๐บ๐ธ
TPI-Abuse
2026-08-25 08:36:54
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 04:36:48.828907 2026] [security2:error] [pid 29560:tid 29560] [client 87.241.158.53:7134] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.241.158.53 (+1 hits since last alert)|gaeltv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gaeltv.com"] [uri "/xmlrpc.php"] [unique_id "ao1UIIbxAPHYerqvKNhdogAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-25 07:32:56
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
cwytech
2026-08-24 14:51:43
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 13:22:43
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:22:35.367346 2026] [security2:error] [pid 27922:tid 27922] [client 87.241.158.53:27295] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.241.158.53 (+1 hits since last alert)|36sovereignchambers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "36sovereignchambers.com"] [uri "/xmlrpc.php"] [unique_id "aoxFm5l6Q91eJuCoL_eAvgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
QT
2026-08-23 13:35:05
(3 days ago)
Unauthorised WordPress admin login attempted at 2026-08-23 23:35:05 +1000
Web App Attack
๐บ๐ธ
IndigoRidge
2026-08-23 12:13:30
(3 days ago)
87.241.158.53 - - [23/Aug/2026:08:12:36 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.c ...
show more
87.241.158.53 - - [23/Aug/2026:08:12:36 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
87.241.158.53 - - [23/Aug/2026:08:12:46 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
87.241.158.53 - - [23/Aug/2026:08:12:57 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
87.241.158.53 - - [23/Aug/2026:08:13:18 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
87.241.158.53 - - [23/Aug/2026:08:13:29 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-08-23 10:38:26
(4 days ago)
4.424 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
Anonymous
2026-08-21 13:30:48
(5 days ago)
[redacted] 87.241.158.53 - - [21/Aug/2026:15:30:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 87.241.158.53 - - [21/Aug/2026:15:30:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 87.241.158.53 - - [21/Aug/2026:15:30:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 87.241.158.53 - - [21/Aug/2026:15:30:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
[redacted] 87.241.158.53 - - [21/Aug/2026:15:30:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 87.241.158.53 - - [21/Aug/2026:15:30:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.1; http://site76819136.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 10:48:06
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 06:47:59.643986 2026] [security2:error] [pid 13104:tid 13104] [client 87.241.158.53:63932] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.241.158.53 (+1 hits since last alert)|michaelkivisto.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "michaelkivisto.com"] [uri "/xmlrpc.php"] [unique_id "aogs30u3qzuQOIQmasztcAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 12:30:40
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 08:30:31.820738 2026] [security2:error] [pid 5193:tid 5208] [client 87.241.158.53:63878] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.241.158.53 (+1 hits since last alert)|rawhabitat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rawhabitat.com"] [uri "/xmlrpc.php"] [unique_id "aobzZ-0MaQMQkYNqLMVr1wAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 12:02:13
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 08:02:06.348090 2026] [security2:error] [pid 19480:tid 19480] [client 87.241.158.53:57373] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.241.158.53 (+1 hits since last alert)|ramseycountycorruption.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ramseycountycorruption.com"] [uri "/xmlrpc.php"] [unique_id "aobsvuONEmXVx_nZ4BeXeAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 09:38:18
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 05:38:11.154778 2026] [security2:error] [pid 6643:tid 6643] [client 87.241.158.53:46494] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.241.158.53 (+1 hits since last alert)|mchen-arch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mchen-arch.com"] [uri "/xmlrpc.php"] [unique_id "aobLA-HO48MDgUXqR0kaOQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-08-20 09:00:42
(1 week ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-20 08:04:15
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 87.241.158.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 04:04:09.776141 2026] [security2:error] [pid 30980:tid 30980] [client 87.241.158.53:46488] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 87.241.158.53 (+1 hits since last alert)|laura-stone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "laura-stone.com"] [uri "/xmlrpc.php"] [unique_id "aoa0-XiDakBPCRNLI-GXDgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-20 07:20:04
(1 week ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack