๐บ๐ธ
TPI-Abuse
2026-07-25 10:16:00
(21 minutes ago)
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 06:15:54.566149 2026] [security2:error] [pid 753704:tid 753704] [client 180.252.83.185:64705] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.252.83.185 (+1 hits since last alert)|495metro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "495metro.com"] [uri "/xmlrpc.php"] [unique_id "amSM2iA6OeIn_K0wu835QAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 23:08:28
(11 hours ago)
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 19:08:24.674924 2026] [security2:error] [pid 2088273:tid 2088292] [client 180.252.83.185:49470] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.252.83.185 (+1 hits since last alert)|illianapartyrentals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "illianapartyrentals.com"] [uri "/xmlrpc.php"] [unique_id "amPwaPh7Mc4uzENVBOm6SAAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-07-24 11:26:14
(23 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-24 09:23:29
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2026-07-24 08:57:16
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (ID/Indonesia/-): 5 in the last ...
show more
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (ID/Indonesia/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-07-24 03:59:23
(1 day ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 23:54:46
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 19:54:38.752463 2026] [security2:error] [pid 3694221:tid 3694221] [client 180.252.83.185:63249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tonydelov.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tonydelov.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amKpvhS1EhPbuY6q0et4hAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-23 12:46:07
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 10:13:35
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 06:13:29.990156 2026] [security2:error] [pid 328390:tid 328390] [client 180.252.83.185:52956] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.252.83.185 (+1 hits since last alert)|aifactoid.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aifactoid.com"] [uri "/xmlrpc.php"] [unique_id "amHpSc27-sQBVaouYTUazwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 09:45:27
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 05:45:20.016473 2026] [security2:error] [pid 2269405:tid 2269405] [client 180.252.83.185:64103] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.252.83.185 (+1 hits since last alert)|serranoscoffee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "serranoscoffee.com"] [uri "/xmlrpc.php"] [unique_id "amHisJF6bR6TlmT9lq1GBQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-22 15:07:27
(2 days ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
Anonymous
2026-07-22 11:12:11
(2 days ago)
[redacted] 180.252.83.185 - - [22/Jul/2026:13:11:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 180.252.83.185 - - [22/Jul/2026:13:11:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 180.252.83.185 - - [22/Jul/2026:13:11:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
[redacted] 180.252.83.185 - - [22/Jul/2026:13:11:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 180.252.83.185 - - [22/Jul/2026:13:11:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 180.252.83.185 - - [22/Jul/2026:13:12:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
...
show less
Hacking
Web App Attack
๐ซ๐ฎ
YF
2026-07-22 11:00:36
(2 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
Anonymous
2026-07-22 10:41:13
(2 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 04:14:32
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.252.83.185 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 00:14:25.417268 2026] [security2:error] [pid 253820:tid 253820] [client 180.252.83.185:49167] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.252.83.185 (+1 hits since last alert)|wildlandconservancy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wildlandconservancy.com"] [uri "/xmlrpc.php"] [unique_id "amBDoeLVhiY4sr54KxPe6AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack