๐ณ๐ฑ
Site.eu
2026-07-22 14:24:46
(8 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ช๐ธ
masterguru
2026-07-22 06:37:54
(16 hours ago)
(xmlrpc) Failed xmlrpc access from 117.221.17.115 (IN/India/-): 5 in the last 3600 secs (0-122)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-21 12:00:35
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 117.221.17.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 117.221.17.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:00:21.305965 2026] [security2:error] [pid 863:tid 863] [client 117.221.17.115:63658] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.221.17.115 (+1 hits since last alert)|my-spec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "my-spec.com"] [uri "/xmlrpc.php"] [unique_id "al9fVQMTtwLTkDE6YwpiLgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-07-21 11:28:02
(1 day ago)
117.221.17.115 - - [21/Jul/2026:19:27:40 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack by ...
show more
117.221.17.115 - - [21/Jul/2026:19:27:40 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack by WordPress.com"
117.221.17.115 - - [21/Jul/2026:19:27:50 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack/13.0; WordPress/6.2; http://site51624226.com"
117.221.17.115 - - [21/Jul/2026:19:28:01 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5874 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-21 05:50:06
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 117.221.17.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 117.221.17.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 01:49:53.509046 2026] [security2:error] [pid 14090:tid 14090] [client 117.221.17.115:49432] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.221.17.115 (+1 hits since last alert)|lusineweb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lusineweb.com"] [uri "/xmlrpc.php"] [unique_id "al8IgQQ7WbCgFiCfiCEDSQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 12:26:36
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 117.221.17.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 117.221.17.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 08:26:25.268412 2026] [security2:error] [pid 23959:tid 23959] [client 117.221.17.115:62988] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.221.17.115 (+1 hits since last alert)|cloudex.link|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cloudex.link"] [uri "/xmlrpc.php"] [unique_id "al4T8WZ-dV7aPetYUPNxOgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 12:25:04
(2 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-07-20 06:31:25
(2 days ago)
[redacted] 117.221.17.115 - - [20/Jul/2026:08:30:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" " ...
show more
[redacted] 117.221.17.115 - - [20/Jul/2026:08:30:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
[redacted] 117.221.17.115 - - [20/Jul/2026:08:30:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 117.221.17.115 - - [20/Jul/2026:08:31:03 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
[redacted] 117.221.17.115 - - [20/Jul/2026:08:31:13 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
[redacted] 117.221.17.115 - - [20/Jul/2026:08:31:24 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-17 11:59:46
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 117.221.17.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 117.221.17.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 17 07:59:35.988992 2026] [security2:error] [pid 779346:tid 779346] [client 117.221.17.115:52206] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.221.17.115 (+1 hits since last alert)|cfmgroup.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cfmgroup.us"] [uri "/xmlrpc.php"] [unique_id "aloZJ8j0_OT17YiQ7biaSQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-17 05:50:47
(5 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-17 05:47:01
(5 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 12:12:04
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 117.221.17.115 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 117.221.17.115 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 08:11:49.671032 2026] [security2:error] [pid 2793142:tid 2793142] [client 117.221.17.115:63733] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.221.17.115 (+1 hits since last alert)|blaslandsporthorses.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "blaslandsporthorses.com"] [uri "/xmlrpc.php"] [unique_id "aljKhZEFKYY3t_fG4x9jlAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jsjdmediallc
2026-07-16 12:00:07
(6 days ago)
Auto-blocked: score 606 (threshold 10). Tier: HIGH. Hits: 120. Flags: xmlrpc, xmlrpc-burst, single-p ...
show more
Auto-blocked: score 606 (threshold 10). Tier: HIGH. Hits: 120. Flags: xmlrpc, xmlrpc-burst, single-path-flood. Paths: /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-07-16 07:39:27
(6 days ago)
(wordpress) Failed wordpress login from 117.221.17.115 (IN/India/-)
Brute-Force
๐ฑ๐ป
garmtech.com
2026-07-16 07:23:52
(6 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack