๐บ๐ธ
TPI-Abuse
2026-06-15 21:07:21
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl ...
show more
(mod_security) mod_security (id:240335) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 17:07:17.402540 2026] [security2:error] [pid 29773:tid 29861] [client 5.132.69.157:62017] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.132.69.157 (+1 hits since last alert)|tsengkwongchi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tsengkwongchi.com"] [uri "/xmlrpc.php"] [unique_id "ajBphXLKrpPjNLA35cMPgwAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 17:37:32
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl ...
show more
(mod_security) mod_security (id:240335) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 13:37:28.082108 2026] [security2:error] [pid 26462:tid 26462] [client 5.132.69.157:50456] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.132.69.157 (+1 hits since last alert)|susanleeward.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "susanleeward.com"] [uri "/xmlrpc.php"] [unique_id "ai7m2JMz8mH889tW0_2m6QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-14 17:30:43
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-11 18:51:53
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 18:12:31
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl ...
show more
(mod_security) mod_security (id:240335) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 14:12:25.910694 2026] [security2:error] [pid 24543:tid 24543] [client 5.132.69.157:60386] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 5.132.69.157 (+1 hits since last alert)|havenlaneministries.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "havenlaneministries.com"] [uri "/xmlrpc.php"] [unique_id "air6iebT45CL7JvGncFe_AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-04-12 20:10:13
(2 months ago)
Unauthorized access to webpage admin
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-04-05 19:46:28
(2 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
NL/Netherlands/157-69-132-5.ftth.glasoperator.nl
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-03-30 20:34:38
(2 months ago)
2026-03-30T21:34:37.348309+01:00 ipoac.nl wordpress(-)-: XML-RPC authentication attempt for unknown ...
show more
2026-03-30T21:34:37.348309+01:00 ipoac.nl wordpress(-)-: XML-RPC authentication attempt for unknown user 87849 from 5.132.69.157
show less
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-03-29 19:54:05
(2 months ago)
2026-03-29T20:54:04.645641+01:00 ipoac.nl wordpress(-)-: XML-RPC authentication attempt for unknown ...
show more
2026-03-29T20:54:04.645641+01:00 ipoac.nl wordpress(-)-: XML-RPC authentication attempt for unknown user 67341 from 5.132.69.157
show less
Web App Attack
๐ซ๐ฎ
YF
2026-03-19 20:00:19
(2 months ago)
xmlrpc.php (Potential DDoS or brute force)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-16 21:50:50
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl ...
show more
(mod_security) mod_security (id:225170) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 17:50:47.026889 2026] [security2:error] [pid 8854:tid 8877] [client 5.132.69.157:54951] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kemalinal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kemalinal.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abh7N0smN16v55q19mVGegAAANQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-03-16 21:27:56
(3 months ago)
(wordpress) Failed wordpress login from 5.132.69.157 (NL/The Netherlands/South Holland/Spijkenisse/1 ...
show more
(wordpress) Failed wordpress login from 5.132.69.157 (NL/The Netherlands/South Holland/Spijkenisse/157-69-132-5.ftth.glasoperator.nl)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-16 19:15:21
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl ...
show more
(mod_security) mod_security (id:225170) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 15:15:13.968458 2026] [security2:error] [pid 18731:tid 18780] [client 5.132.69.157:60388] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||busybeerestaurant.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "busybeerestaurant.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abhWwSo-mHPXvooBKPoM_AAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 21:16:20
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl ...
show more
(mod_security) mod_security (id:225170) triggered by 5.132.69.157 (157-69-132-5.ftth.glasoperator.nl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 17:16:14.266398 2026] [security2:error] [pid 3538:tid 3538] [client 5.132.69.157:57195] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fundingangelinvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fundingangelinvestors.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abXQHi2cM6qpXLniE0GRLQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-03-14 02:14:15
(3 months ago)
Brute-Force
Web App Attack