Anonymous
2026-06-16 02:09:21
(16 minutes ago)
[redacted] 109.243.148.153 - - [16/Jun/2026:04:08:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 109.243.148.153 - - [16/Jun/2026:04:08:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 109.243.148.153 - - [16/Jun/2026:04:08:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.3; http://site13818909.com"
[redacted] 109.243.148.153 - - [16/Jun/2026:04:09:02 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
[redacted] 109.243.148.153 - - [16/Jun/2026:04:09:09 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.3; http://site24962292.com"
[redacted] 109.243.148.153 - - [16/Jun/2026:04:09:20 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 01:55:20
(30 minutes ago)
(mod_security) mod_security (id:240335) triggered by 109.243.148.153 (user-109-243-148-153.play-inte ...
show more
(mod_security) mod_security (id:240335) triggered by 109.243.148.153 (user-109-243-148-153.play-internet.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 21:55:12.431114 2026] [security2:error] [pid 25262:tid 25262] [client 109.243.148.153:7197] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 109.243.148.153 (+1 hits since last alert)|schlegelcreative.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "schlegelcreative.com"] [uri "/xmlrpc.php"] [unique_id "ajCtAGJY7mtzXJRfFPP5HQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
bigwavedave
2026-06-15 23:05:30
(3 hours ago)
Wordpress Attack
Web App Attack
๐ฉ๐ช
rh24
2026-06-15 23:04:12
(3 hours ago)
(xmlrpc_405) XMLRPC-Bot 405 109.243.148.153 (PL/Poland/user-109-243-148-153.play-internet.pl)
Hacking
๐ฉ๐ช
LRob.fr
2026-06-15 22:15:07
(4 hours ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 03:15:29
(23 hours ago)
(mod_security) mod_security (id:240335) triggered by 109.243.148.153 (user-109-243-148-153.play-inte ...
show more
(mod_security) mod_security (id:240335) triggered by 109.243.148.153 (user-109-243-148-153.play-internet.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:15:26.210382 2026] [security2:error] [pid 19378:tid 19378] [client 109.243.148.153:18087] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 109.243.148.153 (+1 hits since last alert)|univey.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "univey.com"] [uri "/xmlrpc.php"] [unique_id "ai9uTqa2BJ_HQ6eQEPuzKAAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:32:27
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 109.243.148.153 (user-109-243-148-153.play-inte ...
show more
(mod_security) mod_security (id:240335) triggered by 109.243.148.153 (user-109-243-148-153.play-internet.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:32:19.746640 2026] [security2:error] [pid 6534:tid 6534] [client 109.243.148.153:18040] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 109.243.148.153 (+1 hits since last alert)|cienmalos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cienmalos.com"] [uri "/xmlrpc.php"] [unique_id "ai9WI7xXfZkT_vIob1tvAgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-15 00:40:53
(1 day ago)
3.441 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ซ๐ท
dynamix
2026-06-15 00:28:40
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-06-14 20:24:10
(1 day ago)
Attac
Brute-Force
๐ธ๐ช
vaia.cloud
2026-06-14 18:04:11
(1 day ago)
trying wp-login.php/xmlrpc.php 33 times in 1 minutes
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 18:00:57
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 109.243.148.153 (user-109-243-148-153.play-inte ...
show more
(mod_security) mod_security (id:240335) triggered by 109.243.148.153 (user-109-243-148-153.play-internet.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 14:00:51.546190 2026] [security2:error] [pid 11109:tid 11109] [client 109.243.148.153:26085] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 109.243.148.153 (+1 hits since last alert)|cajunpicasso.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cajunpicasso.com"] [uri "/xmlrpc.php"] [unique_id "ai7sU80tlzgGOhiRHHrZsQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack