๐ง๐ช
cmbplf
2026-06-26 21:39:57
(3 days ago)
3.549 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-26 15:06:56
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): ...
show more
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 11:06:50.423622 2026] [security2:error] [pid 24596:tid 24596] [client 130.216.116.252:38838] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 130.216.116.252 (+1 hits since last alert)|celebritybikinigossip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "celebritybikinigossip.com"] [uri "/xmlrpc.php"] [unique_id "aj6VimLMeq9prnh_yOtWzwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-26 11:44:04
(4 days ago)
Wordfence waf block on lostswordfish
Web App Attack
Anonymous
2026-06-26 10:44:04
(4 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-26 08:45:12
(4 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
Anonymous
2026-06-24 07:52:07
(6 days ago)
[ns19.kdns.gr] httpd-xmlrpc-post: sites=microtech.com.cy; logs=/var/log/httpd/domains/microtech.com. ...
show more
[ns19.kdns.gr] httpd-xmlrpc-post: sites=microtech.com.cy; logs=/var/log/httpd/domains/microtech.com.cy.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 07:21:19
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): ...
show more
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 03:21:13.395992 2026] [security2:error] [pid 15400:tid 15400] [client 130.216.116.252:34988] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 130.216.116.252 (+1 hits since last alert)|aroilcontrolsystem.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aroilcontrolsystem.com"] [uri "/xmlrpc.php"] [unique_id "ajuFaa2Jch-ecPfHtOoekQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-24 05:47:55
(6 days ago)
[redacted] 130.216.116.252 - - [24/Jun/2026:07:47:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" ...
show more
[redacted] 130.216.116.252 - - [24/Jun/2026:07:47:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack/12.1; WordPress/6.3; http://site82885024.com"
[redacted] 130.216.116.252 - - [24/Jun/2026:07:47:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 130.216.116.252 - - [24/Jun/2026:07:47:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 130.216.116.252 - - [24/Jun/2026:07:47:21 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 130.216.116.252 - - [24/Jun/2026:07:47:31 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 130.216.116.252 - - [24/Jun/2026:07:47:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 130.216.116.252 - - [24/Jun/2026:07:47:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack/12.5; WordPress/6.2; http://site3440
...
show less
Hacking
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-22 22:46:37
(1 week ago)
(PERMBLOCK) 130.216.116.252 (NZ/New Zealand/en460922.uoa.auckland.ac.nz) has had more than 4 temp bl ...
show more
(PERMBLOCK) 130.216.116.252 (NZ/New Zealand/en460922.uoa.auckland.ac.nz) has had more than 4 temp blocks
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-22 21:33:47
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): ...
show more
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 17:33:42.142222 2026] [security2:error] [pid 8221:tid 8221] [client 130.216.116.252:54280] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 130.216.116.252 (+1 hits since last alert)|jesussotoca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jesussotoca.com"] [uri "/xmlrpc.php"] [unique_id "ajmqNiqb8Uxtg96IqJ1C5AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 20:58:06
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): ...
show more
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 16:57:59.232802 2026] [security2:error] [pid 19816:tid 19842] [client 130.216.116.252:55720] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 130.216.116.252 (+1 hits since last alert)|maryschalkdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "maryschalkdesign.com"] [uri "/xmlrpc.php"] [unique_id "ajmh1_6ur10Ss0XVSijfSwAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-22 19:27:55
(1 week ago)
(wordpress) Failed wordpress login from 130.216.116.252 (NZ/New Zealand/en460922.uoa.auckland.ac.nz)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-22 18:59:39
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): ...
show more
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 14:59:31.580455 2026] [security2:error] [pid 14331:tid 14331] [client 130.216.116.252:48106] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 130.216.116.252 (+1 hits since last alert)|youreventnews.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "youreventnews.com"] [uri "/xmlrpc.php"] [unique_id "ajmGEy1BWua8prBMa4c94AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 10:07:35
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): ...
show more
(mod_security) mod_security (id:240335) triggered by 130.216.116.252 (en460922.uoa.auckland.ac.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 06:07:31.972225 2026] [security2:error] [pid 15489:tid 15489] [client 130.216.116.252:43284] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 130.216.116.252 (+1 hits since last alert)|vintageamptubes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vintageamptubes.com"] [uri "/xmlrpc.php"] [unique_id "ajkJY631PenkIyRxdjhW3gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-18 02:45:27
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack