๐บ๐ธ
TPI-Abuse
2026-04-16 19:07:19
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa) ...
show more
(mod_security) mod_security (id:240335) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 15:07:15.073784 2026] [security2:error] [pid 843643:tid 843643] [client 196.39.254.245:49117] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.39.254.245 (+1 hits since last alert)|nesetsv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nesetsv.com"] [uri "/xmlrpc.php"] [unique_id "aeEzY-7LlPtVi5ndWjESEQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2026-04-12 05:41:33
(1 month ago)
196.39.254.245 - - [12/Apr/2026:00:40:55 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2967 "-" "WordPress. ...
show more
196.39.254.245 - - [12/Apr/2026:00:40:55 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2967 "-" "WordPress.com; https://wordpress.com"
196.39.254.245 - - [12/Apr/2026:00:40:59 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2967 "-" "Jetpack by WordPress.com"
196.39.254.245 - - [12/Apr/2026:00:41:10 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2967 "-" "Jetpack by WordPress.com"
196.39.254.245 - - [12/Apr/2026:00:41:21 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2968 "-" "Jetpack/12.0; WordPress/6.1; http://site50341977.com"
196.39.254.245 - - [12/Apr/2026:00:41:32 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2966 "-" "Jetpack/12.0; WordPress/6.4; http://site91856625.com"
...
show less
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-04-12 03:18:33
(1 month ago)
Unauthorized access to webpage admin
Web App Attack
๐จ๐ญ
4server
2026-04-12 02:28:39
(1 month ago)
[SunApr1204:28:32.9241172026][security2:error][pid3119293:tid3119380][client196.39.254.245:0]ModSecu ...
show more
[SunApr1204:28:32.9241172026][security2:error][pid3119293:tid3119380][client196.39.254.245:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"345\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"lemox.ch\"][uri\"/xmlrpc.php\"][unique_id\"adsDUIYGbzXYDv1TT8saZgAAAM4\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-12 02:05:05
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa) ...
show more
(mod_security) mod_security (id:240335) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 11 22:04:58.003214 2026] [security2:error] [pid 1018393:tid 1018393] [client 196.39.254.245:35927] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.39.254.245 (+1 hits since last alert)|hotelausland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hotelausland.com"] [uri "/xmlrpc.php"] [unique_id "adr9yfcVHqHZUEP4HSWy_QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-04-12 00:05:20
(1 month ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-11 23:44:56
(1 month ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฏ๐ต
Valhalla
2026-04-11 07:28:31
(1 month ago)
/xmlrpc.php
Hacking
Web App Attack
๐ฉ๐ช
4server
2026-04-11 02:59:25
(1 month ago)
[SatApr1104:59:21.3992492026][security2:error][pid1787856:tid1787985][client196.39.254.245:0]ModSecu ...
show more
[SatApr1104:59:21.3992492026][security2:error][pid1787856:tid1787985][client196.39.254.245:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"148\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"ci-ticino.ch\"][uri\"/xmlrpc.php\"][unique_id\"adm5CfzOIIblnR1JoyXXSwAAAME\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-10 23:33:12
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa) ...
show more
(mod_security) mod_security (id:225170) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 19:33:05.102328 2026] [security2:error] [pid 1572147:tid 1572147] [client 196.39.254.245:60130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marinestorage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marinestorage.com"] [uri "/wp-json/wp/v2/users"] [unique_id "admIsSRnykAwMWnVRJM2FwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-09 18:49:27
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa) ...
show more
(mod_security) mod_security (id:225170) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 14:49:22.175405 2026] [security2:error] [pid 1344982:tid 1344982] [client 196.39.254.245:56750] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||accommodation-perthairport.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "accommodation-perthairport.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adf0skkLvGbkEnLJAo8a3QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-04-09 04:13:26
(1 month ago)
Unauthorized access to webpage admin
Web App Attack
๐ฉ๐ช
grassau.com
2026-04-06 00:30:19
(1 month ago)
(wordpress) Failed wordpress login from 196.39.254.245 (ZA/South Africa/Gauteng/Johannesburg/196-39- ...
show more
(wordpress) Failed wordpress login from 196.39.254.245 (ZA/South Africa/Gauteng/Johannesburg/196-39-254-245.ftth.web.africa)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-05 22:41:11
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa) ...
show more
(mod_security) mod_security (id:225170) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 18:41:06.011583 2026] [security2:error] [pid 31507:tid 31526] [client 196.39.254.245:1979] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||executiveaccounting.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "executiveaccounting.net"] [uri "/wp-json/wp/v2/users"] [unique_id "adLlAosMKGwhl3uiZwJVJwAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 16:41:35
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa) ...
show more
(mod_security) mod_security (id:225170) triggered by 196.39.254.245 (196-39-254-245.ftth.web.africa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 12:41:30.726885 2026] [security2:error] [pid 17360:tid 17360] [client 196.39.254.245:25487] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||agrollum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "agrollum.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adKQuinSP_A7mGxJWa3k1gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack