๐ฉ๐ช
neckaralb-admin.de
2026-07-26 13:22:08
(56 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 12:42:36
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 156.196.214.220 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 156.196.214.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 08:42:27.718874 2026] [security2:error] [pid 2243093:tid 2243093] [client 156.196.214.220:6281] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.196.214.220 (+1 hits since last alert)|egelfitness.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "egelfitness.nl"] [uri "/xmlrpc.php"] [unique_id "amYAsz0lVZtwuGMC39hEaAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 01:15:02
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 156.196.214.220 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 156.196.214.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 21:14:57.995273 2026] [security2:error] [pid 3404378:tid 3404392] [client 156.196.214.220:4329] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.196.214.220 (+1 hits since last alert)|datuinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "datuinc.com"] [uri "/xmlrpc.php"] [unique_id "amVfkcIpmTsXMl8fv4SGPgAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-25 22:58:27
(15 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-07-25 02:14:12
(1 day ago)
[redacted] 156.196.214.220 - - [25/Jul/2026:04:13:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 156.196.214.220 - - [25/Jul/2026:04:13:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 156.196.214.220 - - [25/Jul/2026:04:13:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
[redacted] 156.196.214.220 - - [25/Jul/2026:04:13:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 156.196.214.220 - - [25/Jul/2026:04:14:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
[redacted] 156.196.214.220 - - [25/Jul/2026:04:14:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
...
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-07-24 21:17:30
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2026-07-24 15:59:11
(1 day ago)
156.196.214.220 - - [24/Jul/2026:17:58:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4669 "-" "Jetpack b ...
show more
156.196.214.220 - - [24/Jul/2026:17:58:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4669 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)" 156.196.214.220 - - [24/Jul/2026:17:59:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4670 "-" "Jetpack by WordPress.com" 156.196.214.220 - - [24/Jul/2026:17:59:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4669 "-" "Jetpack by WordPress.com"
show less
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-24 14:58:05
(1 day ago)
(wordpress) Failed wordpress login from 156.196.214.220 (EG/Egypt/-)
Brute-Force
๐ง๐ฌ
HighWay
2026-07-24 14:24:22
(1 day ago)
156.196.214.220 - - [24/Jul/2026:14:24:00 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4664 "-" "Jetpack b ...
show more
156.196.214.220 - - [24/Jul/2026:14:24:00 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4664 "-" "Jetpack by WordPress.com"
156.196.214.220 - - [24/Jul/2026:14:24:10 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4663 "-" "Jetpack/12.1; WordPress/6.1; http://site54568364.com"
156.196.214.220 - - [24/Jul/2026:14:24:21 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4664 "-" "Jetpack by WordPress.com"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 12:23:38
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 156.196.214.220 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 156.196.214.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:23:33.298659 2026] [security2:error] [pid 3639815:tid 3639815] [client 156.196.214.220:10973] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.196.214.220 (+1 hits since last alert)|wwfstudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wwfstudio.com"] [uri "/xmlrpc.php"] [unique_id "amNZRT8LG_arEwUfy36doQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-24 01:56:39
(2 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
EG/Egypt/-
Web App Attack
๐ฉ๐ช
rh24
2026-07-24 01:56:06
(2 days ago)
(xmlrpc_405) XMLRPC-Bot 405 156.196.214.220 (EG/Egypt/-)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-23 21:41:52
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 156.196.214.220 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 156.196.214.220 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 17:41:43.217676 2026] [security2:error] [pid 1345769:tid 1345769] [client 156.196.214.220:2938] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.196.214.220 (+1 hits since last alert)|cycontechnology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cycontechnology.com"] [uri "/xmlrpc.php"] [unique_id "amKKlzZqdAot9CKdw1HYZQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack