๐บ๐ธ
TPI-Abuse
2026-08-21 11:58:14
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 07:58:10.315262 2026] [security2:error] [pid 3847:tid 3847] [client 180.191.98.238:49567] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.238 (+1 hits since last alert)|equipoperu.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "equipoperu.org"] [uri "/xmlrpc.php"] [unique_id "aog9Uvoxht_HcRlsjNpoVQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-14 14:26:58
(6 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 13:56:50
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 09:56:43.771193 2026] [security2:error] [pid 18677:tid 18677] [client 180.191.98.238:63935] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.238 (+1 hits since last alert)|creationorevolution.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "creationorevolution.net"] [uri "/xmlrpc.php"] [unique_id "an8emz5y-VmLqCoSmw_WBQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 14:51:50
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 10:51:43.883966 2026] [security2:error] [pid 1826383:tid 1826383] [client 180.191.98.238:51468] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.238 (+1 hits since last alert)|cemesur-vision21.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cemesur-vision21.com"] [uri "/xmlrpc.php"] [unique_id "anyIf5jCIiM3H1OXdvg_agAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-10 13:03:21
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-07-29 07:00:00
(3 weeks ago)
Apache probe; attempts=35; exact paths: /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 12:28:27
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:28:21.242790 2026] [security2:error] [pid 3802474:tid 3802474] [client 180.191.98.238:58821] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.238 (+1 hits since last alert)|braintechsoftwaresolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "braintechsoftwaresolutions.com"] [uri "/xmlrpc.php"] [unique_id "amdO5XSHJ5jm_3XNCUBSkgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 14:47:13
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 10:47:08.238723 2026] [security2:error] [pid 1559548:tid 1559548] [client 180.191.98.238:50432] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.238 (+1 hits since last alert)|medusakenya.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "medusakenya.com"] [uri "/xmlrpc.php"] [unique_id "amTMbJJtlwTMsBGy04DWNAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 16:57:34
(4 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-07-22 13:06:03
(4 weeks ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 12:47:49
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.238 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 08:47:43.566445 2026] [security2:error] [pid 865376:tid 865376] [client 180.191.98.238:64573] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.238 (+1 hits since last alert)|truthsabouthealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "truthsabouthealthcare.com"] [uri "/xmlrpc.php"] [unique_id "amC77z7tkRir_2WBakzoJgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-07-20 02:01:11
(1 month ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-07-17 22:29:41
(1 month ago)
Brute-Force
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-17 14:53:42
(1 month ago)
180.191.98.238 - - [17/Jul/2026:10:52:11 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress. ...
show more
180.191.98.238 - - [17/Jul/2026:10:52:11 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress.com; https://wordpress.com"
180.191.98.238 - - [17/Jul/2026:10:52:22 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress.com; https://wordpress.com"
180.191.98.238 - - [17/Jul/2026:10:53:18 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress.com; https://wordpress.com"
180.191.98.238 - - [17/Jul/2026:10:53:29 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress.com; https://wordpress.com"
180.191.98.238 - - [17/Jul/2026:10:53:40 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-07-17 13:37:13
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack