๐บ๐ธ
TPI-Abuse
2026-07-28 15:50:33
(11 hours ago)
(mod_security) mod_security (id:240335) triggered by 154.57.213.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.57.213.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 11:50:21.966369 2026] [security2:error] [pid 3172969:tid 3172969] [client 154.57.213.42:53149] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.57.213.42 (+1 hits since last alert)|theamarals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theamarals.com"] [uri "/xmlrpc.php"] [unique_id "amjPvTXZlQ4gzgbj17ENBgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-07-28 15:40:03
(11 hours ago)
(wordpress) Failed wordpress login from 154.57.213.42 (PK/Pakistan/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
kosada.com
2026-07-28 01:54:06
(1 day ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฉ๐ช
filstal.org
2026-07-22 01:38:43
(1 week ago)
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. U ...
show more
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. UA: Mozilla/5.0 (Windows NT 5.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.100 ADG/11.0.2566 AOLBUILD/11.0.2566 Safari/537.36
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-06-30 15:26:22
(4 weeks ago)
154.57.213.42 - - [30/Jun/2026:23:24:56 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack/12. ...
show more
154.57.213.42 - - [30/Jun/2026:23:24:56 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack/12.5; WordPress/6.2; http://site86357029.com"
154.57.213.42 - - [30/Jun/2026:23:25:06 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by WordPress.com"
154.57.213.42 - - [30/Jun/2026:23:26:21 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
๐ซ๐ท
masterguru
2026-06-18 04:26:25
(1 month ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ซ๐ท
dynamix
2026-06-18 04:23:55
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-16 06:53:05
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 12:57:38
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 154.57.213.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.57.213.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 08:57:27.086489 2026] [security2:error] [pid 21080:tid 21080] [client 154.57.213.42:52023] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.57.213.42 (+1 hits since last alert)|univey.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "univey.com"] [uri "/xmlrpc.php"] [unique_id "ai6lN84NGRlWhJWdDWWVYAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 11:48:13
(1 month ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-14 11:29:12
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 154.57.213.42 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.57.213.42 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 07:29:00.327583 2026] [security2:error] [pid 29532:tid 29532] [client 154.57.213.42:60864] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.57.213.42 (+1 hits since last alert)|brianwhitty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "brianwhitty.com"] [uri "/xmlrpc.php"] [unique_id "ai6QfL9vSTnD1knpRpO-2AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-06-09 08:38:11
(1 month ago)
154.57.213.42 - - [09/Jun/2026:1
...
Brute-Force
Anonymous
2026-06-04 08:30:40
(1 month ago)
Attac
Brute-Force
Anonymous
2026-06-02 07:48:17
(1 month ago)
Attac
Brute-Force