Anonymous
2026-08-23 07:06:50
(2 days ago)
[redacted] 106.219.132.124 - - [23/Aug/2026:09:06:07 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 106.219.132.124 - - [23/Aug/2026:09:06:07 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
[redacted] 106.219.132.124 - - [23/Aug/2026:09:06:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
[redacted] 106.219.132.124 - - [23/Aug/2026:09:06:28 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 106.219.132.124 - - [23/Aug/2026:09:06:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 106.219.132.124 - - [23/Aug/2026:09:06:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-23 02:31:32
(2 days ago)
(wordpress) Failed wordpress login from 106.219.132.124 (IN/India/West Bengal/Kolkata/-)
Brute-Force
Anonymous
2026-08-22 22:14:03
(2 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 20:13:27
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 16:13:23.573930 2026] [security2:error] [pid 23087:tid 23087] [client 106.219.132.124:18475] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.132.124 (+1 hits since last alert)|sfgardening.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sfgardening.com"] [uri "/xmlrpc.php"] [unique_id "aooC4zBIjKmKF3fPTXieUQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 16:45:57
(2 days ago)
POST /xmlrpc.php HTTP/1.1
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-22 15:47:55
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 11:47:49.864163 2026] [security2:error] [pid 3941:tid 3941] [client 106.219.132.124:24279] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.132.124 (+1 hits since last alert)|monmouthcountydanceclasses.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "monmouthcountydanceclasses.com"] [uri "/xmlrpc.php"] [unique_id "aonEpbWFiEN9QhJ55gSYSwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 15:23:29
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 11:23:22.362520 2026] [security2:error] [pid 25986:tid 25986] [client 106.219.132.124:6466] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.132.124 (+1 hits since last alert)|otraes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "otraes.com"] [uri "/xmlrpc.php"] [unique_id "aom-6qWxbEWX-QHWsbAFhQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 05:13:12
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 01:13:08.342321 2026] [security2:error] [pid 12749:tid 12776] [client 106.219.132.124:29261] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.132.124 (+1 hits since last alert)|coasterdvdsonline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "coasterdvdsonline.com"] [uri "/xmlrpc.php"] [unique_id "aokv5IrKINJTl_Gt4apFEwAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-22 03:37:51
(3 days ago)
Wordpress brute force attempt
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 02:07:10
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 22:07:05.616470 2026] [security2:error] [pid 17714:tid 17714] [client 106.219.132.124:11070] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.132.124 (+1 hits since last alert)|peterndudar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "peterndudar.com"] [uri "/xmlrpc.php"] [unique_id "aokESU4wWkiwI6VhlbDETgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-08-22 00:39:08
(3 days ago)
1.211 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
Anonymous
2026-08-21 16:40:25
(3 days ago)
(wordpress) Failed wordpress login from 106.219.132.124 (IN/India/West Bengal/Kolkata/-/[redacted])
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-21 11:46:47
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.219.132.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 07:46:39.616698 2026] [security2:error] [pid 3792:tid 3792] [client 106.219.132.124:33134] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.219.132.124 (+1 hits since last alert)|virtualmediamasters.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "virtualmediamasters.net"] [uri "/xmlrpc.php"] [unique_id "aog6nym5jPzy6pXDosX3jAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-21 05:55:49
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack