๐บ๐ธ
TPI-Abuse
2026-07-21 12:52:22
(2 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:52:17.339274 2026] [security2:error] [pid 10658:tid 10658] [client 106.222.248.144:24898] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.222.248.144 (+1 hits since last alert)|rentkase.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rentkase.com"] [uri "/xmlrpc.php"] [unique_id "al9rgaop0L24FkJBYEFaIgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 12:20:06
(2 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 11:34:27
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:34:20.370017 2026] [security2:error] [pid 17895:tid 17895] [client 106.222.248.144:13054] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.222.248.144 (+1 hits since last alert)|mkdesignndetailing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mkdesignndetailing.com"] [uri "/xmlrpc.php"] [unique_id "al9ZPA07MGTZwYnuqNSTfQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 10:22:01
(4 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 06:21:55.911215 2026] [security2:error] [pid 9597:tid 9597] [client 106.222.248.144:3349] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.222.248.144 (+1 hits since last alert)|lightupaustralia.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lightupaustralia.org"] [uri "/xmlrpc.php"] [unique_id "al9IQxEIkRd4n8bor0SURgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-21 09:47:10
(5 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-21 08:50:36
(6 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 08:46:23
(6 hours ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ซ๐ฎ
KnightIndustries
2026-07-21 07:14:23
(7 hours ago)
2026-07-21T09:14:00.845428+02:00 milkyway wordpress(fawcettcomputerservices.com)[23804]: XML-RPC aut ...
show more
2026-07-21T09:14:00.845428+02:00 milkyway wordpress(fawcettcomputerservices.com)[23804]: XML-RPC authentication failure for joshua from 106.222.248.144
2026-07-21T09:14:11.695332+02:00 milkyway wordpress(fawcettcomputerservices.com)[63952]: XML-RPC authentication failure for joshua from 106.222.248.144
2026-07-21T09:14:22.620015+02:00 milkyway wordpress(fawcettcomputerservices.com)[57985]: XML-RPC authentication failure for joshua from 106.222.248.144
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 06:15:33
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 02:15:29.464247 2026] [security2:error] [pid 2517193:tid 2517193] [client 106.222.248.144:26862] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.222.248.144 (+1 hits since last alert)|kaldaragroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kaldaragroup.com"] [uri "/xmlrpc.php"] [unique_id "al8OgYT6BLysPjGIpdrZGAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-07-21 05:41:35
(9 hours ago)
babystudio4d.com 106.222.248.144 - - [21/Jul/2026:00:41:14 -0500] "POST /xmlrpc.php HTTP/1.1" 200 41 ...
show more
babystudio4d.com 106.222.248.144 - - [21/Jul/2026:00:41:14 -0500] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack/12.0; WordPress/6.4; http://site48752786.com" -
babystudio4d.com 106.222.248.144 - - [21/Jul/2026:00:41:24 -0500] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)" -
babystudio4d.com 106.222.248.144 - - [21/Jul/2026:00:41:34 -0500] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "WordPress.com; https://wordpress.com" -
...
show less
Hacking
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-21 04:45:12
(10 hours ago)
106.222.248.144 - - [21/Jul/2026:00:43:22 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress ...
show more
106.222.248.144 - - [21/Jul/2026:00:43:22 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
106.222.248.144 - - [21/Jul/2026:00:44:26 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
106.222.248.144 - - [21/Jul/2026:00:44:37 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
106.222.248.144 - - [21/Jul/2026:00:44:59 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
106.222.248.144 - - [21/Jul/2026:00:45:10 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 14:48:48
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 10:48:41.815109 2026] [security2:error] [pid 23738:tid 23738] [client 106.222.248.144:3644] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.222.248.144 (+1 hits since last alert)|lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lysedzija.com"] [uri "/xmlrpc.php"] [unique_id "al41Sb3asGrJKyXtAzdA4wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-20 13:42:31
(1 day ago)
106.222.248.144 - - [20/Jul/2026:09:39:51 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress ...
show more
106.222.248.144 - - [20/Jul/2026:09:39:51 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress.com; https://wordpress.com"
106.222.248.144 - - [20/Jul/2026:09:40:34 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress.com; https://wordpress.com"
106.222.248.144 - - [20/Jul/2026:09:41:37 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress.com; https://wordpress.com"
106.222.248.144 - - [20/Jul/2026:09:42:19 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress.com; https://wordpress.com"
106.222.248.144 - - [20/Jul/2026:09:42:30 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5263 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 10:28:01
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 106.222.248.144 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 06:27:55.332492 2026] [security2:error] [pid 20811:tid 20811] [client 106.222.248.144:31549] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.222.248.144 (+1 hits since last alert)|josephshv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "josephshv.com"] [uri "/xmlrpc.php"] [unique_id "al34KypWnc_6diJNR-IiJwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-20 10:06:49
(1 day ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack