๐บ๐ธ
TPI-Abuse
2026-08-13 20:07:27
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 98.97.131.129 (customer.brsabra1.isp.starlink.c ...
show more
(mod_security) mod_security (id:240335) triggered by 98.97.131.129 (customer.brsabra1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 16:07:22.227465 2026] [security2:error] [pid 3129781:tid 3129781] [client 98.97.131.129:49288] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 98.97.131.129 (+1 hits since last alert)|kildarafarms.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kildarafarms.com"] [uri "/xmlrpc.php"] [unique_id "an4j-mg8FsSFdDluPAbJoQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 16:31:33
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 98.97.131.129 (customer.brsabra1.isp.starlink.c ...
show more
(mod_security) mod_security (id:240335) triggered by 98.97.131.129 (customer.brsabra1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 12:31:26.622467 2026] [security2:error] [pid 1563:tid 1563] [client 98.97.131.129:3225] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 98.97.131.129 (+1 hits since last alert)|jesussotoca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jesussotoca.com"] [uri "/xmlrpc.php"] [unique_id "an3xXsq4pQWxT72H90sEmwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-13 11:46:29
(2 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
kosada.com
2026-08-07 23:51:38
(2 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ซ๐ฎ
YF
2026-08-06 20:30:59
(3 weeks ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
IndigoRidge
2026-08-06 15:13:48
(3 weeks ago)
98.97.131.129 - - [06/Aug/2026:11:12:22 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.c ...
show more
98.97.131.129 - - [06/Aug/2026:11:12:22 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
98.97.131.129 - - [06/Aug/2026:11:13:05 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
98.97.131.129 - - [06/Aug/2026:11:13:26 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
98.97.131.129 - - [06/Aug/2026:11:13:37 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
98.97.131.129 - - [06/Aug/2026:11:13:47 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-08-06 12:33:43
(3 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-08-06 11:46:03
(3 weeks ago)
[ThuAug0613:45:59.0489032026][security2:error][pid3959792:tid3959939][client98.97.131.129:0]ModSecur ...
show more
[ThuAug0613:45:59.0489032026][security2:error][pid3959792:tid3959939][client98.97.131.129:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"safeoncloud.ch\"][uri\"/xmlrpc.php\"][unique_id\"anRz95arM5kB5Q2ItKqEkwAAARg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-05 19:47:46
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 98.97.131.129 (customer.brsabra1.isp.starlink.c ...
show more
(mod_security) mod_security (id:225170) triggered by 98.97.131.129 (customer.brsabra1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 15:47:38.019587 2026] [security2:error] [pid 1307900:tid 1307900] [client 98.97.131.129:6943] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||joevallone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "joevallone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anOTWouSQERIG5N8tV8FuQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-05 11:11:52
(3 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-04 16:12:09
(3 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ท
masterguru
2026-08-04 12:05:21
(3 weeks ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-04 10:08:47
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 98.97.131.129 (customer.brsabra1.isp.starlink.c ...
show more
(mod_security) mod_security (id:240335) triggered by 98.97.131.129 (customer.brsabra1.isp.starlink.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 06:08:41.947126 2026] [security2:error] [pid 1924653:tid 1924653] [client 98.97.131.129:7144] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 98.97.131.129 (+1 hits since last alert)|yerevanpress.am|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yerevanpress.am"] [uri "/xmlrpc.php"] [unique_id "anG6KVVBOgYuV7CJ-PiujAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-08-03 18:05:02
(3 weeks ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐ฎ๐น
ciccio diddo
2026-08-03 17:54:59
(3 weeks ago)
CMS/WP Exploit xmlrpc port:Tcp/80,443
Brute-Force
Web App Attack