๐ฑ๐ป
garmtech.com
2026-07-25 04:28:58
(41 minutes ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐ช๐ธ
masterguru
2026-07-25 03:46:35
(1 hour ago)
(xmlrpc) Failed xmlrpc access from 138.84.155.21 (PH/Philippines/-): 5 in the last 3600 secs (0-122)
Hacking
๐ฎ๐น
CoreTech srl
2026-07-25 01:41:29
(3 hours ago)
cloudlinux2 fail2ban: 2026-07-25 03:14:13,867 fail2ban.filter [1816]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-25 03:14:13,867 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 138.84.155.21 - 2026-07-25 03:14:13cloudlinux2 fail2ban: 2026-07-25 03:14:37,046 fail2ban.filter [1816]: INFO [plesk-wordpress] Found 190.92.174.30 - 2026-07-25 03:14:36cloudlinux2 fail2ban: 2026-07-25 03:15:18,106 fail2ban.actions [1816]: NOTICE [plesk-modsecurity] Ban 138.84.155.21cloudlinux2 fail2ban: 2026-07-25 03:15:16,586 fail2ban.filter [1816]: INFO [plesk-wordpress] Found 45.131.195.222 - 2026-07-25 03:15:15cloudlinux2 fail2ban: 2026-07-25 03:15:17,505 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 138.84.155.21 - 2026-07-25 03:15:17cloudlinux2 fail2ban: 2026-07-25 03:15:18,232 fail2ban.filter [1816]: INFO [recidive] Found 138.84.155.21 - 2026-07-25 03:15:18cloudlinux2 fail2ban: 2026-07-25 03:15:12,273 fail2ban.filter [1816]: INFO [plesk-wordpress] Found 45.131.195.222 - 2026-07-25 03:15:11cloudlinux2 fail2ban: 2026-07-25
show less
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-25 01:20:15
(3 hours ago)
138.84.155.21 - - [24/Jul/2026:21:18:49 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5368 "-" "WordPress.c ...
show more
138.84.155.21 - - [24/Jul/2026:21:18:49 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5368 "-" "WordPress.com; https://wordpress.com"
138.84.155.21 - - [24/Jul/2026:21:19:43 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5368 "-" "WordPress.com; https://wordpress.com"
138.84.155.21 - - [24/Jul/2026:21:19:53 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5368 "-" "WordPress.com; https://wordpress.com"
138.84.155.21 - - [24/Jul/2026:21:20:04 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5367 "-" "WordPress.com; https://wordpress.com"
138.84.155.21 - - [24/Jul/2026:21:20:15 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5368 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 00:12:54
(4 hours ago)
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 20:12:49.696413 2026] [security2:error] [pid 908433:tid 908433] [client 138.84.155.21:57172] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 138.84.155.21 (+1 hits since last alert)|levijoneslegal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "levijoneslegal.com"] [uri "/xmlrpc.php"] [unique_id "amP_gV1X4qeKPuK3Wtr3CgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 23:42:04
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 19:41:59.292862 2026] [security2:error] [pid 1422484:tid 1422484] [client 138.84.155.21:49298] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 138.84.155.21 (+1 hits since last alert)|lesdaniels.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lesdaniels.com"] [uri "/xmlrpc.php"] [unique_id "amP4R6oK5ePNUHCyaZOZZQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 19:49:56
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:49:48.320651 2026] [security2:error] [pid 1259216:tid 1259216] [client 138.84.155.21:49267] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 138.84.155.21 (+1 hits since last alert)|hendersonhomes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hendersonhomes.com"] [uri "/xmlrpc.php"] [unique_id "amPB3HIDZzSahCcLqIxpXwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 19:04:08
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:04:02.171065 2026] [security2:error] [pid 623877:tid 623877] [client 138.84.155.21:49406] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 138.84.155.21 (+1 hits since last alert)|losbarbarosdelnorte.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "losbarbarosdelnorte.com"] [uri "/xmlrpc.php"] [unique_id "amO3InivtAPNcwjymLMgnQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 17:58:27
(11 hours ago)
[redacted] 138.84.155.21 - - [24/Jul/2026:19:57:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 138.84.155.21 - - [24/Jul/2026:19:57:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 138.84.155.21 - - [24/Jul/2026:19:57:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.1; http://site41875286.com"
[redacted] 138.84.155.21 - - [24/Jul/2026:19:58:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 138.84.155.21 - - [24/Jul/2026:19:58:15 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 138.84.155.21 - - [24/Jul/2026:19:58:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.4; http://site53433256.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 16:30:57
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 12:30:51.092797 2026] [security2:error] [pid 2793365:tid 2793365] [client 138.84.155.21:27546] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 138.84.155.21 (+1 hits since last alert)|waterjetsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "waterjetsolutions.com"] [uri "/xmlrpc.php"] [unique_id "amOTO166ZFFydGt-t1I-tgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 14:03:59
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:03:51.299158 2026] [security2:error] [pid 2465907:tid 2465907] [client 138.84.155.21:27536] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 138.84.155.21 (+1 hits since last alert)|seskalee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "seskalee.com"] [uri "/xmlrpc.php"] [unique_id "amNwxyMh8W7tjlGZwE6HIgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 13:22:56
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 09:22:51.005149 2026] [security2:error] [pid 3927037:tid 3927037] [client 138.84.155.21:28059] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 138.84.155.21 (+1 hits since last alert)|wokedreamer.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wokedreamer.com"] [uri "/xmlrpc.php"] [unique_id "amNnK3IPZamYRDaw4ds6CAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 09:07:55
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 138.84.155.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 05:07:50.239944 2026] [security2:error] [pid 3485469:tid 3485469] [client 138.84.155.21:57174] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 138.84.155.21 (+1 hits since last alert)|ucommsi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ucommsi.com"] [uri "/xmlrpc.php"] [unique_id "amMrZj3C0cPnAAaH-XAu5gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
bigwavedave
2026-07-24 08:33:51
(20 hours ago)
Wordpress Attack
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-24 02:32:15
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/-
Web App Attack