๐ฆ๐บ
screwlooseit.com.au
2026-08-16 10:39:23
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
PH/Philippines/-
Web App Attack
๐ฉ๐ช
LRob
2026-08-16 02:59:34
(1 day ago)
WordPress login brute-force | req: /xmlrpc.php | UA: Jetpack by WordPress.com
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-15 11:37:48
(2 days ago)
WordPress login brute-force | req: /xmlrpc.php | UA: WordPress.com; https://wordpress.com
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-15 09:39:08
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-15 02:56:29
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 61.9.8.199 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 61.9.8.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 22:56:16.693781 2026] [security2:error] [pid 13157:tid 13157] [client 61.9.8.199:56530] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.9.8.199 (+1 hits since last alert)|ultratecnologia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ultratecnologia.com"] [uri "/xmlrpc.php"] [unique_id "an_VUGXESPgkgvh-So0Y2AAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-08-15 02:00:39
(2 days ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-08-14 15:44:52
(3 days ago)
-:443 61.9.8.199 - - [14/Aug/2026:17:44:51 +0200] - "POST /xmlrpc.php HTTP/1.1" 403 4996 "-" "WordPr ...
show more
-:443 61.9.8.199 - - [14/Aug/2026:17:44:51 +0200] - "POST /xmlrpc.php HTTP/1.1" 403 4996 "-" "WordPress.com; https://wordpress.com"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-14 12:43:05
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 61.9.8.199 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 61.9.8.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 08:42:54.364961 2026] [security2:error] [pid 3679:tid 3679] [client 61.9.8.199:57458] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.9.8.199 (+1 hits since last alert)|oshadega.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "oshadega.com"] [uri "/xmlrpc.php"] [unique_id "an8NTjTHhAJQMP3RQ5vRIwAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-14 10:50:37
(3 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-14 10:29:43
(3 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-14 10:17:28
(3 days ago)
WordPress login brute-force | req: /xmlrpc.php | UA: WordPress.com; https://wordpress.com
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 23:08:54
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 61.9.8.199 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 61.9.8.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 19:08:40.764375 2026] [security2:error] [pid 3756834:tid 3756834] [client 61.9.8.199:34662] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.9.8.199 (+1 hits since last alert)|sharonmauldin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sharonmauldin.com"] [uri "/xmlrpc.php"] [unique_id "an5OeER5k9e7awYxGUl6zQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-13 17:39:11
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
usc-IPDB
2026-08-13 09:01:07
(4 days ago)
61.9.8.199 - - [13/Aug/2026:11:00:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "WordPress.com; ...
show more
61.9.8.199 - - [13/Aug/2026:11:00:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "WordPress.com; https://wordpress.com"
61.9.8.199 - - [13/Aug/2026:11:00:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
61.9.8.199 - - [13/Aug/2026:11:01:07 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "WordPress.com; https://wordpress.com"
...
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-13 08:36:08
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 61.9.8.199 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 61.9.8.199 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 04:35:55.240525 2026] [security2:error] [pid 1542986:tid 1543002] [client 61.9.8.199:38537] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.9.8.199 (+1 hits since last alert)|councilofforeignministers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "councilofforeignministers.com"] [uri "/xmlrpc.php"] [unique_id "an2B6y86eEGymW0K6uOF9wAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack