๐บ๐ธ
TPI-Abuse
2026-07-21 16:38:15
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 160.176.107.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 160.176.107.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 12:38:06.564231 2026] [security2:error] [pid 469980:tid 469980] [client 160.176.107.112:55859] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.176.107.112 (+1 hits since last alert)|graymatterofdc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "graymatterofdc.com"] [uri "/xmlrpc.php"] [unique_id "al-gboUgCoHxTLrH5GZJ_AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
lenz
2026-07-21 14:22:43
(3 days ago)
Jul 21 16:21:59 hosting wordpress(grupa-ddd.pl)[1237]: XML-RPC authentication failure for admin from ...
show more
Jul 21 16:21:59 hosting wordpress(grupa-ddd.pl)[1237]: XML-RPC authentication failure for admin from 160.176.107.112
Jul 21 16:22:10 hosting wordpress(grupa-ddd.pl)[2354]: XML-RPC authentication failure for admin from 160.176.107.112
Jul 21 16:22:21 hosting wordpress(grupa-ddd.pl)[1236]: XML-RPC authentication failure for admin from 160.176.107.112
Jul 21 16:22:32 hosting wordpress(grupa-ddd.pl)[3026]: XML-RPC authentication failure for admin from 160.176.107.112
Jul 21 16:22:42 hosting wordpress(grupa-ddd.pl)[2354]: XML-RPC authentication failure for admin from 160.176.107.112
...
show less
Brute-Force
Web App Attack
Anonymous
2026-07-21 13:53:06
(3 days ago)
(wordpress) Failed wordpress login from 160.176.107.112 (MA/Morocco/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-21 13:24:16
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 160.176.107.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 160.176.107.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 09:24:11.243329 2026] [security2:error] [pid 5434:tid 5434] [client 160.176.107.112:53109] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.176.107.112 (+1 hits since last alert)|produktives.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "produktives.com"] [uri "/xmlrpc.php"] [unique_id "al9y-4SU7raesWnNqzI6VwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 11:49:06
(3 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 20:58:14
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 160.176.107.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 160.176.107.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 16:58:06.299853 2026] [security2:error] [pid 13296:tid 13296] [client 160.176.107.112:57429] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.176.107.112 (+1 hits since last alert)|bikiniadvice.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bikiniadvice.com"] [uri "/xmlrpc.php"] [unique_id "al6L3h-UGkTotL2WNuDSawAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 18:55:06
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 160.176.107.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 160.176.107.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 14:55:00.843135 2026] [security2:error] [pid 3820:tid 3820] [client 160.176.107.112:60757] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.176.107.112 (+1 hits since last alert)|savingspools.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "savingspools.com"] [uri "/xmlrpc.php"] [unique_id "al5vBI6hOMGxqHQUDSFMEwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 18:25:37
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 160.176.107.112 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 160.176.107.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 14:25:32.340654 2026] [security2:error] [pid 1211153:tid 1211153] [client 160.176.107.112:57932] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.176.107.112 (+1 hits since last alert)|cfmgroup.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cfmgroup.us"] [uri "/xmlrpc.php"] [unique_id "al5oHH90q1XKakqFlLE_5wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2025-11-16 06:55:44
(8 months ago)
Blocked by UFW (TCP on 9101)
Source port: 58806
TTL: 111
Packet length: 52
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 9101)
Source port: 58806
TTL: 111
Packet length: 52
TOS: 0x08
This report (for 160.176.107.112) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ซ๐ฎ
bittiguru.fi
2021-01-18 16:01:00
(5 years ago)
WordPress brute force
Brute-Force
Anonymous
2021-01-18 07:12:37
(5 years ago)
www.lust-auf-land.com 160.176.107.112 [18/Jan/2021:13:12:36 +0100] "POST /wp-login.php HTTP/1.1" 200 ...
show more
www.lust-auf-land.com 160.176.107.112 [18/Jan/2021:13:12:36 +0100] "POST /wp-login.php HTTP/1.1" 200 6615 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
www.lust-auf-land.com 160.176.107.112 [18/Jan/2021:13:12:36 +0100] "POST /wp-login.php HTTP/1.1" 200 6616 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:62.0) Gecko/20100101 Firefox/62.0"
show less
Web App Attack