🇦🇺
screwlooseit.com.au
2026-08-12 06:59:23
(4 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
IN/India/-
Web App Attack
🇳🇱
ipoac.nl
2026-08-12 06:19:08
(4 weeks ago)
-:443 120.56.222.43 - - [12/Aug/2026:08:19:07 +0200] - "POST /xmlrpc.php HTTP/1.1" 403 4996 "-" "Jet ...
show more
-:443 120.56.222.43 - - [12/Aug/2026:08:19:07 +0200] - "POST /xmlrpc.php HTTP/1.1" 403 4996 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
show less
Bad Web Bot
Anonymous
2026-08-12 03:21:27
(4 weeks ago)
[redacted] 120.56.222.43 - - [12/Aug/2026:05:20:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 120.56.222.43 - - [12/Aug/2026:05:20:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 120.56.222.43 - - [12/Aug/2026:05:20:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 120.56.222.43 - - [12/Aug/2026:05:21:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 120.56.222.43 - - [12/Aug/2026:05:21:15 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 120.56.222.43 - - [12/Aug/2026:05:21:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-12 01:40:54
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 120.56.222.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.222.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 21:40:50.332467 2026] [security2:error] [pid 2068809:tid 2068809] [client 120.56.222.43:57532] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.222.43 (+1 hits since last alert)|inverzona.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "inverzona.com"] [uri "/xmlrpc.php"] [unique_id "anvPInPbUSbej4LDQfVHhQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
jsjdmediallc
2026-08-11 21:20:04
(4 weeks ago)
Auto-blocked: score 134 (threshold 10). Hits: 67. Flags: xmlrpc. Paths: /xmlrpc.php, /xmlrpc.php, /x ...
show more
Auto-blocked: score 134 (threshold 10). Hits: 67. Flags: xmlrpc. Paths: /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 19:46:33
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 120.56.222.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.222.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 15:46:28.673549 2026] [security2:error] [pid 31030:tid 31050] [client 120.56.222.43:58481] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.222.43 (+1 hits since last alert)|hearthandhomestudio.art|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hearthandhomestudio.art"] [uri "/xmlrpc.php"] [unique_id "ant8FIJGcwsqgua060-5FgAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-11 18:15:19
(4 weeks ago)
[redacted] 120.56.222.43 - - [11/Aug/2026:20:14:36 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "J ...
show more
[redacted] 120.56.222.43 - - [11/Aug/2026:20:14:36 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack by WordPress.com"
[redacted] 120.56.222.43 - - [11/Aug/2026:20:14:46 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 120.56.222.43 - - [11/Aug/2026:20:14:57 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
[redacted] 120.56.222.43 - - [11/Aug/2026:20:15:08 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 120.56.222.43 - - [11/Aug/2026:20:15:18 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack/13.0; WordPress/6.1; http://site17672277.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-08-11 16:17:02
(4 weeks ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
🇳🇱
ConsulHosting
2026-08-11 16:04:17
(4 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 15:16:46
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 120.56.222.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.222.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 11:16:41.033373 2026] [security2:error] [pid 196773:tid 196773] [client 120.56.222.43:63886] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.222.43 (+1 hits since last alert)|globaldentalservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "globaldentalservices.com"] [uri "/xmlrpc.php"] [unique_id "ans82TWhLUt4oFAaSLef-AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-08-11 14:18:30
(4 weeks ago)
[TueAug1116:18:25.3906112026][security2:error][pid1852400:tid1852404][client120.56.222.43:0]ModSecur ...
show more
[TueAug1116:18:25.3906112026][security2:error][pid1852400:tid1852404][client120.56.222.43:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"chryptofarm.ch\"][uri\"/xmlrpc.php\"][unique_id\"ansvMeiCl3LCfZmj6zUWCgAAAAE\"]
show less
Port Scan
Brute-Force
Web App Attack
🇫🇮
YF
2026-08-11 13:00:38
(4 weeks ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
🇸🇪
ljo
2026-08-11 12:21:37
(4 weeks ago)
120.56.222.43 - - [11/Aug/2026:14:20:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "Jetpack by ...
show more
120.56.222.43 - - [11/Aug/2026:14:20:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
120.56.222.43 - - [11/Aug/2026:14:20:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
120.56.222.43 - - [11/Aug/2026:14:20:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "Jetpack by WordPress.com"
120.56.222.43 - - [11/Aug/2026:14:20:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "Jetpack/12.0; WordPress/6.4; http://site84365481.com"
120.56.222.43 - - [11/Aug/2026:14:20:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "WordPress.com; https://wordpress.com"
120.56.222.43 - - [11/Aug/2026:14:20:53 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "WordPress.com; https://wordpress.com"
120.56.222.43 - - [11/Aug/2026:14:21:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5436 "-" "WordPress.com; https://wordpress.com"
120.56.222.43 - - [11/Aug/2026:14:21:15 +0200] "POST /xmlrpc.php HTTP/1
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 10:39:41
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 120.56.222.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 120.56.222.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 06:39:34.601056 2026] [security2:error] [pid 812017:tid 812017] [client 120.56.222.43:63454] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 120.56.222.43 (+1 hits since last alert)|winnindustries.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "winnindustries.com"] [uri "/xmlrpc.php"] [unique_id "anr75iZIOkdvDzjUZWC_lAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack