๐ฉ๐ช
Marc
2026-08-25 12:46:52
(1 day ago)
120.56.160.139 - - [25/Aug/2026:14:46:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4667 "-" "Jetpack/13 ...
show more
120.56.160.139 - - [25/Aug/2026:14:46:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4667 "-" "Jetpack/13.0; WordPress/6.3; http://site69898861.com" 120.56.160.139 - - [25/Aug/2026:14:46:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4668 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)" 120.56.160.139 - - [25/Aug/2026:14:46:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4668 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 09:16:15
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:16:07.128652 2026] [security2:error] [pid 13614:tid 13635] [client 120.56.160.139:58274] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.160.139 (+1 hits since last alert)|atlasrecordssearch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "atlasrecordssearch.com"] [uri "/xmlrpc.php"] [unique_id "ao1dV9IFvid9bv5xxr6SfgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 06:59:53
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 02:59:48.045713 2026] [security2:error] [pid 24550:tid 24550] [client 120.56.160.139:58188] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.160.139 (+1 hits since last alert)|reyadecostarica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "reyadecostarica.com"] [uri "/xmlrpc.php"] [unique_id "ao09ZDDMAusmqCBB7SLH7AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 03:56:02
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 23:55:55.578463 2026] [security2:error] [pid 14647:tid 14647] [client 120.56.160.139:55757] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.160.139 (+1 hits since last alert)|ritterlien.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ritterlien.com"] [uri "/xmlrpc.php"] [unique_id "ao0SSzZKjunyw8Iuz61iawAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-25 02:43:06
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 02:29:01
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 22:28:55.860998 2026] [security2:error] [pid 2317:tid 2317] [client 120.56.160.139:50861] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.160.139 (+1 hits since last alert)|michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "michelehoop.com"] [uri "/xmlrpc.php"] [unique_id "aoz95_RzgpLZmEaPLbnm-gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 01:28:01
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 21:27:54.931263 2026] [security2:error] [pid 19366:tid 19366] [client 120.56.160.139:57202] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.160.139 (+1 hits since last alert)|lemoulinavent.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lemoulinavent.org"] [uri "/xmlrpc.php"] [unique_id "aozvmpZcdh6-fANJu0pETQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-24 22:08:30
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 20:35:37
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 16:35:29.418260 2026] [security2:error] [pid 2799:tid 2799] [client 120.56.160.139:52080] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.160.139 (+1 hits since last alert)|bethanpearce.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bethanpearce.com"] [uri "/xmlrpc.php"] [unique_id "aoyrESPM4ROTVUCkbQ6tAgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 19:03:38
(2 days ago)
[redacted] 120.56.160.139 - - [24/Aug/2026:21:02:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 120.56.160.139 - - [24/Aug/2026:21:02:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 120.56.160.139 - - [24/Aug/2026:21:03:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 120.56.160.139 - - [24/Aug/2026:21:03:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 120.56.160.139 - - [24/Aug/2026:21:03:27 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.2; http://site80344465.com"
[redacted] 120.56.160.139 - - [24/Aug/2026:21:03:38 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-24 18:50:32
(2 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 15:41:32
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.160.139 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 11:41:28.690109 2026] [security2:error] [pid 9006:tid 9006] [client 120.56.160.139:55147] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.160.139 (+1 hits since last alert)|cbrtome.cl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cbrtome.cl"] [uri "/xmlrpc.php"] [unique_id "aoxmKEqkpNqrJEYC3c-fDAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-24 14:05:05
(2 days ago)
Web App Attack
Anonymous
2026-08-24 13:52:54
(2 days ago)
[redacted] 120.56.160.139 - - [24/Aug/2026:15:52:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 120.56.160.139 - - [24/Aug/2026:15:52:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
[redacted] 120.56.160.139 - - [24/Aug/2026:15:52:21 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.3; http://site19779248.com"
[redacted] 120.56.160.139 - - [24/Aug/2026:15:52:31 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 120.56.160.139 - - [24/Aug/2026:15:52:42 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
[redacted] 120.56.160.139 - - [24/Aug/2026:15:52:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
integrantservices.com
2026-08-24 13:21:57
(2 days ago)
(wordpress) Failed wordpress login from 120.56.160.139 (IN/India/-)
Brute-Force