๐ช๐ธ
alferez
2026-08-04 09:43:21
(2 weeks ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-04 09:03:48
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 125.166.9.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 125.166.9.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 05:03:44.862973 2026] [security2:error] [pid 2142269:tid 2142269] [client 125.166.9.91:30198] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.166.9.91 (+1 hits since last alert)|truthsabouthealthcare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "truthsabouthealthcare.com"] [uri "/xmlrpc.php"] [unique_id "anGq8PBDpZ1cQIzRrdKHXAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-08-03 00:48:24
(2 weeks ago)
(xmlrpc) Failed xmlrpc access from 125.166.9.91 (ID/Indonesia/-): 5 in the last 3600 secs (0-122)
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-03 00:47:07
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 125.166.9.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 125.166.9.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 20:47:02.250600 2026] [security2:error] [pid 2040845:tid 2040845] [client 125.166.9.91:15524] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.166.9.91 (+1 hits since last alert)|arriagarealestate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "arriagarealestate.com"] [uri "/xmlrpc.php"] [unique_id "am_lBqcY5efzUokzbFJEMAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-02 07:39:33
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-02 05:46:33
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 125.166.9.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 125.166.9.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 01:46:25.229827 2026] [security2:error] [pid 16278:tid 16278] [client 125.166.9.91:21805] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.166.9.91 (+1 hits since last alert)|learnserve.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "learnserve.net"] [uri "/xmlrpc.php"] [unique_id "am7ZsaowJGPaqNvbkag00QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-08-02 04:49:29
(2 weeks ago)
125.166.9.91 - - [02/Aug/2026:00:48:08 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.co ...
show more
125.166.9.91 - - [02/Aug/2026:00:48:08 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
125.166.9.91 - - [02/Aug/2026:00:48:43 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
125.166.9.91 - - [02/Aug/2026:00:49:05 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
125.166.9.91 - - [02/Aug/2026:00:49:15 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
125.166.9.91 - - [02/Aug/2026:00:49:28 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 07:38:37
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 125.166.9.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 125.166.9.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 03:38:33.742161 2026] [security2:error] [pid 1522331:tid 1522331] [client 125.166.9.91:3663] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.166.9.91 (+1 hits since last alert)|crr-construction.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "crr-construction.com"] [uri "/xmlrpc.php"] [unique_id "am2ieRhc4PSWUDEcSk5L6QAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-08-01 03:21:52
(3 weeks ago)
4.870 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ฉ๐ช
LRob
2026-08-01 00:57:01
(3 weeks ago)
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Jetpack by WordPress.com
Brute-Force
Web App Attack
๐ณ๐ฑ
debestelapp
2026-08-01 00:50:05
(3 weeks ago)
Web App Attack
๐บ๐ธ
xmission.com
2026-05-11 05:21:59
(3 months ago)
Blocked by UFW (TCP on 9101)
Source port: 32893
TTL: 112
Packet length: 48
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 9101)
Source port: 32893
TTL: 112
Packet length: 48
TOS: 0x08
This report (for 125.166.9.91) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Anonymous
2024-10-05 05:44:28
(1 year ago)
Ports: 25,587,465; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฟ๐ฆ
maximonline.co.za
2024-10-02 01:30:15
(1 year ago)
Brute Force SMTP AUTH Attack
Brute-Force
Anonymous
2024-10-01 03:19:05
(1 year ago)
Ports: 25,2525,587,465; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH