๐บ๐ธ
TPI-Abuse
2026-07-24 10:47:24
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:47:18.260023 2026] [security2:error] [pid 1994581:tid 1994581] [client 160.30.104.98:1796] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.30.104.98 (+1 hits since last alert)|tomartsmedia.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tomartsmedia.org"] [uri "/xmlrpc.php"] [unique_id "amNCtkUQhlkwURHbmxpWmQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 10:03:22
(1 week ago)
[redacted] 160.30.104.98 - - [24/Jul/2026:12:02:38 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6642 "-" " ...
show more
[redacted] 160.30.104.98 - - [24/Jul/2026:12:02:38 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6642 "-" "Jetpack/13.0; WordPress/6.1; http://site60232709.com"
[redacted] 160.30.104.98 - - [24/Jul/2026:12:02:49 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6597 "-" "WordPress.com; https://wordpress.com"
[redacted] 160.30.104.98 - - [24/Jul/2026:12:03:00 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6597 "-" "WordPress.com; https://wordpress.com"
[redacted] 160.30.104.98 - - [24/Jul/2026:12:03:11 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6642 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
[redacted] 160.30.104.98 - - [24/Jul/2026:12:03:21 +0200] "POST /xmlrpc.php HTTP/1.1" 403 6556 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐ง๐ฌ
HighWay
2026-07-23 09:07:04
(1 week ago)
160.30.104.98 - - [23/Jul/2026:09:06:41 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4665 "-" "Jetpack by ...
show more
160.30.104.98 - - [23/Jul/2026:09:06:41 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4665 "-" "Jetpack by WordPress.com"
160.30.104.98 - - [23/Jul/2026:09:06:51 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4664 "-" "Jetpack by WordPress.com"
160.30.104.98 - - [23/Jul/2026:09:07:02 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4663 "-" "Jetpack by WordPress.com"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐จ๐ญ
Mario Bretscher
2026-07-22 04:58:55
(1 week ago)
Jul 22 06:58:43 tubegrabe-stafel.ch Cerber(tubegrabe-stafel.ch)[1216921]: Authentication failure for ...
show more
Jul 22 06:58:43 tubegrabe-stafel.ch Cerber(tubegrabe-stafel.ch)[1216921]: Authentication failure for admin from 160.30.104.98
Jul 22 06:58:54 tubegrabe-stafel.ch Cerber(tubegrabe-stafel.ch)[1210664]: Authentication failure for admin from 160.30.104.98
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-07-21 07:16:01
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 03:15:56.068156 2026] [security2:error] [pid 3278753:tid 3278819] [client 160.30.104.98:53394] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.30.104.98 (+1 hits since last alert)|killasgarage.bike|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "killasgarage.bike"] [uri "/xmlrpc.php"] [unique_id "al8crFcNjZY5QmcXd258TgAAAcQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-21 06:27:55
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-21 03:00:18
(1 week ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-18 05:28:35
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 01:28:29.856016 2026] [security2:error] [pid 30338:tid 30338] [client 160.30.104.98:49716] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.30.104.98 (+1 hits since last alert)|capriexpress.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "capriexpress.com"] [uri "/xmlrpc.php"] [unique_id "alsO_XJwQ5c-rDmFTlTV4gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 07:09:55
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 03:09:51.470063 2026] [security2:error] [pid 10650:tid 10650] [client 160.30.104.98:2418] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.30.104.98 (+1 hits since last alert)|f40ph.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "f40ph.org"] [uri "/xmlrpc.php"] [unique_id "alnVP-IT_UpOgPRREnD9YAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-16 01:18:03
(2 weeks ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 12:45:25
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 08:45:19.017314 2026] [security2:error] [pid 23420:tid 23420] [client 160.30.104.98:51169] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.30.104.98 (+1 hits since last alert)|activethinkers.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "activethinkers.net"] [uri "/xmlrpc.php"] [unique_id "aleA36-M58XBefvWW5f6PAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 15:22:28
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.30.104.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 11:22:21.815304 2026] [security2:error] [pid 12163:tid 12194] [client 160.30.104.98:62929] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.30.104.98 (+1 hits since last alert)|travelusa.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "travelusa.us"] [uri "/xmlrpc.php"] [unique_id "alZULYpJV3AxZ7HP2MN_FAAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-14 15:20:34
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-14 15:20:13
(2 weeks ago)
(wordpress) Failed wordpress login from 160.30.104.98 (PK/Pakistan/-/-/-/[redacted])
Brute-Force
Anonymous
2026-07-14 15:18:50
(2 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack