๐ฉ๐ช
ger-stg-sifi1
2026-07-26 13:31:41
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 13:04:31
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.3.220.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.3.220.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 09:04:23.435815 2026] [security2:error] [pid 2834105:tid 2834105] [client 103.3.220.54:48924] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.3.220.54 (+1 hits since last alert)|usaenquirer.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "usaenquirer.com"] [uri "/xmlrpc.php"] [unique_id "amYF17zhMJcrVIMCQbvRUgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-07-25 12:33:25
(2 days ago)
(wordpress) Failed wordpress login from 103.3.220.54 (ID/Indonesia/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-25 10:57:45
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 103.3.220.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 103.3.220.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 06:57:39.539248 2026] [security2:error] [pid 1462960:tid 1462960] [client 103.3.220.54:42147] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||partnershipsbydesign.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "partnershipsbydesign.net"] [uri "/wp-json/wp/v2/users"] [unique_id "amSWo5a_kvmieE4O8FiKBAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-07-25 10:21:03
(2 days ago)
(wordpress) Failed wordpress login from 103.3.220.54 (ID/Indonesia/West Java/Bekasi/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-25 07:37:51
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 103.3.220.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.3.220.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 03:37:47.312959 2026] [security2:error] [pid 881868:tid 881868] [client 103.3.220.54:30778] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.3.220.54 (+1 hits since last alert)|oogeothermal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "oogeothermal.com"] [uri "/xmlrpc.php"] [unique_id "amRny7GoTlsMxTolMLUyiQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-25 04:38:48
(2 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 04:33:51
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 103.3.220.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.3.220.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 00:33:47.659203 2026] [security2:error] [pid 1095288:tid 1095288] [client 103.3.220.54:44137] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.3.220.54 (+1 hits since last alert)|comobarbershop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "comobarbershop.com"] [uri "/xmlrpc.php"] [unique_id "amQ8qwC1TWjxCyhCOTUbNQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-24 16:30:49
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-07-24 16:30:04
(2 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
netclix.gr
2026-07-24 12:43:28
(3 days ago)
(wordpress) Failed wordpress login from 103.3.220.54 (ID/Indonesia/-): (CF_ENABLE)
Brute-Force
๐ซ๐ท
dynamix
2026-07-22 13:25:56
(5 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
pscriptos
2026-07-22 11:25:46
(5 days ago)
{"ClientAddr":"103.3.220.54:47560","ClientHost":"103.3.220.54","ClientPort":"47560","ClientUsername" ...
show more
{"ClientAddr":"103.3.220.54:47560","ClientHost":"103.3.220.54","ClientPort":"47560","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":136480720,"OriginContentSize":418,"OriginDuration":132623347,"OriginStatus":403,"Overhead":3857373,"RequestAddr":"www.cleveradmin.de","RequestContentSize":711,"RequestCount":1734397,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-07-22T13:22:35.016263389+02:00","StartUTC":"2026-07-22T11:22:35.016263389Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-07-22T13:22:35+02:00"}
{"ClientAddr":"103.3.220.54:47560","ClientHost":"103.3.220.54","Clie
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 13:32:58
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 103.3.220.54 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 103.3.220.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 09:32:53.709421 2026] [security2:error] [pid 9318:tid 9318] [client 103.3.220.54:38911] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.3.220.54 (+1 hits since last alert)|agworldmissions.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "agworldmissions.org"] [uri "/xmlrpc.php"] [unique_id "al91BX_kge_7SThV5NMhhAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-21 12:50:12
(6 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack