๐บ๐ธ
lostswordfish.com
2026-06-21 11:10:06
(13 hours ago)
Wordfence waf block on pameganslaw
Web App Attack
Anonymous
2026-06-21 08:26:20
(16 hours ago)
157.15.146.129 - - [21/Jun/2026:10:25:58 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.c ...
show more
157.15.146.129 - - [21/Jun/2026:10:25:58 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.com; https://wordpress.com"
157.15.146.129 - - [21/Jun/2026:10:25:59 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com; https://wordpress.com"
157.15.146.129 - - [21/Jun/2026:10:26:08 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
157.15.146.129 - - [21/Jun/2026:10:26:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
157.15.146.129 - - [21/Jun/2026:10:26:19 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/13.0; WordPress/6.3; http://site80995221.com"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-20 16:45:15
(1 day ago)
[redacted] 157.15.146.129 - - [20/Jun/2026:18:44:32 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 157.15.146.129 - - [20/Jun/2026:18:44:32 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 157.15.146.129 - - [20/Jun/2026:18:44:41 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 157.15.146.129 - - [20/Jun/2026:18:44:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.3; http://site64697874.com"
[redacted] 157.15.146.129 - - [20/Jun/2026:18:45:03 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 157.15.146.129 - - [20/Jun/2026:18:45:14 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-20 13:06:05
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 12:06:15
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 157.15.146.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 157.15.146.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 08:06:11.147148 2026] [security2:error] [pid 698:tid 698] [client 157.15.146.129:54186] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 157.15.146.129 (+1 hits since last alert)|johncyphers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "johncyphers.com"] [uri "/xmlrpc.php"] [unique_id "ajaCMws_n2oR9eQPg0td2wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-20 11:35:23
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 08:55:24
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 157.15.146.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 157.15.146.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 04:55:17.740121 2026] [security2:error] [pid 17578:tid 17578] [client 157.15.146.129:52908] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 157.15.146.129 (+1 hits since last alert)|rajabarber.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rajabarber.com"] [uri "/xmlrpc.php"] [unique_id "ajZVdXFQrWHKKUtvrsrQTgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-06-20 06:48:15
(1 day ago)
157.15.146.129 - - [20/Jun/2026:14:47:53 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack/12 ...
show more
157.15.146.129 - - [20/Jun/2026:14:47:53 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack/12.1; WordPress/6.2; http://site12787424.com"
157.15.146.129 - - [20/Jun/2026:14:48:03 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
157.15.146.129 - - [20/Jun/2026:14:48:14 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-20 03:58:36
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 157.15.146.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 157.15.146.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 23:58:28.794224 2026] [security2:error] [pid 20637:tid 20637] [client 157.15.146.129:57952] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 157.15.146.129 (+1 hits since last alert)|eye7graphics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eye7graphics.com"] [uri "/xmlrpc.php"] [unique_id "ajYP5Aq0R00wzan85F5fNgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-20 03:25:06
(1 day ago)
[ns31.kdns.gr] httpd-xmlrpc-post: sites=michalopoulosstore.gr; logs=/var/log/httpd/domains/michalopo ...
show more
[ns31.kdns.gr] httpd-xmlrpc-post: sites=michalopoulosstore.gr; logs=/var/log/httpd/domains/michalopoulosstore.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-18 13:42:56
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-06-18 11:31:30
(3 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 10:46:31
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 157.15.146.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 157.15.146.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 06:46:23.443312 2026] [security2:error] [pid 23373:tid 23373] [client 157.15.146.129:51600] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 157.15.146.129 (+1 hits since last alert)|texascottagebakers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "texascottagebakers.com"] [uri "/xmlrpc.php"] [unique_id "ajPMf5h4o7SmShMktU2JQgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-16 12:27:50
(5 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-14 14:17:51
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 157.15.146.129 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 157.15.146.129 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 10:17:44.990405 2026] [security2:error] [pid 958:tid 958] [client 157.15.146.129:53901] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 157.15.146.129 (+1 hits since last alert)|lambert-heating-and-air.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lambert-heating-and-air.com"] [uri "/xmlrpc.php"] [unique_id "ai64CExVgaEDagAC5oSWuwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack