๐ซ๐ท
applemooz
2026-07-23 21:14:39
(20 hours ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-23 18:32:27
(23 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 17:58:26
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 110.39.161.226 (WGPON-39161-226.wateen.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 110.39.161.226 (WGPON-39161-226.wateen.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 13:58:18.929774 2026] [security2:error] [pid 1418455:tid 1418455] [client 110.39.161.226:55743] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 110.39.161.226 (+1 hits since last alert)|lightupaustralia.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lightupaustralia.org"] [uri "/xmlrpc.php"] [unique_id "amEEuryERiZ-s7KZaHf6gQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-22 14:36:15
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-22 13:05:15
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 110.39.161.226 (WGPON-39161-226.wateen.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 110.39.161.226 (WGPON-39161-226.wateen.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 09:05:07.128641 2026] [security2:error] [pid 781486:tid 781486] [client 110.39.161.226:59068] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 110.39.161.226 (+1 hits since last alert)|d-sinema.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "d-sinema.com"] [uri "/xmlrpc.php"] [unique_id "amDAA0s4RW7Ll7aajDl9cAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-21 21:56:23
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
Lunix
2026-07-21 21:00:40
(2 days ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 19:20:54
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 110.39.161.226 (WGPON-39161-226.wateen.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 110.39.161.226 (WGPON-39161-226.wateen.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 15:20:48.774892 2026] [security2:error] [pid 6399:tid 6418] [client 110.39.161.226:57596] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 110.39.161.226 (+1 hits since last alert)|visionforandfromchildren.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "visionforandfromchildren.org"] [uri "/xmlrpc.php"] [unique_id "al_GkP2894PQmUySOMI53gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 17:45:31
(3 days ago)
[redacted] 110.39.161.226 - - [21/Jul/2026:19:44:45 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 110.39.161.226 - - [21/Jul/2026:19:44:45 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.2; http://site58332427.com"
[redacted] 110.39.161.226 - - [21/Jul/2026:19:44:56 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.3; http://site27832369.com"
[redacted] 110.39.161.226 - - [21/Jul/2026:19:45:07 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 110.39.161.226 - - [21/Jul/2026:19:45:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.1; http://site63889268.com"
[redacted] 110.39.161.226 - - [21/Jul/2026:19:45:28 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-21 16:53:32
(3 days ago)
110.39.161.226 - - [21/Jul/2026:12:51:33 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress. ...
show more
110.39.161.226 - - [21/Jul/2026:12:51:33 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
110.39.161.226 - - [21/Jul/2026:12:51:54 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
110.39.161.226 - - [21/Jul/2026:12:52:27 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
110.39.161.226 - - [21/Jul/2026:12:53:20 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
110.39.161.226 - - [21/Jul/2026:12:53:31 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
Anonymous
2026-07-20 18:57:11
(3 days ago)
[osotir.org] httpd-xmlrpc-post: sites=www.drasimas.gr; logs=/var/log/httpd/domains/drasimas.gr.log; ...
show more
[osotir.org] httpd-xmlrpc-post: sites=www.drasimas.gr; logs=/var/log/httpd/domains/drasimas.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ซ๐ฎ
KnightIndustries
2026-07-20 15:48:38
(4 days ago)
2026-07-20T17:48:15.775906+02:00 milkyway wordpress(learncryptography.pw)[4167637]: XML-RPC authenti ...
show more
2026-07-20T17:48:15.775906+02:00 milkyway wordpress(learncryptography.pw)[4167637]: XML-RPC authentication failure for macminty from 110.39.161.226
2026-07-20T17:48:26.067175+02:00 milkyway wordpress(learncryptography.pw)[4168137]: XML-RPC authentication failure for macminty from 110.39.161.226
2026-07-20T17:48:37.030183+02:00 milkyway wordpress(learncryptography.pw)[4178663]: XML-RPC authentication failure for macminty from 110.39.161.226
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 13:17:38
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 110.39.161.226 (WGPON-39161-226.wateen.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 110.39.161.226 (WGPON-39161-226.wateen.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 09:17:29.977454 2026] [security2:error] [pid 6474:tid 6474] [client 110.39.161.226:63611] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 110.39.161.226 (+1 hits since last alert)|mchen-arch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mchen-arch.com"] [uri "/xmlrpc.php"] [unique_id "al4f6aQE6Y0nQHXu_O_30wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-17 21:33:56
(6 days ago)
cloudlinux2 fail2ban: 2026-07-17 23:28:53,742 fail2ban.filter [1598]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-17 23:28:53,742 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 110.39.161.226 - 2026-07-17 23:28:53cloudlinux2 fail2ban: 2026-07-17 23:28:53,738 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 104.234.53.58 - 2026-07-17 23:28:53cloudlinux2 fail2ban: 2026-07-17 23:29:45,016 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 173.239.224.38 - 2026-07-17 23:29:44cloudlinux2 fail2ban: 2026-07-17 23:31:24,454 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 110.39.161.226 - 2026-07-17 23:31:24cloudlinux2 fail2ban: 2026-07-17 23:32:06,657 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 216.73.161.228 - 2026-07-17 23:32:06cloudlinux2 fail2ban: 2026-07-17 23:32:09,393 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 110.39.161.226 - 2026-07-17 23:32:09cloudlinux2 fail2ban: 2026-07-17 23:32:10,960 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 216.73.161.228 - 2026-07-17 23:32
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 14:42:33
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 110.39.161.226 (WGPON-39161-226.wateen.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 110.39.161.226 (WGPON-39161-226.wateen.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 10:42:29.021819 2026] [security2:error] [pid 18490:tid 18490] [client 110.39.161.226:56477] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 110.39.161.226 (+1 hits since last alert)|newmooncafe.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "newmooncafe.com"] [uri "/xmlrpc.php"] [unique_id "alo_VRlZpUWbouEoizdV9wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack