Anonymous
2026-05-22 01:07:58
(3 weeks ago)
LH-Watcher: FAKE_ID [Fake Googlebot]
Bad Web Bot
๐ฆ๐บ
screwlooseit.com.au
2026-03-12 14:06:26
(3 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
DK/Denmark/-
Web App Attack
Anonymous
2026-03-12 13:23:14
(3 months ago)
WordPress Brute Force
Brute-Force
Anonymous
2026-03-12 13:04:19
(3 months ago)
[redacted] 158.173.25.91 - - [12/Mar/2026:14:04:16 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "M ...
show more
[redacted] 158.173.25.91 - - [12/Mar/2026:14:04:16 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:14:04:16 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:14:04:16 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:14:04:16 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:14:04:16 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozi
...
show less
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-03-12 13:03:42
(3 months ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (5000900-122)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 12:12:48
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 158.173.25.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 158.173.25.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 08:12:39.383044 2026] [security2:error] [pid 31106:tid 31106] [client 158.173.25.91:1735] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 158.173.25.91 (+1 hits since last alert)|www.pleaseaddbacon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.pleaseaddbacon.com"] [uri "/xmlrpc.php"] [unique_id "abKtt6lSi5cNm-oMiqs6ZwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-03-12 12:11:55
(3 months ago)
[redacted] 158.173.25.91 - - [12/Mar/2026:13:11:53 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "M ...
show more
[redacted] 158.173.25.91 - - [12/Mar/2026:13:11:53 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:13:11:53 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:13:11:53 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:13:11:53 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:13:11:53 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178
...
show less
Hacking
Web App Attack
Anonymous
2026-03-12 11:57:03
(3 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, [1/1] done, GET /xmlrpc.php HTTP/ ...
show more
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, [1/1] done, GET /xmlrpc.php HTTP/2.0
show less
Hacking
Web App Attack
๐จ๐ญ
backslash
2026-03-12 11:51:00
(3 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
Anonymous
2026-03-12 11:48:41
(3 months ago)
[redacted] 158.173.25.91 - - [12/Mar/2026:12:48:38 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "M ...
show more
[redacted] 158.173.25.91 - - [12/Mar/2026:12:48:38 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:12:48:38 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:12:48:38 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:12:48:38 +0100] "POST /xmlrpc.php HTTP/1.1" 200 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/136.0.0.0 Safari/537.36"
[redacted] 158.173.25.91 - - [12/Mar/2026:12:48:38 +0100] "POST /xmlrpc.php HT
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-12 11:41:58
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 158.173.25.91 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 158.173.25.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 07:41:52.179414 2026] [security2:error] [pid 18757:tid 18757] [client 158.173.25.91:54143] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 158.173.25.91 (+1 hits since last alert)|gamerah.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gamerah.net"] [uri "/xmlrpc.php"] [unique_id "abKmgL7mSj1a_I8AxK0SowAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-03-12 11:30:38
(3 months ago)
(wordpress) Failed wordpress login from 158.173.25.91 (US/United States/New York/New York/-)
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-03-12 11:27:16
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 25
Exploited Host
Web App Attack
๐ง๐ช
cmbplf
2026-03-12 11:27:00
(3 months ago)
3.362 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Mangelot Hosting
2026-02-28 05:53:19
(3 months ago)
(smtpauth) Failed SMTP AUTH login from 158.173.25.91 (US/United States/-): 5 in the last 3600 secs; ...
show more
(smtpauth) Failed SMTP AUTH login from 158.173.25.91 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs:
show less
Brute-Force