๐บ๐ธ
bigwavedave
2026-07-22 16:51:34
(18 hours ago)
Wordpress Attack
Web App Attack
๐ฉ๐ช
LRob
2026-07-19 19:14:05
(3 days ago)
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Jetpack/13.0; WordPress/6.1; http://site1457105 ...
show more
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Jetpack/13.0; WordPress/6.1; http://site14571051.com
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 17:44:52
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 160.30.39.38 (static-160-30-39-38.aeronetonline ...
show more
(mod_security) mod_security (id:240335) triggered by 160.30.39.38 (static-160-30-39-38.aeronetonline.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 13:44:47.582715 2026] [security2:error] [pid 4480:tid 4480] [client 160.30.39.38:58055] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.30.39.38 (+1 hits since last alert)|casapapayasanmiguel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "casapapayasanmiguel.com"] [uri "/xmlrpc.php"] [unique_id "al0ND42DdFN1--VRw5nXSgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-12 09:05:37
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-09 15:08:26
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
konseptit
2026-07-06 17:08:20
(2 weeks ago)
(wordpress) Failed wordpress login from 160.30.39.38 (IN/India/static-160-30-39-38.aeronetonline.in)
Brute-Force
Anonymous
2026-07-03 17:02:42
(2 weeks ago)
[da.kdns.gr] httpd-xmlrpc-post: sites=www.oro24.gr; logs=/var/log/httpd/domains/oro24.gr.log; sample ...
show more
[da.kdns.gr] httpd-xmlrpc-post: sites=www.oro24.gr; logs=/var/log/httpd/domains/oro24.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
Anonymous
2026-07-03 15:24:44
(2 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 14:27:30
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 160.30.39.38 (static-160-30-39-38.aeronetonline ...
show more
(mod_security) mod_security (id:240335) triggered by 160.30.39.38 (static-160-30-39-38.aeronetonline.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 10:27:21.717388 2026] [security2:error] [pid 8562:tid 8562] [client 160.30.39.38:49697] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.30.39.38 (+1 hits since last alert)|celltechs.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "celltechs.net"] [uri "/xmlrpc.php"] [unique_id "akUjyeahRf96cvVrMQmVkgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-29 17:50:31
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 160.30.39.38 (static-160-30-39-38.aeronetonline ...
show more
(mod_security) mod_security (id:240335) triggered by 160.30.39.38 (static-160-30-39-38.aeronetonline.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 13:50:26.790462 2026] [security2:error] [pid 13372:tid 13372] [client 160.30.39.38:50625] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.30.39.38 (+1 hits since last alert)|breezentry.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "breezentry.com"] [uri "/xmlrpc.php"] [unique_id "akKwYmvGBfJtQIr3u4V_8wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-29 17:04:03
(3 weeks ago)
Wordfence waf block on pameganslaw
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-14 05:51:29
(1 month ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
static-160-30-39-38.aeronetonline.in
Web App Attack
๐ฉ๐ช
grassau.com
2026-05-30 13:08:50
(1 month ago)
(wordpress) Failed wordpress login from 160.30.39.38 (IN/India/Telangana/Hyderabad/static-160-30-39- ...
show more
(wordpress) Failed wordpress login from 160.30.39.38 (IN/India/Telangana/Hyderabad/static-160-30-39-38.aeronetonline.in)
show less
Brute-Force
Anonymous
2026-05-24 17:06:05
(1 month ago)
Bot / scanning and/or hacking attempts: GET /xmlrpc.php HTTP/1.1, POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-05-21 17:28:42
(2 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack