Anonymous
2026-06-05 22:50:01
(1 week ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-05 17:23:55
(1 week ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
MY/Malaysia/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 08:52:34
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 175.144.98.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 175.144.98.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 04:52:27.236904 2026] [security2:error] [pid 6173:tid 6194] [client 175.144.98.230:50948] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 175.144.98.230 (+1 hits since last alert)|aafm.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aafm.us"] [uri "/xmlrpc.php"] [unique_id "aiKOS-jXITtMiz2s_EpsQwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 07:19:33
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 175.144.98.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 175.144.98.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 03:19:27.424910 2026] [security2:error] [pid 30539:tid 30554] [client 175.144.98.230:55207] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 175.144.98.230 (+1 hits since last alert)|gabegabel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gabegabel.com"] [uri "/xmlrpc.php"] [unique_id "aiJ4fz-rIbztS9DxUBiV8QAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 19:29:13
(1 week ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-04 15:23:25
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 175.144.98.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 175.144.98.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 11:23:18.122142 2026] [security2:error] [pid 13591:tid 13591] [client 175.144.98.230:54262] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 175.144.98.230 (+1 hits since last alert)|usaangelinvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "usaangelinvestors.com"] [uri "/xmlrpc.php"] [unique_id "aiGYZmlI_y0ItNAi-XvG6wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-04 15:22:44
(1 week ago)
(wordpress) Failed wordpress login from 175.144.98.230 (MY/Malaysia/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-04 14:54:47
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 175.144.98.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 175.144.98.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 10:54:44.399145 2026] [security2:error] [pid 21515:tid 21515] [client 175.144.98.230:55006] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 175.144.98.230 (+1 hits since last alert)|sigridsnaturalfoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sigridsnaturalfoods.com"] [uri "/xmlrpc.php"] [unique_id "aiGRtGoJTSmvHhd3srtc4wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 14:24:10
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 175.144.98.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 175.144.98.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 10:24:03.755792 2026] [security2:error] [pid 17704:tid 17704] [client 175.144.98.230:53625] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 175.144.98.230 (+1 hits since last alert)|slimlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "slimlaw.com"] [uri "/xmlrpc.php"] [unique_id "aiGKg2_hyKJwvl2lvn5FdQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-04 11:59:03
(1 week ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
Anonymous
2026-06-04 11:47:08
(1 week ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=tentes-margaritis.gr; logs=/var/log/httpd/domains/tentes-mar ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=tentes-margaritis.gr; logs=/var/log/httpd/domains/tentes-margaritis.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack