Anonymous
2026-07-26 11:06:52
(2 hours ago)
[web.zebs.ch] httpd-xmlrpc-post: sites=www.zebs.ch; logs=/var/log/httpd/domains/zebs.ch.log; samples ...
show more
[web.zebs.ch] httpd-xmlrpc-post: sites=www.zebs.ch; logs=/var/log/httpd/domains/zebs.ch.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ซ๐ฎ
KnightIndustries
2026-07-25 21:49:02
(15 hours ago)
2026-07-25T23:47:16.548329+02:00 milkyway wordpress(learncryptography.pw)[654101]: XML-RPC authentic ...
show more
2026-07-25T23:47:16.548329+02:00 milkyway wordpress(learncryptography.pw)[654101]: XML-RPC authentication failure for macminty from 124.158.42.163
2026-07-25T23:48:09.190582+02:00 milkyway wordpress(learncryptography.pw)[654095]: XML-RPC authentication failure for macminty from 124.158.42.163
2026-07-25T23:49:01.748596+02:00 milkyway wordpress(learncryptography.pw)[654093]: XML-RPC authentication failure for macminty from 124.158.42.163
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 14:27:48
(22 hours ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 10:27:36.530761 2026] [security2:error] [pid 1413105:tid 1413105] [client 124.158.42.163:44262] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.163 (+1 hits since last alert)|directcch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "directcch.com"] [uri "/xmlrpc.php"] [unique_id "amTH2P9qxtJS6YgfeX3oZQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-25 12:37:07
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 22:13:20
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 18:13:08.767675 2026] [security2:error] [pid 85610:tid 85610] [client 124.158.42.163:36815] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.163 (+1 hits since last alert)|madisonmedia.ai|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "madisonmedia.ai"] [uri "/xmlrpc.php"] [unique_id "amPjdHA5IHEN0kEZqUBAGgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 12:23:39
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 08:23:26.945185 2026] [security2:error] [pid 856634:tid 856634] [client 124.158.42.163:63645] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.163 (+1 hits since last alert)|capriexpress.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "capriexpress.com"] [uri "/xmlrpc.php"] [unique_id "amC2PrkR_f3juwTGZ7bSWQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 12:49:58
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:49:45.230634 2026] [security2:error] [pid 14325:tid 14325] [client 124.158.42.163:25165] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.163 (+1 hits since last alert)|tcomputerguy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tcomputerguy.com"] [uri "/xmlrpc.php"] [unique_id "al9q6ZzTP8iEMCiX42Z-1QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-07-21 09:10:05
(5 days ago)
Wordfence waf block on flintlocal432
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 07:03:27
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 03:03:17.655641 2026] [security2:error] [pid 20831:tid 20831] [client 124.158.42.163:40528] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.163 (+1 hits since last alert)|rodandreelpiercam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rodandreelpiercam.com"] [uri "/xmlrpc.php"] [unique_id "al8ZtWX58udaATsemCDs7QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-21 04:48:57
(5 days ago)
cloudlinux2 fail2ban: 2026-07-21 06:44:25,418 fail2ban.filter [1927]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-21 06:44:25,418 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 157.42.0.255 - 2026-07-21 06:44:25cloudlinux2 fail2ban: 2026-07-21 06:44:29,426 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 124.158.42.163 - 2026-07-21 06:44:29cloudlinux2 fail2ban: 2026-07-21 06:44:40,067 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 124.158.42.163 - 2026-07-21 06:44:40cloudlinux2 fail2ban: 2026-07-21 06:44:56,139 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 193.36.224.229 - 2026-07-21 06:44:55cloudlinux2 fail2ban: 2026-07-21 06:44:56,001 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 193.36.224.218 - 2026-07-21 06:44:55cloudlinux2 fail2ban: 2026-07-21 06:45:13,489 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 193.19.109.241 - 2026-07-21 06:45:12cloudlinux2 fail2ban: 2026-07-21 06:45:29,801 fail2ban.filter [1927]: INFO [recidive] Found 157.42.0.255 - 2026-07-21 06:45:29cloudli
show less
Web App Attack
๐ซ๐ท
dynamix
2026-07-21 01:07:23
(5 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 23:18:36
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 19:18:22.290674 2026] [security2:error] [pid 3190731:tid 3190731] [client 124.158.42.163:25831] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.163 (+1 hits since last alert)|solarfarms.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solarfarms.info"] [uri "/xmlrpc.php"] [unique_id "al6svr7LLfv9mFfr49plTgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ท
setupgr
2026-07-20 12:38:31
(6 days ago)
(XMLRPC) WP XMLRPC Attack 124.158.42.163 (PH/Philippines/National Capital Region/Pasig/-/[AS17639 CO ...
show more
(XMLRPC) WP XMLRPC Attack 124.158.42.163 (PH/Philippines/National Capital Region/Pasig/-/[AS17639 CONVERGE-AS Converge ICT Solutions Inc.]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 124.158.42.163 - - [20/Jul/2026:15:38:02 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18935 "-" "Jetpack by WordPress.com"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-20 11:44:24
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.163 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 07:44:13.120437 2026] [security2:error] [pid 4000317:tid 4000317] [client 124.158.42.163:55380] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.163 (+1 hits since last alert)|cynosurehomeservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cynosurehomeservices.com"] [uri "/xmlrpc.php"] [unique_id "al4KDWkLTz5kKhNYRP8ctAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-17 21:03:56
(1 week ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack