๐ซ๐ท
dynamix
2026-07-24 08:34:24
(15 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 18:16:18
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 154.227.128.103 (103-128-227-154.r.airtel.ug): ...
show more
(mod_security) mod_security (id:240335) triggered by 154.227.128.103 (103-128-227-154.r.airtel.ug): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 14:16:12.427214 2026] [security2:error] [pid 3368553:tid 3368553] [client 154.227.128.103:19147] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.227.128.103 (+1 hits since last alert)|innovacionesnimba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "innovacionesnimba.com"] [uri "/xmlrpc.php"] [unique_id "amJabMoV-45oCtHKEsMyMAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-07-23 17:57:57
(1 day ago)
(wordpress) Failed wordpress login from 154.227.128.103 (UG/Uganda/103-128-227-154.r.airtel.ug): (C ...
show more
(wordpress) Failed wordpress login from 154.227.128.103 (UG/Uganda/103-128-227-154.r.airtel.ug): (CF_ENABLE)
show less
Brute-Force
๐ช๐ธ
alferez
2026-07-23 17:31:22
(1 day ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
bigwavedave
2026-07-23 17:24:20
(1 day ago)
Wordpress Attack
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-07-23 17:18:04
(1 day ago)
Wordfence waf block on wp20190711M4
Web App Attack
Anonymous
2026-07-23 16:56:04
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
Marc
2026-07-23 16:53:28
(1 day ago)
154.227.128.103 - - [23/Jul/2026:18:53:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4776 "-" "WordPress ...
show more
154.227.128.103 - - [23/Jul/2026:18:53:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4776 "-" "WordPress.com; https://wordpress.com" 154.227.128.103 - - [23/Jul/2026:18:53:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4775 "-" "WordPress.com; https://wordpress.com" 154.227.128.103 - - [23/Jul/2026:18:53:27 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4775 "-" "Jetpack/12.1; WordPress/6.1; http://site82993180.com"
show less
Brute-Force
Web App Attack
Anonymous
2026-07-23 08:54:01
(1 day ago)
Fail2Ban WordPress login brute-force detected
Brute-Force
Web App Attack
๐ซ๐ท
tecnicorioja
2026-07-22 22:00:29
(2 days ago)
POST /xmlrpc.php [22/Jul/2026:12:35:00
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 13:01:49
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 154.227.128.103 (103-128-227-154.r.airtel.ug): ...
show more
(mod_security) mod_security (id:240335) triggered by 154.227.128.103 (103-128-227-154.r.airtel.ug): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 09:01:41.713339 2026] [security2:error] [pid 845446:tid 845446] [client 154.227.128.103:16699] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.227.128.103 (+1 hits since last alert)|edgecomix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "edgecomix.com"] [uri "/xmlrpc.php"] [unique_id "amC_NT_HnuGST9fP_tt87wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 12:02:47
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 154.227.128.103 (103-128-227-154.r.airtel.ug): ...
show more
(mod_security) mod_security (id:240335) triggered by 154.227.128.103 (103-128-227-154.r.airtel.ug): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 08:02:39.910236 2026] [security2:error] [pid 2011754:tid 2011754] [client 154.227.128.103:9419] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.227.128.103 (+1 hits since last alert)|jellisonrepair.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jellisonrepair.com"] [uri "/xmlrpc.php"] [unique_id "amCxX5i0BjPVdloblSlfuAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-22 09:28:31
(2 days ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.co ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-22 09:04:33
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-07-22 07:13:22
(2 days ago)
(xmlrpc) Failed xmlrpc access from 154.227.128.103 (UG/Uganda/103-128-227-154.r.airtel.ug): 5 in the ...
show more
(xmlrpc) Failed xmlrpc access from 154.227.128.103 (UG/Uganda/103-128-227-154.r.airtel.ug): 5 in the last 3600 secs (0-122)
show less
Hacking