๐ง๐ช
madeit
2026-09-15 12:50:17
(16 hours ago)
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-15 10:51:36
(18 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-15 10:45:07
(18 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-15 10:26:40
(18 hours ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ธ๐ฌ
abuseipreport.darajati
2026-09-15 07:49:00
(21 hours ago)
106.213.82.236 - - [2026-09-15T15:48:22+08:00] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "WordPress.co ...
show more
106.213.82.236 - - [2026-09-15T15:48:22+08:00] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "WordPress.com; https://wordpress.com"
106.213.82.236 - - [2026-09-15T15:48:27+08:00] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "WordPress.com; https://wordpress.com"
106.213.82.236 - - [2026-09-15T15:48:38+08:00] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com"
106.213.82.236 - - [2026-09-15T15:48:48+08:00] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack/12.0; WordPress/6.1; http://site53307276.com"
106.213.82.236 - - [2026-09-15T15:48:59+08:00] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
...
show less
Web App Attack
Anonymous
2026-07-14 06:27:05
(2 months ago)
Bad Web Bot
Web App Attack
Anonymous
2026-07-14 03:13:02
(2 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ซ๐ฎ
YF
2026-07-10 10:00:24
(2 months ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
jsjdmediallc
2026-07-10 08:40:05
(2 months ago)
Auto-blocked: score 336 (threshold 10). Tier: HIGH. Hits: 66. Flags: xmlrpc, xmlrpc-burst, single-pa ...
show more
Auto-blocked: score 336 (threshold 10). Tier: HIGH. Hits: 66. Flags: xmlrpc, xmlrpc-burst, single-path-flood. Paths: /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-10 08:16:23
(2 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
IN/India/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 07:47:05
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 106.213.82.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.213.82.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 03:47:00.232227 2026] [security2:error] [pid 6418:tid 6418] [client 106.213.82.236:18759] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.213.82.236 (+1 hits since last alert)|crep-psych.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "crep-psych.org"] [uri "/xmlrpc.php"] [unique_id "alCjdGstfBcGtuYO7W0gFQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 06:04:34
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 106.213.82.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.213.82.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 02:04:28.941149 2026] [security2:error] [pid 32312:tid 32312] [client 106.213.82.236:3388] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.213.82.236 (+1 hits since last alert)|lambert-heating-and-air.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lambert-heating-and-air.com"] [uri "/xmlrpc.php"] [unique_id "alCLbN76gE5xlbk82lA_tgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-09 06:42:32
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 106.213.82.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.213.82.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 09 02:42:28.714281 2026] [security2:error] [pid 13553:tid 13553] [client 106.213.82.236:4467] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.213.82.236 (+1 hits since last alert)|jazziiafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jazziiafoundation.org"] [uri "/xmlrpc.php"] [unique_id "ak9C1PpECZYb9tPFVXbmqwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
Global Cyber Police
2025-07-27 17:56:43
(1 year ago)
Malicious bot activity detected: Hitting honeypot page (200 OK with 258/259 bytes sent).
Port Scan
Brute-Force
Web App Attack
๐ฌ๐ง
SilverZippo
2024-09-21 14:29:47
(1 year ago)
Web App Attack
Web App Attack