๐ซ๐ท
dynamix
2026-08-25 02:35:30
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
IndigoRidge
2026-08-21 06:16:40
(6 days ago)
103.224.152.116 - - [21/Aug/2026:02:13:59 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress ...
show more
103.224.152.116 - - [21/Aug/2026:02:13:59 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress.com; https://wordpress.com"
103.224.152.116 - - [21/Aug/2026:02:14:09 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress.com; https://wordpress.com"
103.224.152.116 - - [21/Aug/2026:02:14:20 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress.com; https://wordpress.com"
103.224.152.116 - - [21/Aug/2026:02:15:24 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress.com; https://wordpress.com"
103.224.152.116 - - [21/Aug/2026:02:16:38 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5122 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ซ๐ท
Kenshin869
2026-08-20 09:12:08
(6 days ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-20 06:31:03
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 103.224.152.116 (116.152.224.103-in-addr.arpa-m ...
show more
(mod_security) mod_security (id:240335) triggered by 103.224.152.116 (116.152.224.103-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 02:30:55.564434 2026] [security2:error] [pid 23291:tid 23291] [client 103.224.152.116:65496] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.224.152.116 (+1 hits since last alert)|ftiptondds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ftiptondds.com"] [uri "/xmlrpc.php"] [unique_id "aoafHzBMn4nTlj1hgTNdpQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-08-16 11:10:43
(1 week ago)
103.224.152.116 - - [16/Aug/2026:07:07:54 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress ...
show more
103.224.152.116 - - [16/Aug/2026:07:07:54 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
103.224.152.116 - - [16/Aug/2026:07:08:26 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
103.224.152.116 - - [16/Aug/2026:07:09:08 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
103.224.152.116 - - [16/Aug/2026:07:09:50 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
103.224.152.116 - - [16/Aug/2026:07:10:42 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-09 05:59:33
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.224.152.116 (116.152.224.103-in-addr.arpa-m ...
show more
(mod_security) mod_security (id:240335) triggered by 103.224.152.116 (116.152.224.103-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 01:59:26.276952 2026] [security2:error] [pid 90920:tid 90920] [client 103.224.152.116:51709] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.224.152.116 (+1 hits since last alert)|lspfest.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lspfest.com"] [uri "/xmlrpc.php"] [unique_id "angXPlr8cj-qF2GZxx3yUQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-28 08:00:03
(4 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-07-27 12:53:36
(4 weeks ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 05:35:19
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 103.224.152.116 (116.152.224.103-in-addr.arpa-m ...
show more
(mod_security) mod_security (id:240335) triggered by 103.224.152.116 (116.152.224.103-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:35:14.464396 2026] [security2:error] [pid 19691:tid 19891] [client 103.224.152.116:60601] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.224.152.116 (+1 hits since last alert)|munatseng.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "munatseng.org"] [uri "/xmlrpc.php"] [unique_id "ai-PEmP9MJEDhbHGivjb9QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 13:24:13
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 103.224.152.116 (116.152.224.103-in-addr.arpa-m ...
show more
(mod_security) mod_security (id:240335) triggered by 103.224.152.116 (116.152.224.103-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 09:24:07.855760 2026] [security2:error] [pid 29592:tid 29592] [client 103.224.152.116:64444] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.224.152.116 (+1 hits since last alert)|campos.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "campos.tv"] [uri "/xmlrpc.php"] [unique_id "afC0961DrK6eHIqgXZyLewAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-04-13 07:36:59
(4 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack