๐น๐ท
rtbh.com.tr
2026-01-20 20:11:08
(4 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-29 18:29:14
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 81.88.52.154 (lhwp3154.webapps.net): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 81.88.52.154 (lhwp3154.webapps.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 13:29:06.212585 2025] [security2:error] [pid 29212:tid 29212] [client 81.88.52.154:39362] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 81.88.52.154 (+1 hits since last alert)|indiahouseportland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "indiahouseportland.com"] [uri "/xmlrpc.php"] [unique_id "aVLIcpq5QiOPaGK-fBLQQAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-29 04:26:56
(5 months ago)
[redacted] 81.88.52.154 - - [29/Dec/2025:05:26:49 +0100] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Mo ...
show more
[redacted] 81.88.52.154 - - [29/Dec/2025:05:26:49 +0100] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:25.0) Gecko/20100101 Firefox/29.0"
[redacted] 81.88.52.154 - - [29/Dec/2025:05:26:50 +0100] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:25.0) Gecko/20100101 Firefox/29.0"
[redacted] 81.88.52.154 - - [29/Dec/2025:05:26:50 +0100] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:25.0) Gecko/20100101 Firefox/29.0"
[redacted] 81.88.52.154 - - [29/Dec/2025:05:26:51 +0100] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:25.0) Gecko/20100101 Firefox/29.0"
[redacted] 81.88.52.154 - - [29/Dec/2025:05:26:52 +0100] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:25.0) Gecko/20100101 Firefox/29.0"
[redacted] 81.88.52.154 - - [29/Dec/2025:05:26:53
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 01:28:42
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 81.88.52.154 (lhwp3154.webapps.net): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 81.88.52.154 (lhwp3154.webapps.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 20:28:36.105417 2025] [security2:error] [pid 6840:tid 6840] [client 81.88.52.154:46638] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 81.88.52.154 (+1 hits since last alert)|doublenaughtspycar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "doublenaughtspycar.com"] [uri "/xmlrpc.php"] [unique_id "aVHZRB1hZcrCLpepTXYmmAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-28 21:59:55
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 81.88.52.154 (lhwp3154.webapps.net): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 81.88.52.154 (lhwp3154.webapps.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 28 16:59:50.223791 2025] [security2:error] [pid 27674:tid 27674] [client 81.88.52.154:33926] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 81.88.52.154 (+1 hits since last alert)|serranoscoffee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "serranoscoffee.com"] [uri "/xmlrpc.php"] [unique_id "aVGoVhDmf8AzNtvjeXfwbwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
rtbh.com.tr
2025-12-28 20:10:42
(5 months ago)
list.rtbh.com.tr report: tcp/0
Brute-Force
๐ซ๐ท
SpaceHost-Server
2025-12-21 22:29:57
(5 months ago)
81.88.52.154 - - [21/Dec/2025:23:29:54 +0100] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Mozilla/5.0 ...
show more
81.88.52.154 - - [21/Dec/2025:23:29:54 +0100] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Mozilla/5.0 (Windows NT 6.0; rv:34.0) Gecko/20100101 Firefox/34.0"
81.88.52.154 - - [21/Dec/2025:23:29:55 +0100] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Mozilla/5.0 (Windows NT 6.0; rv:34.0) Gecko/20100101 Firefox/34.0"
81.88.52.154 - - [21/Dec/2025:23:29:56 +0100] "POST /xmlrpc.php HTTP/1.1" 200 4894 "-" "Mozilla/5.0 (Windows NT 6.0; rv:34.0) Gecko/20100101 Firefox/34.0"
show less
Hacking
Web App Attack
๐ช๐ธ
masterguru
2025-12-21 20:48:29
(5 months ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (5000900-122)
Web App Attack
๐ฉ๐ช
stinpriza
2025-12-20 22:02:06
(5 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-20 10:37:59
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 81.88.52.154 (lhwp3154.webapps.net): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.52.154 (lhwp3154.webapps.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 20 05:37:52.800939 2025] [security2:error] [pid 12680:tid 12731] [client 81.88.52.154:58846] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||woodamy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "woodamy.com"] [uri "/wp-json/wp/v2/users.json"] [unique_id "aUZ8gG0kVjepkQVrTgMyZAAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
octageeks.com
2025-12-20 05:07:36
(5 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐ฉ๐ช
stinpriza
2025-12-19 19:26:14
(5 months ago)
Web App Attack
Web App Attack
๐ฉ๐ช
big-cloud.nl
2025-12-19 04:14:15
(5 months ago)
Try to access /xmlrpc.php
Web App Attack
๐ฎ๐ฉ
Burayot
2025-12-16 05:46:23
(5 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 81.88.52.154 (IT/Italy/lhwp3154.web ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 81.88.52.154 (IT/Italy/lhwp3154.webapps.net): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2025-12-16 00:56:58
(5 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH