๐ซ๐ท
dynamix
2026-06-16 14:08:25
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
Kenshin869
2026-06-16 14:08:16
(2 days ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-16 13:30:16
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 09:30:10.688405 2026] [security2:error] [pid 11357:tid 11413] [client 102.205.250.56:42650] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.205.250.56 (+1 hits since last alert)|atlasrecordssearch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "atlasrecordssearch.com"] [uri "/xmlrpc.php"] [unique_id "ajFP4la1UK2CsFzKPHewPQAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-16 11:41:14
(2 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-15 23:30:43
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 19:30:39.031218 2026] [security2:error] [pid 24485:tid 24485] [client 102.205.250.56:55233] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.205.250.56 (+1 hits since last alert)|realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "realclean.net"] [uri "/xmlrpc.php"] [unique_id "ajCLH9YiKrrfcPB-ZSxrqwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 22:25:34
(3 days ago)
[redacted] 102.205.250.56 - - [16/Jun/2026:00:24:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 102.205.250.56 - - [16/Jun/2026:00:24:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.205.250.56 - - [16/Jun/2026:00:25:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 102.205.250.56 - - [16/Jun/2026:00:25:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.4; http://site84592834.com"
[redacted] 102.205.250.56 - - [16/Jun/2026:00:25:22 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.205.250.56 - - [16/Jun/2026:00:25:33 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-15 17:59:47
(3 days ago)
[redacted] 102.205.250.56 - - [15/Jun/2026:19:59:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 102.205.250.56 - - [15/Jun/2026:19:59:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
[redacted] 102.205.250.56 - - [15/Jun/2026:19:59:15 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 102.205.250.56 - - [15/Jun/2026:19:59:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.205.250.56 - - [15/Jun/2026:19:59:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.205.250.56 - - [15/Jun/2026:19:59:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-15 15:56:40
(3 days ago)
[redacted] 102.205.250.56 - - [15/Jun/2026:17:55:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 102.205.250.56 - - [15/Jun/2026:17:55:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.4; http://site67346354.com"
[redacted] 102.205.250.56 - - [15/Jun/2026:17:55:58 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.205.250.56 - - [15/Jun/2026:17:56:07 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.205.250.56 - - [15/Jun/2026:17:56:28 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.205.250.56 - - [15/Jun/2026:17:56:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 12:44:37
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 08:44:31.365381 2026] [security2:error] [pid 15830:tid 15830] [client 102.205.250.56:45508] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.205.250.56 (+1 hits since last alert)|pcga.golf|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pcga.golf"] [uri "/xmlrpc.php"] [unique_id "ai_zr5lVHKk2AucmE8_bYQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-06-14 14:00:23
(4 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
Anonymous
2026-06-14 11:48:02
(4 days ago)
[redacted] 102.205.250.56 - - [14/Jun/2026:13:46:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 102.205.250.56 - - [14/Jun/2026:13:46:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
[redacted] 102.205.250.56 - - [14/Jun/2026:13:46:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.2; http://site16668447.com"
[redacted] 102.205.250.56 - - [14/Jun/2026:13:47:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
[redacted] 102.205.250.56 - - [14/Jun/2026:13:47:53 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 102.205.250.56 - - [14/Jun/2026:13:48:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.1; http://site21565240.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-14 10:50:39
(4 days ago)
[ssd1.kdns.gr] httpd-xmlrpc-post: sites=gflawoffice.com; logs=/var/log/httpd/domains/gflawoffice.com ...
show more
[ssd1.kdns.gr] httpd-xmlrpc-post: sites=gflawoffice.com; logs=/var/log/httpd/domains/gflawoffice.com.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 14:59:33
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 10:59:29.799211 2026] [security2:error] [pid 28125:tid 28125] [client 102.205.250.56:12370] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.205.250.56 (+1 hits since last alert)|theyoungstrategist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theyoungstrategist.com"] [uri "/xmlrpc.php"] [unique_id "aiwe0bzY2u5eRVwr8cF-cgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 22:43:24
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 18:43:19.281938 2026] [security2:error] [pid 20651:tid 20651] [client 102.205.250.56:23018] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.205.250.56 (+1 hits since last alert)|sliconswamp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sliconswamp.com"] [uri "/xmlrpc.php"] [unique_id "ais6B7W1bdlDYeJWJ6CBcQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 20:31:22
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 102.205.250.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 16:31:14.294767 2026] [security2:error] [pid 19541:tid 19541] [client 102.205.250.56:34957] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 102.205.250.56 (+1 hits since last alert)|abundancecompany.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abundancecompany.com"] [uri "/xmlrpc.php"] [unique_id "aisbEnMKQ_ADUgyMsK3YZgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack