๐บ๐ธ
TPI-Abuse
2026-07-23 02:21:07
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 181.115.118.119 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 181.115.118.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 22:20:59.986203 2026] [security2:error] [pid 2352972:tid 2352972] [client 181.115.118.119:47309] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 181.115.118.119 (+1 hits since last alert)|lakependoreillemobility.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lakependoreillemobility.com"] [uri "/xmlrpc.php"] [unique_id "amF6i3mtYtfCicyImXMGCgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-07-22 20:51:16
(1 day ago)
(XMLRPC) WP XMLRPC Attack 181.115.118.119 (HN/Honduras/Intibucรยก Department/Intibucรยก/-/[AS14754 TEL ...
show more
(XMLRPC) WP XMLRPC Attack 181.115.118.119 (HN/Honduras/Intibucรยก Department/Intibucรยก/-/[AS14754 TELECOMUNICACIONES DE GUATEMALA, SOCIEDAD ANONIMA]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 181.115.118.119 - - [22/Jul/2026:23:51:00 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18934 "-" "WordPress.com; https://wordpress.com"
show less
Port Scan
๐ฉ๐ช
konseptit
2026-07-22 19:49:56
(1 day ago)
(wordpress) Failed wordpress login from 181.115.118.119 (HN/Honduras/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-22 17:28:23
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 181.115.118.119 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 181.115.118.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 13:28:16.637109 2026] [security2:error] [pid 1920186:tid 1920186] [client 181.115.118.119:31755] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 181.115.118.119 (+1 hits since last alert)|roguetechhub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "roguetechhub.com"] [uri "/xmlrpc.php"] [unique_id "amD9sHn_i0fjle0k172UTQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 01:39:15
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 181.115.118.119 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 181.115.118.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 21:39:10.152123 2026] [security2:error] [pid 125051:tid 125051] [client 181.115.118.119:39679] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 181.115.118.119 (+1 hits since last alert)|warpedweed.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "warpedweed.com"] [uri "/xmlrpc.php"] [unique_id "amAfPngtr9eFuK5uIURZ9AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-22 01:20:21
(2 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 01:06:02
(2 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 18:18:20
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 181.115.118.119 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 181.115.118.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:18:14.069773 2026] [security2:error] [pid 3318343:tid 3318343] [client 181.115.118.119:38475] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 181.115.118.119 (+1 hits since last alert)|superlamb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "superlamb.com"] [uri "/xmlrpc.php"] [unique_id "al-35vtFsCUYRWvX9nNZkwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-05-01 10:54:46
(2 months ago)
๐ฅถ Part of massive botnet scraping campaign that nearly turned into a DDoS on 2025-11-27
DDoS Attack
๐บ๐ธ
matt
2026-03-04 02:43:22
(4 months ago)
DDOS attack with query parameters attempting to overload WordPress site.
DDoS Attack
Anonymous
2025-12-22 13:59:58
(7 months ago)
apache vulnerability scan
Web App Attack
Anonymous
2025-11-24 21:00:37
(7 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2025-11-19 04:03:02
(8 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2025-11-15 03:10:48
(8 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2024-10-04 17:56:24
(1 year ago)
apache vulnerability scan
Web App Attack