Anonymous
2026-07-29 08:27:12
(1 hour ago)
[redacted] 117.4.83.59 - - [29/Jul/2026:10:26:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Wor ...
show more
[redacted] 117.4.83.59 - - [29/Jul/2026:10:26:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 117.4.83.59 - - [29/Jul/2026:10:26:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 117.4.83.59 - - [29/Jul/2026:10:26:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 117.4.83.59 - - [29/Jul/2026:10:27:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 117.4.83.59 - - [29/Jul/2026:10:27:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-07-29 07:00:00
(2 hours ago)
Apache probe; attempts=46; exact paths: /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 09:59:30
(23 hours ago)
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 05:59:21.467319 2026] [security2:error] [pid 32716:tid 32716] [client 117.4.83.59:57478] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.4.83.59 (+1 hits since last alert)|arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "arsenalfordemocracy.com"] [uri "/xmlrpc.php"] [unique_id "amh9eXEJeo8gUSYxzc5DEwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-07-28 08:22:38
(1 day ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 07:01:47
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 03:01:41.946938 2026] [security2:error] [pid 29951:tid 29951] [client 117.4.83.59:55113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.4.83.59 (+1 hits since last alert)|gemco-mfg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gemco-mfg.com"] [uri "/xmlrpc.php"] [unique_id "amhT1RMY6vdjE6rfsL03IQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 09:51:22
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 05:51:17.048021 2026] [security2:error] [pid 442634:tid 442634] [client 117.4.83.59:45545] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.4.83.59 (+1 hits since last alert)|firstunitedreserve.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "firstunitedreserve.com"] [uri "/xmlrpc.php"] [unique_id "amcqFSzwGiLIEK5f5LNDXAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 08:19:09
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 04:19:01.765580 2026] [security2:error] [pid 8595:tid 8595] [client 117.4.83.59:55267] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.4.83.59 (+1 hits since last alert)|barecreationsaz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "barecreationsaz.com"] [uri "/xmlrpc.php"] [unique_id "amcUdT_MeQvBqhSqYRqhqwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-27 03:42:29
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-07-23 15:30:06
(5 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-07-02 06:12:08
(3 weeks ago)
(xmlrpc) Failed xmlrpc access from 117.4.83.59 (VN/Vietnam/localhost): 5 in the last 3600 secs (0-12 ...
show more
(xmlrpc) Failed xmlrpc access from 117.4.83.59 (VN/Vietnam/localhost): 5 in the last 3600 secs (0-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-02 04:11:21
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 00:11:14.212462 2026] [security2:error] [pid 32352:tid 32352] [client 117.4.83.59:55075] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.4.83.59 (+1 hits since last alert)|riser-astrology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "riser-astrology.com"] [uri "/xmlrpc.php"] [unique_id "akXk4qc072w0JInMtOd-qAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 02:40:50
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 22:40:42.903004 2026] [security2:error] [pid 3823:tid 3823] [client 117.4.83.59:44160] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.4.83.59 (+1 hits since last alert)|reallifelearninghub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "reallifelearninghub.com"] [uri "/xmlrpc.php"] [unique_id "akXPqrF5Ekd1Iqox8Q9FtwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 01:58:21
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 21:58:17.961475 2026] [security2:error] [pid 4794:tid 4794] [client 117.4.83.59:42645] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.4.83.59 (+1 hits since last alert)|mkdesignndetailing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mkdesignndetailing.com"] [uri "/xmlrpc.php"] [unique_id "akXFuWXFg-Rc8svL4flQoQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-01 06:47:14
(4 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 03:52:55
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:240335) triggered by 117.4.83.59 (localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 23:52:49.511773 2026] [security2:error] [pid 4866:tid 4866] [client 117.4.83.59:53321] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 117.4.83.59 (+1 hits since last alert)|cienmalos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cienmalos.com"] [uri "/xmlrpc.php"] [unique_id "akM9kR55BX2akVr3-iYO9gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack