๐บ๐ธ
TPI-Abuse
2026-06-14 12:14:02
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 156.155.14.58 (156-155-14-58.ip.internet.co.za) ...
show more
(mod_security) mod_security (id:240335) triggered by 156.155.14.58 (156-155-14-58.ip.internet.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 08:13:56.022546 2026] [security2:error] [pid 18377:tid 18377] [client 156.155.14.58:59295] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.155.14.58 (+1 hits since last alert)|bervick.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bervick.com"] [uri "/xmlrpc.php"] [unique_id "ai6bBHNmC2LRDu8FQ6vbNwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 11:46:09
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 156.155.14.58 (156-155-14-58.ip.internet.co.za) ...
show more
(mod_security) mod_security (id:240335) triggered by 156.155.14.58 (156-155-14-58.ip.internet.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 07:46:03.228028 2026] [security2:error] [pid 10968:tid 10968] [client 156.155.14.58:33989] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.155.14.58 (+1 hits since last alert)|lighthousescm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lighthousescm.com"] [uri "/xmlrpc.php"] [unique_id "ai6Ue9wUdPrzgp4K-czoEgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 10:42:56
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 156.155.14.58 (156-155-14-58.ip.internet.co.za) ...
show more
(mod_security) mod_security (id:240335) triggered by 156.155.14.58 (156-155-14-58.ip.internet.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:42:48.595485 2026] [security2:error] [pid 6603:tid 6603] [client 156.155.14.58:64551] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.155.14.58 (+1 hits since last alert)|badgerkelley.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "badgerkelley.com"] [uri "/xmlrpc.php"] [unique_id "ai6FqKnNDMsIsvKkacBv3QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Tha_14
2026-06-14 08:03:33
(2 days ago)
Limit on login attempts is reached
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-13 12:33:44
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 156.155.14.58 (156-155-14-58.ip.internet.co.za) ...
show more
(mod_security) mod_security (id:240335) triggered by 156.155.14.58 (156-155-14-58.ip.internet.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 08:33:38.428546 2026] [security2:error] [pid 24957:tid 24957] [client 156.155.14.58:8747] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.155.14.58 (+1 hits since last alert)|puckerbikini.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "puckerbikini.com"] [uri "/xmlrpc.php"] [unique_id "ai1OIuP7H6Imn0F12UH6ZwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
pusathosting.com
2026-06-13 11:50:05
(3 days ago)
24ds22 bruteforce
Brute-Force
Web App Attack
Anonymous
2026-06-12 15:45:14
(3 days ago)
[redacted] 156.155.14.58 - - [12/Jun/2026:17:44:21 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 156.155.14.58 - - [12/Jun/2026:17:44:21 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 156.155.14.58 - - [12/Jun/2026:17:44:31 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 156.155.14.58 - - [12/Jun/2026:17:44:42 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.1; http://site72209716.com"
[redacted] 156.155.14.58 - - [12/Jun/2026:17:44:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 156.155.14.58 - - [12/Jun/2026:17:45:13 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 15:21:06
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 156.155.14.58 (156-155-14-58.ip.internet.co.za) ...
show more
(mod_security) mod_security (id:240335) triggered by 156.155.14.58 (156-155-14-58.ip.internet.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 11:20:59.561809 2026] [security2:error] [pid 10679:tid 10679] [client 156.155.14.58:51560] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.155.14.58 (+1 hits since last alert)|stoughtonpipeandwelding.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "stoughtonpipeandwelding.net"] [uri "/xmlrpc.php"] [unique_id "aiwj24rsHCt3NOzcwjYF-wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-18 22:44:08
(1 month ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host