π¦πΊ
screwlooseit.com.au
2026-08-23 06:23:09
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
BR/Brazil/b150af23.virtua.com.br
Web App Attack
π«π·
Kenshin869
2026-08-22 15:18:43
(2 days ago)
Wordpress unauthorized access attempt
Brute-Force
π©πͺ
ghostwarriors
2026-08-22 14:50:34
(2 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 14:47:52
(2 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
π§πΎ
lns.bz
2026-08-21 12:37:18
(3 days ago)
Banned for trying to access xmlrpc [BY]
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 11:38:56
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 177.80.175.35 (b150af23.virtua.com.br): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 177.80.175.35 (b150af23.virtua.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 07:38:49.947875 2026] [security2:error] [pid 14998:tid 14998] [client 177.80.175.35:53234] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 177.80.175.35 (+1 hits since last alert)|loriarsenault.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "loriarsenault.com"] [uri "/xmlrpc.php"] [unique_id "aog4yV1nMAaB8L5Xks_JgAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
GabrielJST
2026-08-21 08:20:40
(3 days ago)
(wordpress) Failed wordpress login from 177.80.175.35 (BR/Brazil/b150af23.virtua.com.br)
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-21 07:22:11
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 177.80.175.35 (b150af23.virtua.com.br): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 177.80.175.35 (b150af23.virtua.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 03:22:02.047756 2026] [security2:error] [pid 778:tid 879] [client 177.80.175.35:58366] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 177.80.175.35 (+1 hits since last alert)|vbmonsterdev.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vbmonsterdev.com"] [uri "/xmlrpc.php"] [unique_id "aof8muje4QFsOIAQjKo89wAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 05:20:00
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 177.80.175.35 (b150af23.virtua.com.br): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 177.80.175.35 (b150af23.virtua.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 01:19:55.224182 2026] [security2:error] [pid 4150:tid 4150] [client 177.80.175.35:60451] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 177.80.175.35 (+1 hits since last alert)|dianamead.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dianamead.com"] [uri "/xmlrpc.php"] [unique_id "aoff-z3pd_hmCelA3qHFCgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Lee Daniel
2026-08-21 04:17:07
(3 days ago)
[21/Aug/2026:00:16:24.086366 --0400] aofRGC9kp-j9blUBnHkxQwAAAIo 177.80.175.35 40236 127.0.0.1 7081
...
show more
[21/Aug/2026:00:16:24.086366 --0400] aofRGC9kp-j9blUBnHkxQwAAAIo 177.80.175.35 40236 127.0.0.1 7081
[21/Aug/2026:00:16:34.726895 --0400] aofRIqB4myUhjUoCYRMBrgAAAVM 177.80.175.35 52298 127.0.0.1 7081
[21/Aug/2026:00:16:45.400833 --0400] aofRLU0jw-FYHvrKBg8eQgAAAAw 177.80.175.35 44856 127.0.0.1 7081
[21/Aug/2026:00:16:56.036224 --0400] aofROC9kp-j9blUBnHkxgwAAAII 177.80.175.35 37226 127.0.0.1 7081
[21/Aug/2026:00:17:06.723781 --0400] aofRQqB4myUhjUoCYRMBvgAAAU8 177.80.175.35 34018 127.0.0.1 7081
...
show less
DDoS Attack
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-21 01:01:51
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 177.80.175.35 (b150af23.virtua.com.br): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 177.80.175.35 (b150af23.virtua.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 21:01:46.396193 2026] [security2:error] [pid 24430:tid 24430] [client 177.80.175.35:56702] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 177.80.175.35 (+1 hits since last alert)|greenlight.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "greenlight.us"] [uri "/xmlrpc.php"] [unique_id "aoejetn47X6txMLemdqw3gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
rh24
2026-08-20 22:35:06
(3 days ago)
(xmlrpc_405) XMLRPC-Bot 405 177.80.175.35 (BR/Brazil/b150af23.virtua.com.br)
Hacking
π©πͺ
Marc
2026-08-20 21:53:46
(3 days ago)
177.80.175.35 - - [20/Aug/2026:23:53:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4670 "-" "Jetpack/12. ...
show more
177.80.175.35 - - [20/Aug/2026:23:53:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4670 "-" "Jetpack/12.0; WordPress/6.3; http://site50541766.com" 177.80.175.35 - - [20/Aug/2026:23:53:34 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4670 "-" "WordPress.com; https://wordpress.com" 177.80.175.35 - - [20/Aug/2026:23:53:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4670 "-" "Jetpack/12.1; WordPress/6.2; http://site25855094.com"
show less
Brute-Force
Web App Attack
πΊπΈ
IndigoRidge
2026-08-20 21:45:49
(3 days ago)
177.80.175.35 - - [20/Aug/2026:17:44:13 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5724 "-" "WordPress.c ...
show more
177.80.175.35 - - [20/Aug/2026:17:44:13 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5724 "-" "WordPress.com; https://wordpress.com"
177.80.175.35 - - [20/Aug/2026:17:44:45 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5724 "-" "WordPress.com; https://wordpress.com"
177.80.175.35 - - [20/Aug/2026:17:44:56 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5724 "-" "WordPress.com; https://wordpress.com"
177.80.175.35 - - [20/Aug/2026:17:45:17 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5724 "-" "WordPress.com; https://wordpress.com"
177.80.175.35 - - [20/Aug/2026:17:45:49 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5724 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-20 21:24:54
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 177.80.175.35 (b150af23.virtua.com.br): 1 in th ...
show more
(mod_security) mod_security (id:240335) triggered by 177.80.175.35 (b150af23.virtua.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 17:24:46.425116 2026] [security2:error] [pid 31607:tid 31607] [client 177.80.175.35:58480] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 177.80.175.35 (+1 hits since last alert)|frelsburg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "frelsburg.com"] [uri "/xmlrpc.php"] [unique_id "aodwnrHGqiCQaFl2uSvrfgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack