πΊπΈ
TPI-Abuse
2026-08-23 14:52:06
(6 hours ago)
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:52:00.619236 2026] [security2:error] [pid 32515:tid 32515] [client 197.253.114.166:34254] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.253.114.166 (+1 hits since last alert)|pharmaceuticalsalescareerhub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pharmaceuticalsalescareerhub.com"] [uri "/xmlrpc.php"] [unique_id "aosJEBCzxDzIMEjNW3vHVwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
grassau.com
2026-08-21 18:04:56
(2 days ago)
(wordpress) Failed wordpress login from 197.253.114.166 (GH/Ghana/Greater Accra Region/Accra/-)
Brute-Force
π©πͺ
rh24
2026-08-18 16:14:56
(5 days ago)
(wordpress) Failed wordpress login from 197.253.114.166 (GH/Ghana/-): (CF_ENABLE)
Brute-Force
πΊπΈ
IndigoRidge
2026-08-15 21:23:45
(1 week ago)
197.253.114.166 - - [15/Aug/2026:17:21:15 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5612 "-" "WordPress ...
show more
197.253.114.166 - - [15/Aug/2026:17:21:15 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5612 "-" "WordPress.com; https://wordpress.com"
197.253.114.166 - - [15/Aug/2026:17:21:47 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5612 "-" "WordPress.com; https://wordpress.com"
197.253.114.166 - - [15/Aug/2026:17:22:08 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5612 "-" "WordPress.com; https://wordpress.com"
197.253.114.166 - - [15/Aug/2026:17:22:19 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5612 "-" "WordPress.com; https://wordpress.com"
197.253.114.166 - - [15/Aug/2026:17:23:44 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5612 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-15 20:43:04
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 16:42:59.922142 2026] [security2:error] [pid 8781:tid 8781] [client 197.253.114.166:26211] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.253.114.166 (+1 hits since last alert)|indiahouseportland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "indiahouseportland.com"] [uri "/xmlrpc.php"] [unique_id "aoDPUyaddKR0kgVHWP_UFwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-14 21:52:50
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 17:52:46.650140 2026] [security2:error] [pid 23128:tid 23128] [client 197.253.114.166:60229] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.253.114.166 (+1 hits since last alert)|idmadventures.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "idmadventures.com"] [uri "/xmlrpc.php"] [unique_id "an-OLk_S8cjp9aXp4kDl2wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
4server
2026-08-14 21:44:51
(1 week ago)
[FriAug1423:44:46.6632622026][security2:error][pid3751501:tid3752216][client197.253.114.166:0]ModSec ...
show more
[FriAug1423:44:46.6632622026][security2:error][pid3751501:tid3752216][client197.253.114.166:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"468\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"sesael.ch\"][uri\"/xmlrpc.php\"][unique_id\"an-MThwWGVVGpEzBNyaQUQAAAQ4\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-13 18:26:28
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 14:26:23.914530 2026] [security2:error] [pid 8080:tid 8080] [client 197.253.114.166:11442] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.253.114.166 (+1 hits since last alert)|midwayisland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "midwayisland.com"] [uri "/xmlrpc.php"] [unique_id "an4MT4MJfpAPDUjjClANOQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
applemooz
2026-08-12 11:34:28
(1 week ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-10 19:48:04
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 15:48:00.464012 2026] [security2:error] [pid 1635780:tid 1635780] [client 197.253.114.166:63236] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.253.114.166 (+1 hits since last alert)|lightupaustralia.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lightupaustralia.org"] [uri "/xmlrpc.php"] [unique_id "anoq8HcItDZxvTilP0F2cwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
findlab
2026-08-10 16:30:01
(1 week ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-06 20:39:55
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 197.253.114.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 16:39:48.301520 2026] [security2:error] [pid 1135934:tid 1135934] [client 197.253.114.166:12453] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.253.114.166 (+1 hits since last alert)|bluesbluff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bluesbluff.com"] [uri "/xmlrpc.php"] [unique_id "anTxFJkJ7IEC7SAioND8iAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
Dunham Support
2026-08-06 09:10:08
(2 weeks ago)
(wordpress) Failed wordpress login from 197.253.114.166 (GH/Ghana/-)
Brute-Force
π¨π¦
polycoda
2026-08-06 07:38:21
(2 weeks ago)
AutoBlock: π WordPress Login Brute Force (20X or 30X) (Decay-Based)
Brute-Force
Web App Attack
π«π·
dynamix
2026-08-06 07:31:12
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack