Anonymous
2026-06-04 12:46:04
(4 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-03 16:00:04
(1 day ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-06-03 12:06:33
(1 day ago)
(wordpress) Failed wordpress login from 125.209.86.58 (PK/Pakistan/dipitt.com)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-03 07:20:06
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 125.209.86.58 (dipitt.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:240335) triggered by 125.209.86.58 (dipitt.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 03:20:01.004003 2026] [security2:error] [pid 12055:tid 12055] [client 125.209.86.58:52030] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.209.86.58 (+1 hits since last alert)|soonerstone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "soonerstone.com"] [uri "/xmlrpc.php"] [unique_id "ah_VoKsxKIFG2hDvgqUBQAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-01 14:39:27
(3 days ago)
125.209.86.58 - - [01/Jun/2026:16:39:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.co ...
show more
125.209.86.58 - - [01/Jun/2026:16:39:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.com; https://wordpress.com"
125.209.86.58 - - [01/Jun/2026:16:39:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com; https://wordpress.com"
125.209.86.58 - - [01/Jun/2026:16:39:15 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12.5; WordPress/6.1; http://site19739770.com"
125.209.86.58 - - [01/Jun/2026:16:39:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12.5; WordPress/6.1; http://site19739770.com"
125.209.86.58 - - [01/Jun/2026:16:39:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-01 05:22:23
(3 days ago)
Attac
Brute-Force
๐ฉ๐ช
ger-stg-sifi1
2026-05-25 08:53:10
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 08:26:14
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 125.209.86.58 (dipitt.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:240335) triggered by 125.209.86.58 (dipitt.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 04:26:08.488082 2026] [security2:error] [pid 30561:tid 30561] [client 125.209.86.58:64674] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.209.86.58 (+1 hits since last alert)|boraimpact.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "boraimpact.com"] [uri "/xmlrpc.php"] [unique_id "ahQHoMurPEyFKlmU7OboRwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-25 05:48:41
(1 week ago)
Attac
Brute-Force
Anonymous
2026-05-22 13:21:57
(1 week ago)
Fail2Ban - Wordpress brute-force
...
Brute-Force
Web App Attack
Anonymous
2026-05-22 05:40:53
(1 week ago)
Attac
Brute-Force
๐ฉ๐ช
konseptit
2026-05-22 05:40:08
(1 week ago)
(wordpress) Failed wordpress login from 125.209.86.58 (PK/Pakistan/dipitt.com)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-21 15:38:02
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 125.209.86.58 (dipitt.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:240335) triggered by 125.209.86.58 (dipitt.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 11:37:54.061393 2026] [security2:error] [pid 1899:tid 1899] [client 125.209.86.58:56205] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.209.86.58 (+1 hits since last alert)|oakvillenaturopathicclinic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "oakvillenaturopathicclinic.com"] [uri "/xmlrpc.php"] [unique_id "ag8m0hpxw3JWPOyOc_x3mQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-21 12:41:16
(2 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-05-20 11:40:10
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 125.209.86.58 (dipitt.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:240335) triggered by 125.209.86.58 (dipitt.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 07:40:02.166000 2026] [security2:error] [pid 12750:tid 12750] [client 125.209.86.58:55781] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 125.209.86.58 (+1 hits since last alert)|acarsubscription.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "acarsubscription.com"] [uri "/xmlrpc.php"] [unique_id "ag2dktcr2px1DcfvSTaqXAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack