๐ซ๐ท
masterguru
2026-06-10 04:45:53
(1 week ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ซ๐ท
Yepngo
2026-06-10 03:13:50
(1 week ago)
116.193.137.209 - - [10/Jun/2026:05:13:39 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "Jetpack by ...
show more
116.193.137.209 - - [10/Jun/2026:05:13:39 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
116.193.137.209 - - [10/Jun/2026:05:13:49 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-09 14:23:04
(1 week ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
xmission.com
2026-06-09 14:22:06
(1 week ago)
116.193.137.209 - - [09/Jun/2026:08:22:05 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by ...
show more
116.193.137.209 - - [09/Jun/2026:08:22:05 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 13:54:51
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 116.193.137.209 (node-116-193-137-209.allianceb ...
show more
(mod_security) mod_security (id:240335) triggered by 116.193.137.209 (node-116-193-137-209.alliancebroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:54:47.477689 2026] [security2:error] [pid 13225:tid 13225] [client 116.193.137.209:62912] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 116.193.137.209 (+1 hits since last alert)|bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bamedica.com"] [uri "/xmlrpc.php"] [unique_id "aigbJxiyH5j3ue3PazkrZgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-06-09 13:22:32
(1 week ago)
(wordpress) Failed wordpress login from 116.193.137.209 (IN/India/West Bengal/Kolkata/node-116-193-1 ...
show more
(wordpress) Failed wordpress login from 116.193.137.209 (IN/India/West Bengal/Kolkata/node-116-193-137-209.alliancebroadband.in)
show less
Brute-Force
๐ฆ๐บ
screwlooseit.com.au
2026-06-09 12:20:36
(1 week ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
IN/India/node-116-193-137-209.alliancebroadband.in
Web App Attack
Anonymous
2026-06-09 07:48:10
(1 week ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 14:50:23
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 116.193.137.209 (node-116-193-137-209.allianceb ...
show more
(mod_security) mod_security (id:240335) triggered by 116.193.137.209 (node-116-193-137-209.alliancebroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 10:50:19.933663 2026] [security2:error] [pid 2327:tid 2327] [client 116.193.137.209:55639] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 116.193.137.209 (+1 hits since last alert)|cemesur-vision21.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cemesur-vision21.com"] [uri "/xmlrpc.php"] [unique_id "aibWq9Q_fU3HFjRjr1I6KwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-06-08 14:32:02
(2 weeks ago)
116.193.137.209 - [08/Jun/2026:17:31:52 +0300] "POST /xmlrpc.php HTTP/1.1" 200 428 "-" "Jetpack by W ...
show more
116.193.137.209 - [08/Jun/2026:17:31:52 +0300] "POST /xmlrpc.php HTTP/1.1" 200 428 "-" "Jetpack by WordPress.com" "-"
116.193.137.209 - [08/Jun/2026:17:32:02 +0300] "POST /xmlrpc.php HTTP/1.1" 200 428 "-" "Jetpack/12.5; WordPress/6.2; http://site77242372.com" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-06-08 14:16:44
(2 weeks ago)
116.193.137.209 - [08/Jun/2026:17:16:34 +0300] "POST /xmlrpc.php HTTP/1.1" 200 428 "-" "Jetpack by W ...
show more
116.193.137.209 - [08/Jun/2026:17:16:34 +0300] "POST /xmlrpc.php HTTP/1.1" 200 428 "-" "Jetpack by WordPress.com" "-"
116.193.137.209 - [08/Jun/2026:17:16:43 +0300] "POST /xmlrpc.php HTTP/1.1" 200 428 "-" "Jetpack by WordPress.com" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 11:01:55
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 116.193.137.209 (node-116-193-137-209.allianceb ...
show more
(mod_security) mod_security (id:240335) triggered by 116.193.137.209 (node-116-193-137-209.alliancebroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 07:01:49.253268 2026] [security2:error] [pid 14814:tid 14814] [client 116.193.137.209:60956] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 116.193.137.209 (+1 hits since last alert)|femalegamblers.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "femalegamblers.org"] [uri "/xmlrpc.php"] [unique_id "aiahHTw6mwim_6F_v9GojAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 10:58:38
(2 weeks ago)
116.193.137.209 - - [08/Jun/2026:12:58:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress. ...
show more
116.193.137.209 - - [08/Jun/2026:12:58:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.com; https://wordpress.com"
116.193.137.209 - - [08/Jun/2026:12:58:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com; https://wordpress.com"
116.193.137.209 - - [08/Jun/2026:12:58:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
116.193.137.209 - - [08/Jun/2026:12:58:27 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
116.193.137.209 - - [08/Jun/2026:12:58:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 07:23:05
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 116.193.137.209 (node-116-193-137-209.allianceb ...
show more
(mod_security) mod_security (id:240335) triggered by 116.193.137.209 (node-116-193-137-209.alliancebroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 03:22:59.863794 2026] [security2:error] [pid 24846:tid 24846] [client 116.193.137.209:64566] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 116.193.137.209 (+1 hits since last alert)|univey.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "univey.com"] [uri "/xmlrpc.php"] [unique_id "aiZt02QiY5WuQvCPvDJEoQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 05:20:15
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 116.193.137.209 (node-116-193-137-209.allianceb ...
show more
(mod_security) mod_security (id:240335) triggered by 116.193.137.209 (node-116-193-137-209.alliancebroadband.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 01:20:08.824346 2026] [security2:error] [pid 5762:tid 5762] [client 116.193.137.209:53822] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 116.193.137.209 (+1 hits since last alert)|nearfieldchrist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nearfieldchrist.com"] [uri "/xmlrpc.php"] [unique_id "aiZRCCY6UIVyuu_xD7Ec_wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack