๐ณ๐ฑ
applemooz
2025-10-07 17:58:10
(8 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐ณ๐ฑ
applemooz
2025-10-06 04:25:41
(8 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2025-10-05 05:07:54
(8 months ago)
Brute-Force
๐บ๐ธ
WeekendWeb
2025-10-04 12:39:39
(8 months ago)
Wordpress Vunerability attack
Web App Attack
๐ซ๐ฎ
YF
2025-09-29 21:00:36
(8 months ago)
xmlrpc.php (Potential DDoS or brute force)
Brute-Force
Web App Attack
Anonymous
2025-09-29 00:32:24
(8 months ago)
WordPress Brute Force
Brute-Force
๐ซ๐ท
dynamix
2025-09-28 23:40:21
(8 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2025-09-25 15:51:54
(8 months ago)
Bad Web Bot
Web App Attack
Anonymous
2025-09-20 04:53:46
(8 months ago)
[redacted] 154.213.202.30 - - [20/Sep/2025:06:53:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" " ...
show more
[redacted] 154.213.202.30 - - [20/Sep/2025:06:53:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (X11; U; Linux i586; de; rv:5.0) Gecko/20100101 Firefox/5.0"
[redacted] 154.213.202.30 - - [20/Sep/2025:06:53:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_6_3; en-us) AppleWebKit/531.21.11 (KHTML, like Gecko) Version/4.0.4 Safari/531.21.10"
[redacted] 154.213.202.30 - - [20/Sep/2025:06:53:39 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1; InfoPath.1; .NET CLR 2.0.50727)"
[redacted] 154.213.202.30 - - [20/Sep/2025:06:53:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_6_8) AppleWebKit/534.59.10 (KHTML, like Gecko) Version/5.1.9 Safari/534.59.10"
[redacted] 154.213.202.30 - - [20/Sep/2025:06:53:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 08:25:43
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 154.213.202.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.202.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 04:25:37.652523 2025] [security2:error] [pid 32165:tid 32165] [client 154.213.202.30:55625] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.conservadordehualpen.cl|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.conservadordehualpen.cl"] [uri "/s3cmd.ini"] [unique_id "aME2ASTvu8Gag7NJwoIc3QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-09-10 04:20:01
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 154.213.202.30 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 154.213.202.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 10 00:19:54.587819 2025] [security2:error] [pid 23220:tid 23220] [client 154.213.202.30:11763] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cruisedawgs.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cruisedawgs.com"] [uri "/s3cmd.ini"] [unique_id "aMD8amlzQnFa3JOKRnu7pwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bsoft.de
2025-09-08 02:39:21
(9 months ago)
154.213.202.30 - - [08/Sep/2025:03:25:59 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 ...
show more
154.213.202.30 - - [08/Sep/2025:03:25:59 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; en) AppleWebKit/412.6 (KHTML, like Gecko) Safari/412.2"
154.213.202.30 - - [08/Sep/2025:03:28:19 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/5.0 (Linux; U; Android 5.1; es-us; Ilium X210 Build/LMY47I) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/39.0.0.0 Mobile Safari/537.36"
154.213.202.30 - - [08/Sep/2025:04:39:19 +0200] "POST /xmlrpc.php HTTP/1.1" 200 426 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E)"
show less
Web App Attack
๐ฆ๐บ
weblite
2025-09-03 02:26:59
(9 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack
๐ฉ๐ช
1gz
2025-08-31 20:14:13
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET met ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action taken: CHALLENGE
Protocol: HTTP/2 (GET method)
Endpoint: /auth/login
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/129.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2025-08-25 12:51:32
(9 months ago)
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.08.25 is noted in report tim ...
show more
Attempted brute force login to web vpn 3 time(s); last attempt for 2025.08.25 is noted in report timestamp
show less
Hacking
Brute-Force