.131.209 (UG/Uganda/Kampala District/Kampala/209-131- ...
show more
(wordpress) Failed wordpress login from 154.227.131.209 (UG/Uganda/Kampala District/Kampala/209-131-227-154.r.airtel.ug/[redacted])
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-20 15:30:22
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 154.227.131.209 (209-131-227-154.r.airtel.ug): ...
show more
(mod_security) mod_security (id:240335) triggered by 154.227.131.209 (209-131-227-154.r.airtel.ug): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 11:30:18.006154 2026] [security2:error] [pid 1507645:tid 1507645] [client 154.227.131.209:4102] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.227.131.209 (+1 hits since last alert)|guarinofurnituredesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "guarinofurnituredesigns.com"] [uri "/xmlrpc.php"] [unique_id "al4_Cqsg-T6CGuRHh_z0RAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-07-20 14:57:27
(3 days ago)
(wordpress) Failed wordpress login from 154.227.131.209 (UG/Uganda/209-131-227-154.r.airtel.ug)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-20 10:47:18
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 154.227.131.209 (209-131-227-154.r.airtel.ug): ...
show more
(mod_security) mod_security (id:240335) triggered by 154.227.131.209 (209-131-227-154.r.airtel.ug): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 06:47:10.624870 2026] [security2:error] [pid 27414:tid 27414] [client 154.227.131.209:24752] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.227.131.209 (+1 hits since last alert)|passy.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "passy.us"] [uri "/xmlrpc.php"] [unique_id "al38rucjT3PmLhnEJmQXeAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
exxos
2025-08-31 13:05:12
(10 months ago)
Attacks with Bad user agents
Hacking
๐ณ๐ฑ
exxos
2025-08-31 12:03:01
(10 months ago)
http-no-verb
Hacking
๐ง๐ช
Ivo Vynckier
2024-08-02 14:24:00
(1 year ago)
154.227.131.209 - - [02/Aug/2024:12:15:59 +0200] "GET /wp-login.php HTTP/1.1" 404 27 "-" "Mozilla/5. ...
show more
154.227.131.209 - - [02/Aug/2024:12:15:59 +0200] "GET /wp-login.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
154.227.131.209 - - [02/Aug/2024:12:16:00 +0200] "GET /xmlrpc.php HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
show less
Web App Attack