๐บ๐ธ
graphics-muse.org
2026-05-19 12:06:56
(2 weeks ago)
Tue May 19 06:06:03.368776 2026103.93.105.154 - - [19/May/2026:06:06:02 -0600] "POST /xmlrpc.php HTT ...
show more
Tue May 19 06:06:03.368776 2026103.93.105.154 - - [19/May/2026:06:06:02 -0600] "POST /xmlrpc.php HTTP/1.1" 200 448
Tue May 19 06:06:03.368776 2026103.93.105.154 - - [19/May/2026:06:06:02 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3610 "-" "WordPress.com; https://wordpress.com"
Tue May 19 06:06:45.220939 2026103.93.105.154 - - [19/May/2026:06:06:45 -0600] "POST /xmlrpc.php HTTP/1.1" 200 448
Tue May 19 06:06:45.220939 2026103.93.105.154 - - [19/May/2026:06:06:45 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3609 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
Tue May 19 06:06:55.926350 2026103.93.105.154 - - [19/May/2026:06:06:55 -0600] "POST /xmlrpc.php HTTP/1.1" 200 448
Tue May 19 06:06:55.926350 2026103.93.105.154 - - [19/May/2026:06:06:55 -0600] "POST /xmlrpc.php HTTP/1.1" 200 3611 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-05-17 15:58:14
(2 weeks ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-17 05:54:17
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.93.105.154 (server.rainbowisp.in): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 103.93.105.154 (server.rainbowisp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 01:54:09.171338 2026] [security2:error] [pid 9071:tid 9185] [client 103.93.105.154:61301] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.93.105.154 (+1 hits since last alert)|aafm.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aafm.us"] [uri "/xmlrpc.php"] [unique_id "aglYAekVTPWQvVbWOcvREAAAAcA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-05-12 06:21:41
(3 weeks ago)
Wordpress Vunerability attack
Web App Attack
๐ฌ๐ง
noise.agency
2026-05-10 08:35:56
(3 weeks ago)
(wordpress) Failed wordpress login from 103.93.105.154 (IN/India/server.rainbowisp.in)
Brute-Force
๐ฑ๐ป
garmtech.com
2026-05-07 11:48:25
(3 weeks ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-05-03 04:48:08
(1 month ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-05-01 22:26:39
(1 month ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-01 14:32:35
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.93.105.154 (server.rainbowisp.in): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 103.93.105.154 (server.rainbowisp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 10:32:26.931881 2026] [security2:error] [pid 22518:tid 22541] [client 103.93.105.154:62820] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.93.105.154 (+1 hits since last alert)|georgementz.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "georgementz.org"] [uri "/xmlrpc.php"] [unique_id "afS5esTtgvYzO8s1ENlB4AAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-04-30 22:25:43
(1 month ago)
Brute-Force
Web App Attack
Anonymous
2026-04-17 06:31:05
(1 month ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-17 03:43:33
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 103.93.105.154 (server.rainbowisp.in): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 103.93.105.154 (server.rainbowisp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 23:43:27.485126 2026] [security2:error] [pid 3554698:tid 3554698] [client 103.93.105.154:53690] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.93.105.154 (+1 hits since last alert)|comicpreservation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "comicpreservation.com"] [uri "/xmlrpc.php"] [unique_id "aeGsXzS5YakN9DbqMrbxMAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-30 14:40:43
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.93.105.154 (server.rainbowisp.in): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 103.93.105.154 (server.rainbowisp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 10:40:37.273153 2026] [security2:error] [pid 9474:tid 9483] [client 103.93.105.154:51620] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aclarityforensics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aclarityforensics.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acqLZTpQC7YgIxiO9xbq7gAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
0tsystems
2026-03-30 04:15:27
(2 months ago)
Automated scan detected on 0t.systems: /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-29 09:01:36
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.93.105.154 (server.rainbowisp.in): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 103.93.105.154 (server.rainbowisp.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 29 05:01:28.919384 2026] [security2:error] [pid 9172:tid 9172] [client 103.93.105.154:62216] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||desertmiragetowing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "desertmiragetowing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acjqaKgM4TnGdxzXomFVngAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack