Anonymous
2026-09-03 11:12:37
(2 days ago)
Blocked by ModSec and CSF
Port Scan
🇺🇸
kosada.com
2026-08-25 03:44:05
(1 week ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-17 09:12:03
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 143.44.224.127 (143.44.224.127-rev.convergeict. ...
show more
(mod_security) mod_security (id:240335) triggered by 143.44.224.127 (143.44.224.127-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 05:11:57.541031 2026] [security2:error] [pid 3580:tid 3580] [client 143.44.224.127:2679] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 143.44.224.127 (+1 hits since last alert)|americanureport.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "americanureport.com"] [uri "/xmlrpc.php"] [unique_id "aoLQXcXNVfR_gpNaBBg-4AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-17 08:09:28
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 143.44.224.127 (143.44.224.127-rev.convergeict. ...
show more
(mod_security) mod_security (id:240335) triggered by 143.44.224.127 (143.44.224.127-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 04:09:22.127028 2026] [security2:error] [pid 24709:tid 24709] [client 143.44.224.127:2869] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 143.44.224.127 (+1 hits since last alert)|achildsspace.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "achildsspace.com"] [uri "/xmlrpc.php"] [unique_id "aoLBslP-jfmA_pQtwt-b7gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-17 07:05:20
(2 weeks ago)
WordPress login brute-force | req: /xmlrpc.php | UA: Jetpack by WordPress.com
Brute-Force
Web App Attack
🇫🇷
dynamix
2026-08-17 05:21:36
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-08-15 02:59:29
(3 weeks ago)
[redacted] 143.44.224.127 - - [15/Aug/2026:04:58:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 143.44.224.127 - - [15/Aug/2026:04:58:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.4; http://site30613722.com"
[redacted] 143.44.224.127 - - [15/Aug/2026:04:58:56 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.1; http://site66932528.com"
[redacted] 143.44.224.127 - - [15/Aug/2026:04:59:07 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 143.44.224.127 - - [15/Aug/2026:04:59:22 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
[redacted] 143.44.224.127 - - [15/Aug/2026:04:59:28 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
🇳🇱
ConsulHosting
2026-08-15 01:14:13
(3 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-08-15 00:59:57
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 143.44.224.127 (143.44.224.127-rev.convergeict. ...
show more
(mod_security) mod_security (id:240335) triggered by 143.44.224.127 (143.44.224.127-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 20:59:50.638436 2026] [security2:error] [pid 27540:tid 27540] [client 143.44.224.127:18758] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 143.44.224.127 (+1 hits since last alert)|alsetsystems.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "alsetsystems.com"] [uri "/xmlrpc.php"] [unique_id "an-6BoS66h2eOiojQvba7wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lostswordfish.com
2026-08-13 13:54:04
(3 weeks ago)
Wordfence waf block on flintlocal432
Web App Attack
🇺🇸
TPI-Abuse
2026-08-13 11:09:37
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 143.44.224.127 (143.44.224.127-rev.convergeict. ...
show more
(mod_security) mod_security (id:240335) triggered by 143.44.224.127 (143.44.224.127-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 07:09:33.054110 2026] [security2:error] [pid 2335309:tid 2335309] [client 143.44.224.127:22658] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 143.44.224.127 (+1 hits since last alert)|anthonyanimalclinic.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "anthonyanimalclinic.net"] [uri "/xmlrpc.php"] [unique_id "an2l7ffrAexNiX6cSUv6QAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-13 10:39:36
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 143.44.224.127 (143.44.224.127-rev.convergeict. ...
show more
(mod_security) mod_security (id:240335) triggered by 143.44.224.127 (143.44.224.127-rev.convergeict.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 06:39:29.919978 2026] [security2:error] [pid 26796:tid 26796] [client 143.44.224.127:22667] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 143.44.224.127 (+1 hits since last alert)|bickleton.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bickleton.org"] [uri "/xmlrpc.php"] [unique_id "an2e4XDJzfA2IQUk1fj_8AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-08-13 09:57:11
(3 weeks ago)
[ThuAug1311:57:09.1838722026][security2:error][pid560204:tid560227][client143.44.224.127:0]ModSecuri ...
show more
[ThuAug1311:57:09.1838722026][security2:error][pid560204:tid560227][client143.44.224.127:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"artisteer-italia.org\"][uri\"/xmlrpc.php\"][unique_id\"an2U9bW3rFxoZ0DZJ6pkxQAAAFQ\"]
show less
Port Scan
Brute-Force
Web App Attack
🇳🇿
Tripwire
2026-08-13 09:55:45
(3 weeks ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
🇨🇦
polycoda
2026-08-13 09:10:08
(3 weeks ago)
AutoBlock: 🔐 WordPress Login Brute Force (20X or 30X) (Decay-Based)
Brute-Force
Web App Attack