๐จ๐ฆ
zXero
2026-06-18 21:05:29
(4 days ago)
Fail2Ban automatic report - jail: no-wordpress
Brute-Force
SSH
DDoS Attack
๐ฌ๐ง
noise.agency
2026-06-14 23:16:45
(1 week ago)
(wordpress) Failed wordpress login from 103.96.105.237 (BD/Bangladesh/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-14 15:38:34
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 103.96.105.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.96.105.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 11:38:28.554202 2026] [security2:error] [pid 25655:tid 25655] [client 103.96.105.237:49573] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.96.105.237 (+1 hits since last alert)|prostar.industries|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "prostar.industries"] [uri "/xmlrpc.php"] [unique_id "ai7K9IvW6bjcL9fqij0cAwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
reznekcs
2026-06-14 13:22:20
(1 week ago)
F2B wordpress ban. Logs: 103.96.105.237 - - [14/Jun/2026:15:22:08 +0200] "POST /xmlrpc.php HTTP/1.1" ...
show more
F2B wordpress ban. Logs: 103.96.105.237 - - [14/Jun/2026:15:22:08 +0200] "POST /xmlrpc.php HTTP/1.1" 200 458 "-" "Jetpack/13.0; WordPress/6.4; http://site55537272.com"
103.96.105.237 - - [14/Jun/2026:15:22:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 458 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
show less
Brute-Force
Web App Attack
๐ฒ๐น
Malta
2026-06-12 20:12:00
(1 week ago)
103.96.105.237 - - [12/Jun/2026:22:12:00 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack by WordPress.co ...
show more
103.96.105.237 - - [12/Jun/2026:22:12:00 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack by WordPress.com"
show less
Hacking
Web App Attack
Anonymous
2026-06-12 05:39:26
(1 week ago)
103.96.105.237 - - [12/Jun/2026:07:38:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack by ...
show more
103.96.105.237 - - [12/Jun/2026:07:38:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack by WordPress.com"
103.96.105.237 - - [12/Jun/2026:07:38:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack by WordPress.com"
103.96.105.237 - - [12/Jun/2026:07:39:03 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack by WordPress.com"
103.96.105.237 - - [12/Jun/2026:07:39:13 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
103.96.105.237 - - [12/Jun/2026:07:39:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack/13.0; WordPress/6.4; http://site91604123.com"
...
show less
Brute-Force
Web App Attack
๐จ๐ฆ
zXero
2026-06-09 12:50:19
(1 week ago)
Fail2Ban automatic report - jail: no-wordpress
Brute-Force
SSH
DDoS Attack
๐ฉ๐ช
FeG Deutschland
2026-06-08 17:57:33
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 128
Exploited Host
Web App Attack
๐ฉ๐ช
Marc
2026-06-08 10:36:07
(2 weeks ago)
103.96.105.237 - - [08/Jun/2026:12:35:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3419 "-" "Jetpack by ...
show more
103.96.105.237 - - [08/Jun/2026:12:35:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3419 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)" 103.96.105.237 - - [08/Jun/2026:12:35:54 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3467 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)" 103.96.105.237 - - [08/Jun/2026:12:36:05 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3466 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 07:34:49
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.96.105.237 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 103.96.105.237 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 03:34:45.797596 2026] [security2:error] [pid 23400:tid 23400] [client 103.96.105.237:54660] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.96.105.237 (+1 hits since last alert)|caymancline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "caymancline.com"] [uri "/xmlrpc.php"] [unique_id "aiZwlWTv-TIXXwVIwORNbgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-06 20:04:03
(2 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-06-06 11:11:38
(2 weeks ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=listarxos.gr; logs=/var/log/httpd/domains/listarxos.gr.log; ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=listarxos.gr; logs=/var/log/httpd/domains/listarxos.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
soverin
2026-06-05 15:42:39
(2 weeks ago)
spam
Email Spam
Anonymous
2026-06-05 15:03:53
(2 weeks ago)
103.96.105.237 - - [05/Jun/2026:17:03:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12. ...
show more
103.96.105.237 - - [05/Jun/2026:17:03:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12.1; WordPress/6.2; http://site21473973.com"
103.96.105.237 - - [05/Jun/2026:17:03:34 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12.1; WordPress/6.2; http://site21473973.com"
103.96.105.237 - - [05/Jun/2026:17:03:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
103.96.105.237 - - [05/Jun/2026:17:03:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
103.96.105.237 - - [05/Jun/2026:17:03:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
...
show less
Brute-Force
Web App Attack
๐จ๐ฆ
zXero
2026-06-03 12:26:47
(2 weeks ago)
Fail2Ban automatic report - jail: no-wordpress
Brute-Force
SSH
DDoS Attack