๐ณ๐ฑ
maxxsense
2026-10-07 12:46:12
(1 day ago)
(wordpress) Failed wordpress login from 115.242.55.148 (IN/India/-)
Brute-Force
๐ฉ๐ช
LRob
2026-10-06 10:30:15
(2 days ago)
WordPress login brute force | path: /xmlrpc.php | ua: Jetpack by WordPress.com, Jetpack/13.0; WordPr ...
show more
WordPress login brute force | path: /xmlrpc.php | ua: Jetpack by WordPress.com, Jetpack/13.0; WordPress/6.1; http://site44212523.com
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-05 04:58:30
(3 days ago)
[ti-22al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpr ...
show more
[ti-22al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpress. Example: 115.242.55.148 - - [05/Oct/2026:06:57:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 6018 "-" "WordPress.com; https://wordpress.com"
115.242.55.148 - - [05/Oct/2026:06:57:51 +0200] "POST /xmlrpc.php HTTP/1.1" 405 6018 "-" "Jetpack/12.0; WordPress/6.2; http://site73712839.com"
115.242.55.148 - - [05/Oct/2026:06:58:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 6018 "-" "Jetpack/12.0; WordPress/6.1; http://site30737931.com"
115.242.55.148 - - [05/Oct/2026:06:58:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 6018 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-22 09:50:34
(2 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-09-22 09:32:54
(2 weeks ago)
(wordpress) Failed wordpress login from 115.242.55.148 (IN/India/Maharashtra/Mumbai/-/[redacted])
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-20 07:17:03
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 115.242.55.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 115.242.55.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 03:16:54.306206 2026] [security2:error] [pid 2829368:tid 2829368] [client 115.242.55.148:52859] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 115.242.55.148 (+1 hits since last alert)|spacebooger.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "spacebooger.com"] [uri "/xmlrpc.php"] [unique_id "aeXS5iFfJCW1ZatwXnspDAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-20 06:25:25
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 115.242.55.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 115.242.55.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 02:25:17.926008 2026] [security2:error] [pid 4016197:tid 4016197] [client 115.242.55.148:279] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 115.242.55.148 (+1 hits since last alert)|midwayisland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "midwayisland.com"] [uri "/xmlrpc.php"] [unique_id "aeXGzQ7H05WVg9ovy9p2QwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-18 05:05:41
(5 months ago)
Fail2ban filtered
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-16 10:55:05
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 115.242.55.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 115.242.55.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 06:54:57.111520 2026] [security2:error] [pid 386568:tid 386568] [client 115.242.55.148:30892] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 115.242.55.148 (+1 hits since last alert)|ssion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ssion.com"] [uri "/xmlrpc.php"] [unique_id "aeDAAfFXSCcIoVehdMK0FQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-15 07:42:37
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 115.242.55.148 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 115.242.55.148 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 03:42:29.352059 2026] [security2:error] [pid 885273:tid 885273] [client 115.242.55.148:21090] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 115.242.55.148 (+1 hits since last alert)|97films.media|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "97films.media"] [uri "/xmlrpc.php"] [unique_id "ad9BZTTUH9tPtRPc5FBm-QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-13 11:35:04
(5 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
WeekendWeb
2026-04-13 05:40:03
(5 months ago)
Wordpress Vunerability attack
Web App Attack
๐ฉ๐ช
LRob
2026-04-08 05:45:15
(6 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-04-08 04:18:32
(6 months ago)
[WedApr0806:18:27.0496522026][security2:error][pid1841731:tid1841749][client115.242.55.148:0]ModSecu ...
show more
[WedApr0806:18:27.0496522026][security2:error][pid1841731:tid1841749][client115.242.55.148:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"112\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"alessandrolucchini.ch\"][uri\"/xmlrpc.php\"][unique_id\"adXXE5UEfdULK2tTFN5V_wAAAIw\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-03-05 05:06:03
(7 months ago)
Trying to access config files
Web App Attack