๐ช๐ธ
librebit
2026-07-23 02:19:58
(2 weeks ago)
Brute force
Brute-Force
๐ณ๐ฑ
debestelapp
2026-07-21 20:55:07
(2 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 20:00:34
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 16:00:30.697222 2026] [security2:error] [pid 10651:tid 10651] [client 196.15.14.245:63994] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.15.14.245 (+1 hits since last alert)|rentkase.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rentkase.com"] [uri "/xmlrpc.php"] [unique_id "al_P3uQi3jQeATy5kHJkgAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-07-21 03:27:24
(2 weeks ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 17:31:39
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 13:31:33.942012 2026] [security2:error] [pid 4457:tid 4457] [client 196.15.14.245:64299] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.15.14.245 (+1 hits since last alert)|parastesh.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "parastesh.org"] [uri "/xmlrpc.php"] [unique_id "al5bdRwGAtEFTdd--pgDaAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 04:25:26
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 00:25:18.714745 2026] [security2:error] [pid 2089387:tid 2089404] [client 196.15.14.245:63144] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.15.14.245 (+1 hits since last alert)|thecraftsycat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thecraftsycat.com"] [uri "/xmlrpc.php"] [unique_id "alsALohpOh5BEKQ3zTU-CgAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-07-18 03:47:38
(2 weeks ago)
196.15.14.245 - - [18/Jul/2026:05:47:37 +0200] "POST /xmlrpc.php HTTP/1.1" "WordPress.com; https://w ...
show more
196.15.14.245 - - [18/Jul/2026:05:47:37 +0200] "POST /xmlrpc.php HTTP/1.1" "WordPress.com; https://wordpress.com"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 01:04:03
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 21:03:55.869900 2026] [security2:error] [pid 1476527:tid 1476527] [client 196.15.14.245:64070] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.15.14.245 (+1 hits since last alert)|innovacionesnimba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "innovacionesnimba.com"] [uri "/xmlrpc.php"] [unique_id "alrQ-6RHuIoPyqDlDIOzbgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 20:11:26
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 16:11:22.188086 2026] [security2:error] [pid 17954:tid 17954] [client 196.15.14.245:63787] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.15.14.245 (+1 hits since last alert)|bfpsamoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bfpsamoa.com"] [uri "/xmlrpc.php"] [unique_id "alqMapG7z1IrR4YZ7Rw3EAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 17:52:30
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 13:52:25.784747 2026] [security2:error] [pid 32345:tid 32345] [client 196.15.14.245:63377] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.15.14.245 (+1 hits since last alert)|localpetsitters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "localpetsitters.com"] [uri "/xmlrpc.php"] [unique_id "alpr2SDOBvZsRDMbz3un_wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-07-16 13:28:33
(2 weeks ago)
(xmlrpc) Failed xmlrpc access from 196.15.14.245 (ZA/South Africa/-): 5 in the last 3600 secs (0-122 ...
show more
(xmlrpc) Failed xmlrpc access from 196.15.14.245 (ZA/South Africa/-): 5 in the last 3600 secs (0-122)
show less
Hacking
๐ณ๐ฑ
Site.eu
2026-07-16 13:25:30
(2 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-16 13:01:18
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.15.14.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 09:01:14.274234 2026] [security2:error] [pid 2505:tid 2505] [client 196.15.14.245:63089] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.15.14.245 (+1 hits since last alert)|verdeprofundo.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "verdeprofundo.net"] [uri "/xmlrpc.php"] [unique_id "aljWGr6oWXV6KhtDqOq6NAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-16 12:31:04
(3 weeks ago)
196.15.14.245 - - [16/Jul/2026:08:28:55 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5760 "-" "WordPress.c ...
show more
196.15.14.245 - - [16/Jul/2026:08:28:55 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5760 "-" "WordPress.com; https://wordpress.com"
196.15.14.245 - - [16/Jul/2026:08:29:06 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5760 "-" "WordPress.com; https://wordpress.com"
196.15.14.245 - - [16/Jul/2026:08:30:31 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5760 "-" "WordPress.com; https://wordpress.com"
196.15.14.245 - - [16/Jul/2026:08:30:42 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5760 "-" "WordPress.com; https://wordpress.com"
196.15.14.245 - - [16/Jul/2026:08:31:04 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5760 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-07-16 11:24:32
(3 weeks ago)
Probing websites for vulnerabilities
Web App Attack