๐บ๐ธ
TPI-Abuse
2026-08-23 12:26:42
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:26:35.029729 2026] [security2:error] [pid 26248:tid 26248] [client 196.238.179.0:64066] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.238.179.0 (+1 hits since last alert)|zezel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "zezel.com"] [uri "/xmlrpc.php"] [unique_id "aorm-0bmCjIPX8h597hVPAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 10:54:45
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 06:54:39.075426 2026] [security2:error] [pid 9790:tid 9790] [client 196.238.179.0:49360] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.238.179.0 (+1 hits since last alert)|premierveterinarysurgery.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "premierveterinarysurgery.com"] [uri "/xmlrpc.php"] [unique_id "aorRb6olRCVDgmnMVAQR7gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 10:06:44
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 06:06:36.049355 2026] [security2:error] [pid 21862:tid 21862] [client 196.238.179.0:56782] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.238.179.0 (+1 hits since last alert)|rdhtrucking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rdhtrucking.com"] [uri "/xmlrpc.php"] [unique_id "aorGLL6GPG-FBGzxo7DcQAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-08-23 08:29:29
(1 day ago)
196.238.179.0 - - [23/Aug/2026:04:28:24 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5070 "-" "WordPress.c ...
show more
196.238.179.0 - - [23/Aug/2026:04:28:24 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5070 "-" "WordPress.com; https://wordpress.com"
196.238.179.0 - - [23/Aug/2026:04:28:46 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5054 "-" "WordPress.com; https://wordpress.com"
196.238.179.0 - - [23/Aug/2026:04:28:56 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5070 "-" "WordPress.com; https://wordpress.com"
196.238.179.0 - - [23/Aug/2026:04:29:17 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5054 "-" "WordPress.com; https://wordpress.com"
196.238.179.0 - - [23/Aug/2026:04:29:28 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5054 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 07:53:39
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 03:53:32.185014 2026] [security2:error] [pid 32012:tid 32026] [client 196.238.179.0:58409] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.238.179.0 (+1 hits since last alert)|danelandia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "danelandia.com"] [uri "/xmlrpc.php"] [unique_id "aoqm_KD--H_ztBR8y-zGNwAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 17:58:45
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:58:41.302426 2026] [security2:error] [pid 16982:tid 16982] [client 196.238.179.0:58968] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.238.179.0 (+1 hits since last alert)|indoorsfinishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "indoorsfinishing.com"] [uri "/xmlrpc.php"] [unique_id "aonjUcjtBIr53lz9UOvEXAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-22 14:44:09
(2 days ago)
(wordpress) Failed wordpress login from 196.238.179.0 (TN/Tunisia/Tunis Governorate/Tunis/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-22 12:11:10
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.238.179.0 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:11:00.946274 2026] [security2:error] [pid 14574:tid 14574] [client 196.238.179.0:53020] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.238.179.0 (+1 hits since last alert)|honigcpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "honigcpa.com"] [uri "/xmlrpc.php"] [unique_id "aomR1KukWvDw3PWU8GEuagAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Hiigara
2026-08-17 18:01:41
(1 week ago)
connection attempt : 196.238.179.0 on port : tcp/23 (Telnet)
Port Scan
๐ฆ๐ท
Bruno
2026-08-17 17:18:12
(1 week ago)
Port Scanner: 196.238.179.0
Port Scan