π¨π¦
polycoda
2026-07-20 17:18:55
(7 hours ago)
AutoBlock: π WordPress Login Brute Force (20X or 30X) (Decay-Based)
Brute-Force
Web App Attack
Anonymous
2026-07-20 17:18:00
(7 hours ago)
[redacted] 103.137.25.5 - - [20/Jul/2026:19:17:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Wo ...
show more
[redacted] 103.137.25.5 - - [20/Jul/2026:19:17:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 103.137.25.5 - - [20/Jul/2026:19:17:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 103.137.25.5 - - [20/Jul/2026:19:17:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 103.137.25.5 - - [20/Jul/2026:19:17:48 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 103.137.25.5 - - [20/Jul/2026:19:17:59 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-17 11:04:55
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 103.137.25.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.137.25.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 07:04:41.358765 2026] [security2:error] [pid 740970:tid 740970] [client 103.137.25.5:49234] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.137.25.5 (+1 hits since last alert)|tigerpathteam.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tigerpathteam.org"] [uri "/xmlrpc.php"] [unique_id "aloMSRiepQAwFplNoJ6BgAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
NotCool
2026-07-14 11:01:05
(6 days ago)
(XMLRPC) WP XMLPRC Attack 103.137.25.5 (PK/Pakistan/-): 50 in the last 3600 secs
Web App Attack
π«π·
bazter.pro
2026-07-13 08:55:28
(1 week ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-07-10 15:07:47
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-10 13:13:21
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 103.137.25.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.137.25.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 09:13:05.151086 2026] [security2:error] [pid 25830:tid 25830] [client 103.137.25.5:59804] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.137.25.5 (+1 hits since last alert)|nolaanime.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nolaanime.com"] [uri "/xmlrpc.php"] [unique_id "alDv4X0edAvjkDUusFQt3QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
oralunal
2026-07-09 06:56:30
(1 week ago)
IP banned by Fail2Ban in jail its-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-07-09 06:52:26
(1 week ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
PK/Pakistan/-
Web App Attack
Anonymous
2026-07-04 17:00:10
(2 weeks ago)
Attac
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-01 07:36:39
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.137.25.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.137.25.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 03:36:23.676808 2026] [security2:error] [pid 21941:tid 21941] [client 103.137.25.5:63733] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.137.25.5 (+1 hits since last alert)|theamarals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theamarals.com"] [uri "/xmlrpc.php"] [unique_id "akTDdwVPmOOu2JzP0Y5N_QAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-06-13 07:15:33
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack