๐บ๐ธ
TPI-Abuse
2026-10-01 08:13:27
(1 day ago)
(mod_security) mod_security (id:210350) triggered by 182.252.88.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210350) triggered by 182.252.88.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 04:13:16.965997 2026] [security2:error] [pid 22173:tid 22173] [client 182.252.88.230:44308] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||misfitranch.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "misfitranch.com"] [uri "/"] [unique_id "ar4WHGFvS6yqZ1MzACjT1AAAAAo"], referer: https://instantbacklinkmaker.shop/dir/link-outreach-services-137589
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
KevinNeale
2026-09-29 21:11:07
(3 days ago)
Fail2Ban recidive block for repeated malicious authentication attempts.
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-24 04:30:29
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-10 05:19:13
(3 weeks ago)
(mod_security) mod_security (id:35002) triggered by 182.252.88.230 (BD/Bangladesh/-): N in the last ...
show more
(mod_security) mod_security (id:35002) triggered by 182.252.88.230 (BD/Bangladesh/-): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 08:32:07
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 182.252.88.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 182.252.88.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:31:52.036286 2026] [security2:error] [pid 16955:tid 16955] [client 182.252.88.230:58002] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||med-engineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "med-engineering.com"] [uri "/cialis.com"] [unique_id "apKY-KmcTU1YywUGatBMlwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-27 02:43:37
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-07 05:51:24
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 182.252.88.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 182.252.88.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 01:51:12.530244 2026] [security2:error] [pid 2776624:tid 2776624] [client 182.252.88.230:56599] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 182.252.88.230 (+1 hits since last alert)|lyldevelopers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lyldevelopers.com"] [uri "/xmlrpc.php"] [unique_id "anVyUF5zu5bLdBKlKK5c9gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-04 06:12:52
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 182.252.88.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 182.252.88.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 02:12:39.076345 2026] [security2:error] [pid 1464634:tid 1464634] [client 182.252.88.230:57592] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 182.252.88.230 (+1 hits since last alert)|calvaryadminservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "calvaryadminservices.com"] [uri "/xmlrpc.php"] [unique_id "anGC17BZcUr6uQfwGAw-XgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-08-02 02:32:37
(2 months ago)
182.252.88.230 - - [02/Aug/2026:10:32:14 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by ...
show more
182.252.88.230 - - [02/Aug/2026:10:32:14 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by WordPress.com"
182.252.88.230 - - [02/Aug/2026:10:32:25 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
182.252.88.230 - - [02/Aug/2026:10:32:36 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5893 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
๐บ๐ธ
IndigoRidge
2026-08-01 06:47:56
(2 months ago)
182.252.88.230 - - [01/Aug/2026:02:45:55 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5084 "-" "WordPress. ...
show more
182.252.88.230 - - [01/Aug/2026:02:45:55 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5084 "-" "WordPress.com; https://wordpress.com"
182.252.88.230 - - [01/Aug/2026:02:46:38 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5084 "-" "WordPress.com; https://wordpress.com"
182.252.88.230 - - [01/Aug/2026:02:47:00 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5084 "-" "WordPress.com; https://wordpress.com"
182.252.88.230 - - [01/Aug/2026:02:47:32 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5084 "-" "WordPress.com; https://wordpress.com"
182.252.88.230 - - [01/Aug/2026:02:47:54 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5084 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-28 04:50:35
(2 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-07-28 04:46:37
(2 months ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-07-27 08:02:05
(2 months ago)
Wordfence waf block on baystatereentrynetwork
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 06:53:10
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 182.252.88.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 182.252.88.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 02:52:58.131888 2026] [security2:error] [pid 1899465:tid 1899465] [client 182.252.88.230:64975] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 182.252.88.230 (+1 hits since last alert)|415test.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "415test.com"] [uri "/xmlrpc.php"] [unique_id "amG6SgmlYk9DPhNQNjwkAQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-04 11:56:20
(2 months ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack