๐บ๐ธ
TPI-Abuse
2026-07-25 18:22:43
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 41.59.168.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.59.168.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 14:22:40.435389 2026] [security2:error] [pid 3354:tid 3401] [client 41.59.168.160:57023] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.59.168.160 (+1 hits since last alert)|dbestcarting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dbestcarting.com"] [uri "/xmlrpc.php"] [unique_id "amT-8MXvFGHS4Vx-T2DsywAAAUs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 14:59:08
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 41.59.168.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.59.168.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 10:59:02.048082 2026] [security2:error] [pid 3075816:tid 3075816] [client 41.59.168.160:55770] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.59.168.160 (+1 hits since last alert)|lyldevelopers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lyldevelopers.com"] [uri "/xmlrpc.php"] [unique_id "amTPNhA7aOaHqpBwSn0q3AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
rafale2k
2026-07-25 12:24:48
(3 days ago)
WordPress Brute Force
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 11:21:52
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 41.59.168.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.59.168.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 07:21:47.105945 2026] [security2:error] [pid 3785220:tid 3785220] [client 41.59.168.160:65508] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.59.168.160 (+1 hits since last alert)|hertzan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hertzan.com"] [uri "/xmlrpc.php"] [unique_id "amScS6gvmLL57wnwPQD8LQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-07-25 08:42:20
(3 days ago)
{"ClientAddr":"41.59.168.160:60878","ClientHost":"41.59.168.160","ClientPort":"60878","ClientUsernam ...
show more
{"ClientAddr":"41.59.168.160:60878","ClientHost":"41.59.168.160","ClientPort":"60878","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":167531262,"OriginContentSize":418,"OriginDuration":161134839,"OriginStatus":403,"Overhead":6396423,"RequestAddr":"www.cleveradmin.de","RequestContentSize":705,"RequestCount":1967854,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-07-25T10:42:00.525156743+02:00","StartUTC":"2026-07-25T08:42:00.525156743Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-07-25T10:42:00+02:00"}
{"ClientAddr":"41.59.168.160:60878","ClientHost":"41.59.168.160","
...
show less
Brute-Force
Web App Attack
Anonymous
2026-07-25 08:13:14
(3 days ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=www.hparxo.gr; logs=/var/log/httpd/domains/hparxo.gr.log; sa ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=www.hparxo.gr; logs=/var/log/httpd/domains/hparxo.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 19:35:39
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 41.59.168.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.59.168.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:35:34.082184 2026] [security2:error] [pid 3951665:tid 3951665] [client 41.59.168.160:58828] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.59.168.160 (+1 hits since last alert)|stacyfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "stacyfarm.com"] [uri "/xmlrpc.php"] [unique_id "amO-hnRQWe80taneGDu2lAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-24 17:20:39
(4 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 16:55:37
(4 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-24 11:23:56
(4 days ago)
cloudlinux2 fail2ban: 2026-07-24 13:19:04,886 fail2ban.filter [1816]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-24 13:19:04,886 fail2ban.filter [1816]: INFO [plesk-wordpress] Found 192.250.232.197 - 2026-07-24 13:19:04cloudlinux2 fail2ban: 2026-07-24 13:19:23,570 fail2ban.filter [1816]: INFO [plesk-wordpress] Found 23.94.155.78 - 2026-07-24 13:19:23cloudlinux2 fail2ban: 2026-07-24 13:19:27,970 fail2ban.filter [1816]: INFO [plesk-wordpress] Found 23.94.155.78 - 2026-07-24 13:19:27cloudlinux2 fail2ban: 2026-07-24 13:21:14,090 fail2ban.filter [1816]: INFO [plesk-wordpress] Found 164.92.111.201 - 2026-07-24 13:21:14cloudlinux2 fail2ban: 2026-07-24 13:21:39,140 fail2ban.filter [1816]: INFO [plesk-wordpress] Found 45.131.195.211 - 2026-07-24 13:21:38cloudlinux2 fail2ban: 2026-07-24 13:21:34,554 fail2ban.actions [1816]: NOTICE [plesk-modsecurity] Unban 60.53.136.215cloudlinux2 fail2ban: 2026-07-24 13:21:42,092 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 41.59.168.160 - 2026-07-24 13:21:42cloudlinux2 fail2ban: 202
show less
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 11:09:58
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 10:50:26
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 41.59.168.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.59.168.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:50:00.506490 2026] [security2:error] [pid 103977:tid 103977] [client 41.59.168.160:55399] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.59.168.160 (+1 hits since last alert)|nolaanime.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nolaanime.com"] [uri "/xmlrpc.php"] [unique_id "amNDWEzqjPJFx9bOg1bqzwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-23 19:46:32
(4 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
TZ/Tanzania/-
Web App Attack
๐ฉ๐ช
LRob
2026-07-23 18:49:05
(4 days ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack/13.0; WordPress ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack/13.0; WordPress/6.1; http://site45819613.com
show less
Brute-Force
Web App Attack
๐จ๐ณ
ThreatBook.io
2026-03-20 23:16:04
(4 months ago)
ThreatBook Intelligence: Zombie,Dynamic IP more details on https://threatbook.io/ip/41.59.168.160
SSH