๐บ๐ธ
TPI-Abuse
2026-07-28 07:51:48
(17 hours ago)
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 03:51:43.819088 2026] [security2:error] [pid 577123:tid 577123] [client 196.77.103.107:64278] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.77.103.107 (+1 hits since last alert)|fltsiminc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fltsiminc.com"] [uri "/xmlrpc.php"] [unique_id "amhfj0PfEqOResYfG4RrqwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 07:11:29
(17 hours ago)
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 03:11:23.760542 2026] [security2:error] [pid 2325115:tid 2325115] [client 196.77.103.107:59625] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.77.103.107 (+1 hits since last alert)|sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sharawi-gum.com"] [uri "/xmlrpc.php"] [unique_id "amhWG_OvciJuuNbk_XLdNQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-28 04:35:27
(20 hours ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 01:31:38
(23 hours ago)
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 21:31:34.353335 2026] [security2:error] [pid 865740:tid 865740] [client 196.77.103.107:53043] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.77.103.107 (+1 hits since last alert)|eatcakecup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eatcakecup.com"] [uri "/xmlrpc.php"] [unique_id "amgGds-oYlhj7j1GWnWVewAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-27 23:27:54
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 22:58:12
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 18:58:08.651704 2026] [security2:error] [pid 1232833:tid 1232833] [client 196.77.103.107:50169] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.77.103.107 (+1 hits since last alert)|fgrotary.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fgrotary.org"] [uri "/xmlrpc.php"] [unique_id "amfigHElPW236MQMqiBowAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-27 22:25:24
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
MA/Morocco/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 21:15:59
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 17:15:53.511170 2026] [security2:error] [pid 8756:tid 8756] [client 196.77.103.107:64549] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.77.103.107 (+1 hits since last alert)|barecreationsaz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "barecreationsaz.com"] [uri "/xmlrpc.php"] [unique_id "amfKiZ2HrQ2ncH02wAGL9gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-27 21:13:48
(1 day ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.co ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-07-27 21:13:02
(1 day ago)
196.77.103.107 - - [28/Jul/2026:05:12:40 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "Jetpack by ...
show more
196.77.103.107 - - [28/Jul/2026:05:12:40 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
196.77.103.107 - - [28/Jul/2026:05:12:50 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "WordPress.com; https://wordpress.com"
196.77.103.107 - - [28/Jul/2026:05:13:01 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5935 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
...
show less
Brute-Force
๐บ๐ธ
Dave Hansen
2026-07-27 16:26:41
(1 day ago)
(wordpress) Failed wordpress login from 196.77.103.107 (MA/Morocco/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 12:54:05
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:53:57.580883 2026] [security2:error] [pid 367658:tid 367658] [client 196.77.103.107:54710] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.77.103.107 (+1 hits since last alert)|kbalan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kbalan.com"] [uri "/xmlrpc.php"] [unique_id "amdU5bZkx-BRdd7vNeyN_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 12:22:45
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 196.77.103.107 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 08:22:42.414000 2026] [security2:error] [pid 1658785:tid 1658785] [client 196.77.103.107:53819] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.77.103.107 (+1 hits since last alert)|aifactoid.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aifactoid.com"] [uri "/xmlrpc.php"] [unique_id "amdNktDOyhi53KDQKRPN-AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
EGP Abuse Dept
2023-09-14 15:24:42
(2 years ago)
Unauthorized connection to Telnet port 23
Port Scan
Hacking