🇫🇷
dynamix
2026-08-07 19:47:02
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
🇷🇴
INTEQ
2026-08-07 18:58:56
(1 month ago)
Web attack from 176.29.158.170
Web App Attack
Anonymous
2026-08-07 18:06:05
(1 month ago)
Trying to access config files
Web App Attack
🇺🇸
LSPCCU
2026-08-07 00:46:52
(1 month ago)
TSEC Honeypot Network report. Threat score: 70/100. Categories: DDoS Attack, Hacking, Brute-Force, W ...
show more
TSEC Honeypot Network report. Threat score: 70/100. Categories: DDoS Attack, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: cowrie, ssh-telnet. Context: 176.29.158.170 classified as automated brute-force attacker targeting SSH/Telnet credentials (high confidence).
show less
DDoS Attack
Hacking
Brute-Force
Web App Attack
SSH
🇺🇸
TPI-Abuse
2026-08-03 23:15:44
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 176.29.158.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 176.29.158.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 19:15:38.961860 2026] [security2:error] [pid 2076293:tid 2076293] [client 176.29.158.170:31295] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 176.29.158.170 (+1 hits since last alert)|partnershipsbydesign.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "partnershipsbydesign.net"] [uri "/xmlrpc.php"] [unique_id "anEhGuxvor2aR1XHt-TquQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-08-03 18:04:36
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
🇺🇸
integrantservices.com
2026-08-03 16:45:00
(1 month ago)
(wordpress) Failed wordpress login from 176.29.158.170 (JO/Jordan/-)
Brute-Force
🇩🇪
LRob
2026-08-03 13:39:49
(1 month ago)
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_forma ...
show more
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/cat_ids~661,132,432/tag_ids~669,482,473,653,243/request_format~json/ | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
show less
DDoS Attack
Web App Attack
🇪🇸
masterguru
2026-08-02 23:53:36
(1 month ago)
(xmlrpc) Failed xmlrpc access from 176.29.158.170 (JO/Jordan/-): 5 in the last 3600 secs (0-122)
Hacking
🇺🇸
TPI-Abuse
2026-08-02 20:16:08
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 176.29.158.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 176.29.158.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 16:16:02.006579 2026] [security2:error] [pid 4007279:tid 4007279] [client 176.29.158.170:7624] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 176.29.158.170 (+1 hits since last alert)|inquisitivequincie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "inquisitivequincie.com"] [uri "/xmlrpc.php"] [unique_id "am-lgvZu-YA2iauPnGutgQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-02 15:17:00
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 176.29.158.170 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 176.29.158.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 11:16:55.680406 2026] [security2:error] [pid 7200:tid 7216] [client 176.29.158.170:28217] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 176.29.158.170 (+1 hits since last alert)|tradersofficepark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tradersofficepark.com"] [uri "/xmlrpc.php"] [unique_id "am9fZwTqwTvq4AjC6cunfgAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
grassau.com
2026-08-01 22:48:09
(1 month ago)
(wordpress) Failed wordpress login from 176.29.158.170 (JO/Jordan/Amman Governorate/Amman/-)
Brute-Force
🇺🇸
IndigoRidge
2026-08-01 18:21:28
(1 month ago)
176.29.158.170 - - [01/Aug/2026:14:19:50 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5530 "-" "WordPress. ...
show more
176.29.158.170 - - [01/Aug/2026:14:19:50 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5530 "-" "WordPress.com; https://wordpress.com"
176.29.158.170 - - [01/Aug/2026:14:20:03 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5530 "-" "WordPress.com; https://wordpress.com"
176.29.158.170 - - [01/Aug/2026:14:20:24 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5530 "-" "WordPress.com; https://wordpress.com"
176.29.158.170 - - [01/Aug/2026:14:20:39 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5530 "-" "WordPress.com; https://wordpress.com"
176.29.158.170 - - [01/Aug/2026:14:21:28 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5530 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
🇨🇦
polycoda
2025-12-18 15:01:08
(8 months ago)
🥶 Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
DDoS Attack
Anonymous
2025-11-25 08:19:56
(9 months ago)
scanning http requests from known botnet
Web App Attack