Anonymous
2026-09-17 10:48:02
(5 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-14 06:50:27
(1 week ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-14 06:28:19
(1 week ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-11 08:49:00
(1 week ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /xmlrpc.php | ua: Jetpack/12.5; WordPress/6.1; http://site75256984.com | 2026-09-11 08:49 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-08-31 10:31:43
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
WeekendWeb
2026-08-17 11:08:15
(1 month ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 06:58:39
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 02:58:30.945565 2026] [security2:error] [pid 7265:tid 7265] [client 103.25.46.39:59782] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.25.46.39 (+1 hits since last alert)|superzilla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "superzilla.com"] [uri "/xmlrpc.php"] [unique_id "aoKxFrwAKdDA73tv88Rx5wAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 08:22:53
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 04:22:45.636755 2026] [security2:error] [pid 85717:tid 85717] [client 103.25.46.39:52485] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.25.46.39 (+1 hits since last alert)|inverzona.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "inverzona.com"] [uri "/xmlrpc.php"] [unique_id "aoAh1QiWKuR8uskVNBra0AAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-07 09:20:58
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-07 08:56:26
(1 month ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 05:43:08
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 01:43:02.874159 2026] [security2:error] [pid 3450266:tid 3450266] [client 103.25.46.39:60499] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.25.46.39 (+1 hits since last alert)|bonesband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bonesband.com"] [uri "/xmlrpc.php"] [unique_id "anVwZmxDk3jdiQRTEESVrgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-06 08:17:10
(1 month ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.space | URI: /xmlrpc.php | UA: WordPress.com; https://wordpress.com | BODY: <?xml version="1.0"?><methodCall><methodName>metaWeblog.newPost</methodName><params><param><value><string>1</string></value></param><param><value><string>31023</string></value></param><param><value><string>31023</string></value></param><param><value><struct><member><name>title</name><value><string>3fai6cosgudu7q</string></value></member><member><name>description</name><value><string>ol0ms95hw99smacalv74dmu
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-04 07:50:25
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-04 07:37:04
(1 month ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 06:24:54
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.25.46.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 02:24:49.624036 2026] [security2:error] [pid 755083:tid 755083] [client 103.25.46.39:59445] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.25.46.39 (+1 hits since last alert)|rwabutazafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rwabutazafoundation.org"] [uri "/xmlrpc.php"] [unique_id "amw_sXgs_RQ-QGicxI6z1wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack