๐ณ๐ฑ
Site.eu
2026-07-24 00:48:26
(3 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
bigwavedave
2026-07-23 23:15:50
(3 days ago)
Wordpress Attack
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-23 23:15:03
(3 days ago)
(wordpress) Failed wordpress login from 103.241.224.239 (IN/India/-)
Brute-Force
Anonymous
2026-07-23 17:36:54
(3 days ago)
[redacted] 103.241.224.239 - - [23/Jul/2026:19:36:10 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 103.241.224.239 - - [23/Jul/2026:19:36:10 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 103.241.224.239 - - [23/Jul/2026:19:36:20 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 103.241.224.239 - - [23/Jul/2026:19:36:31 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.4; http://site71757397.com"
[redacted] 103.241.224.239 - - [23/Jul/2026:19:36:42 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 103.241.224.239 - - [23/Jul/2026:19:36:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐ช๐ธ
alferez
2026-07-23 12:05:22
(4 days ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 11:46:57
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 103.241.224.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.241.224.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 07:46:51.491914 2026] [security2:error] [pid 2558224:tid 2558224] [client 103.241.224.239:41925] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.241.224.239 (+1 hits since last alert)|eye7graphics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eye7graphics.com"] [uri "/xmlrpc.php"] [unique_id "amH_K5XEQ3sYHPHuka1K3wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-23 06:57:07
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 05:15:17
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 103.241.224.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.241.224.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 01:15:11.504625 2026] [security2:error] [pid 4135171:tid 4135171] [client 103.241.224.239:42203] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.241.224.239 (+1 hits since last alert)|graymatterofdc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "graymatterofdc.com"] [uri "/xmlrpc.php"] [unique_id "amGjXwekT0uccUJXK712EgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 03:44:00
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 103.241.224.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.241.224.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 23:43:55.969708 2026] [security2:error] [pid 3086205:tid 3086205] [client 103.241.224.239:42485] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.241.224.239 (+1 hits since last alert)|cienmalos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cienmalos.com"] [uri "/xmlrpc.php"] [unique_id "amGN--WHw7uDiEHW2Zx5KQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-23 03:42:06
(4 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-07-23 03:25:52
(4 days ago)
103.241.224.239 - [23/Jul/2026:06:25:42 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "WordPress.co ...
show more
103.241.224.239 - [23/Jul/2026:06:25:42 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "WordPress.com; https://wordpress.com" "-"
103.241.224.239 - [23/Jul/2026:06:25:51 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "Jetpack/13.0; WordPress/6.4; http://site64995082.com" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-07-23 03:10:29
(4 days ago)
103.241.224.239 - [23/Jul/2026:06:10:21 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "Jetpack by W ...
show more
103.241.224.239 - [23/Jul/2026:06:10:21 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "Jetpack by WordPress.com" "-"
103.241.224.239 - [23/Jul/2026:06:10:29 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "Jetpack by WordPress.com" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-23 01:58:13
(4 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-23 01:55:13
(4 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 23:37:38
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 103.241.224.239 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 103.241.224.239 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 19:37:32.468417 2026] [security2:error] [pid 3580004:tid 3580004] [client 103.241.224.239:42246] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.241.224.239 (+1 hits since last alert)|maffiniandbearce.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "maffiniandbearce.com"] [uri "/xmlrpc.php"] [unique_id "amFUPBoXFtWtX4DUEYJ4qQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack