๐ซ๐ฎ
YF
2026-06-12 04:00:47
(5 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-12 02:16:12
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 196.189.25.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 196.189.25.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 22:16:05.034060 2026] [security2:error] [pid 388:tid 388] [client 196.189.25.157:3643] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.189.25.157 (+1 hits since last alert)|415test.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "415test.com"] [uri "/xmlrpc.php"] [unique_id "aitr5RydREty4RFpLUd87wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-12 02:14:16
(5 days ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-12 00:10:36
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 196.189.25.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 196.189.25.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 20:10:31.865629 2026] [security2:error] [pid 28721:tid 28721] [client 196.189.25.157:3249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.189.25.157 (+1 hits since last alert)|karenbernsteinlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "karenbernsteinlaw.com"] [uri "/xmlrpc.php"] [unique_id "aitOd8qX7S-iuuE1vzPAuwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 20:39:38
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 196.189.25.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 196.189.25.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 16:39:34.585496 2026] [security2:error] [pid 10065:tid 10084] [client 196.189.25.157:3353] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.189.25.157 (+1 hits since last alert)|northtexaslive.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "northtexaslive.com"] [uri "/xmlrpc.php"] [unique_id "aisdBo2NcMUqpHyr2K7rQQAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
stefaniak41500
2026-06-11 20:33:57
(6 days ago)
Shield Guard: Scanner: wordpress (+70) | Chemin suspect: /xmlrpc.php | xmlrpc.php bloquรฉ
Web App Attack
Port Scan
Anonymous
2026-06-11 19:59:42
(6 days ago)
[redacted] 196.189.25.157 - - [11/Jun/2026:21:58:58 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 196.189.25.157 - - [11/Jun/2026:21:58:58 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 196.189.25.157 - - [11/Jun/2026:21:59:09 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
[redacted] 196.189.25.157 - - [11/Jun/2026:21:59:19 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 196.189.25.157 - - [11/Jun/2026:21:59:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 196.189.25.157 - - [11/Jun/2026:21:59:41 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
ps-center
2026-01-17 14:05:03
(5 months ago)
RDM-W: TCP-Scanner. Port: 23
Port Scan
๐จ๐ณ
ThreatBook.io
2026-01-17 01:21:03
(5 months ago)
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/196.189.25.157
SSH
Anonymous
2026-01-08 19:34:51
(5 months ago)
Unauthorized connection attempt on Port 23
Port Scan
Hacking
Exploited Host
๐ซ๐ท
bigorre.org
2025-08-23 11:40:15
(9 months ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐ฉ๐ช
seller_service
2020-11-26 08:08:01
(5 years ago)
php WP PHPmyadamin ABUSE blocked for 12h
Web App Attack