๐บ๐ธ
TPI-Abuse
2026-07-20 08:53:43
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 04:53:37.463737 2026] [security2:error] [pid 1682697:tid 1682829] [client 45.117.180.152:60258] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.117.180.152 (+1 hits since last alert)|iancaird.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iancaird.com"] [uri "/xmlrpc.php"] [unique_id "al3iESW_b9opcQP7GOn1awAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 07:48:02
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 03:47:57.515633 2026] [security2:error] [pid 841098:tid 841098] [client 45.117.180.152:59647] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.117.180.152 (+1 hits since last alert)|shhcenter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "shhcenter.com"] [uri "/xmlrpc.php"] [unique_id "al3SraFXV5RxD7Gro_wBEwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-07-20 07:47:20
(1 day ago)
Wordpress Vunerability attack
Web App Attack
Anonymous
2026-07-20 05:27:00
(1 day ago)
[redacted] 45.117.180.152 - - [20/Jul/2026:07:26:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" " ...
show more
[redacted] 45.117.180.152 - - [20/Jul/2026:07:26:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/12.1; WordPress/6.3; http://site10841849.com"
[redacted] 45.117.180.152 - - [20/Jul/2026:07:26:27 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
[redacted] 45.117.180.152 - - [20/Jul/2026:07:26:38 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
[redacted] 45.117.180.152 - - [20/Jul/2026:07:26:48 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/13.0; WordPress/6.4; http://site61003261.com"
[redacted] 45.117.180.152 - - [20/Jul/2026:07:26:59 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 04:29:18
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 00:29:13.732170 2026] [security2:error] [pid 7349:tid 7349] [client 45.117.180.152:59789] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.117.180.152 (+1 hits since last alert)|greatwesternfirearms.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "greatwesternfirearms.com"] [uri "/xmlrpc.php"] [unique_id "al2kGSmL8AHNAUomuTwFMAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐ท
bubausluge
2026-07-18 06:24:40
(3 days ago)
Detected by Aegis SOC: HTTP 5xx Server Errors | MITRE: T1499 | Fails: 131 | Period: 2026-07-18T06:17 ...
show more
Detected by Aegis SOC: HTTP 5xx Server Errors | MITRE: T1499 | Fails: 131 | Period: 2026-07-18T06:17:59 to 2026-07-18T06:23:21
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-18 06:20:32
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 02:20:27.997129 2026] [security2:error] [pid 1602:tid 1627] [client 45.117.180.152:60471] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.117.180.152 (+1 hits since last alert)|arizonasolutionsgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "arizonasolutionsgroup.com"] [uri "/xmlrpc.php"] [unique_id "alsbKz-N-EaIJZXDvqw5HgAAARU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 05:48:28
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 01:48:22.739439 2026] [security2:error] [pid 1846585:tid 1846585] [client 45.117.180.152:60449] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.117.180.152 (+1 hits since last alert)|calvaryadminservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "calvaryadminservices.com"] [uri "/xmlrpc.php"] [unique_id "alsTppZkwMtoP3_jscmB_gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-18 03:14:02
(3 days ago)
(wordpress) Failed wordpress login from 45.117.180.152 (IN/India/-)
Brute-Force
Anonymous
2026-07-17 11:50:10
(4 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-07-17 04:48:19
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
cwytech
2026-07-15 10:45:20
(6 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack
Anonymous
2026-07-15 10:13:58
(6 days ago)
[redacted] 45.117.180.152 - - [15/Jul/2026:12:13:16 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" " ...
show more
[redacted] 45.117.180.152 - - [15/Jul/2026:12:13:16 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "WordPress.com; https://wordpress.com"
[redacted] 45.117.180.152 - - [15/Jul/2026:12:13:26 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
[redacted] 45.117.180.152 - - [15/Jul/2026:12:13:36 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack/12.5; WordPress/6.1; http://site14513786.com"
[redacted] 45.117.180.152 - - [15/Jul/2026:12:13:47 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack/12.5; WordPress/6.4; http://site93494697.com"
[redacted] 45.117.180.152 - - [15/Jul/2026:12:13:57 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 07:49:39
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.117.180.152 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 03:49:33.565557 2026] [security2:error] [pid 4312:tid 4312] [client 45.117.180.152:59838] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.117.180.152 (+1 hits since last alert)|localpetsitters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "localpetsitters.com"] [uri "/xmlrpc.php"] [unique_id "alc7jZt1IluVTBDKQ8j9PwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-15 05:44:40
(6 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack