Anonymous
2026-08-04 17:56:29
(1 month ago)
[redacted] 2.50.137.12 - - [04/Aug/2026:19:55:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jet ...
show more
[redacted] 2.50.137.12 - - [04/Aug/2026:19:55:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 2.50.137.12 - - [04/Aug/2026:19:55:56 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 2.50.137.12 - - [04/Aug/2026:19:56:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 2.50.137.12 - - [04/Aug/2026:19:56:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 2.50.137.12 - - [04/Aug/2026:19:56:28 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
...
show less
Hacking
Web App Attack
🇫🇮
YF
2026-08-04 17:00:51
(1 month ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
🇪🇸
masterguru
2026-08-04 16:58:47
(1 month ago)
(xmlrpc) Failed xmlrpc access from 2.50.137.12 (AE/United Arab Emirates/bba-2-50-137-12.alshamil.net ...
show more
(xmlrpc) Failed xmlrpc access from 2.50.137.12 (AE/United Arab Emirates/bba-2-50-137-12.alshamil.net.ae): 5 in the last 3600 secs (0-122)
show less
Hacking
🇺🇸
TPI-Abuse
2026-08-04 15:13:27
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.12 (bba-2-50-137-12.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.12 (bba-2-50-137-12.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 11:13:18.971733 2026] [security2:error] [pid 329132:tid 329146] [client 2.50.137.12:62256] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.12 (+1 hits since last alert)|plumeraproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "plumeraproductions.com"] [uri "/xmlrpc.php"] [unique_id "anIBjof1KuQ3lZk6Rq41VwAAAQo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 13:40:56
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.12 (bba-2-50-137-12.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.12 (bba-2-50-137-12.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 09:40:50.985363 2026] [security2:error] [pid 1819765:tid 1819765] [client 2.50.137.12:64122] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.12 (+1 hits since last alert)|soonerstone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "soonerstone.com"] [uri "/xmlrpc.php"] [unique_id "anHr4q744B5rEvOjSPbSQAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-08-04 09:37:30
(1 month ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
AE/United Arab Emirates/bba-2-50-137-12.alshamil.net.ae
Web App Attack
🇺🇸
TPI-Abuse
2026-08-04 06:21:05
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.12 (bba-2-50-137-12.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.12 (bba-2-50-137-12.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 02:20:58.899983 2026] [security2:error] [pid 1967643:tid 1967643] [client 2.50.137.12:52431] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.12 (+1 hits since last alert)|serranoscoffee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "serranoscoffee.com"] [uri "/xmlrpc.php"] [unique_id "anGEyprEV5XwI7bfAZFEuQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
bigwavedave
2026-08-04 06:19:28
(1 month ago)
Wordpress Attack
Web App Attack
🇩🇪
rh24
2026-08-03 15:31:26
(1 month ago)
(xmlrpc_405) XMLRPC-Bot 405 2.50.137.12 (AE/United Arab Emirates/bba-2-50-137-12.alshamil.net.ae)
Hacking
🇪🇸
alferez
2026-08-03 13:53:20
(1 month ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 13:32:01
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.12 (bba-2-50-137-12.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.12 (bba-2-50-137-12.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 09:31:52.391558 2026] [security2:error] [pid 1162672:tid 1162672] [client 2.50.137.12:58494] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.12 (+1 hits since last alert)|capriexpress.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "capriexpress.com"] [uri "/xmlrpc.php"] [unique_id "anCYSLG0w9URMWvJHYCRuAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2024-05-06 22:08:51
(2 years ago)
Looking for CMS/PHP/SQL vulnerablilities - 13
Exploited Host
Web App Attack
🇦🇺
MAGIC
2024-04-22 10:01:38
(2 years ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
🇳🇱
wlt-blocker
2024-04-09 19:03:53
(2 years ago)
Attempts to login to mail server with wrong username and/or password
Brute-Force
🇺🇸
TPI-Abuse
2024-03-10 09:03:37
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.12 (bba-2-50-137-12.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.12 (bba-2-50-137-12.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 10 05:02:54.549811 2024] [security2:error] [pid 11839] [client 2.50.137.12:40026] [client 2.50.137.12] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.12 (+1 hits since last alert)|www.wild-goose.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.wild-goose.net"] [uri "/xmlrpc.php"] [unique_id "Ze13PmhioLRNSx0y2xw3gQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack