๐ฎ๐ฉ
bps-statistics
2026-07-29 15:58:03
(1 day ago)
Malicious Access
Brute-Force
๐ฎ๐ฉ
bps-statistics
2026-07-28 14:56:20
(3 days ago)
Malicious Access
Brute-Force
๐ฎ๐ฉ
bps-statistics
2026-07-27 14:10:37
(4 days ago)
Malicious Access
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-08 19:50:31
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 160.20.220.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.220.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 08 15:50:25.440477 2026] [security2:error] [pid 24116:tid 24116] [client 160.20.220.10:51929] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.220.10 (+1 hits since last alert)|kdgsf.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kdgsf.xyz"] [uri "/xmlrpc.php"] [unique_id "ak6qAT-LrvfgGKz5wruWawAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-06 02:38:49
(3 weeks ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 06:23:12
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 160.20.220.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.220.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 02:23:09.519434 2026] [security2:error] [pid 25789:tid 25789] [client 160.20.220.10:53348] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.220.10 (+1 hits since last alert)|yanlidesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yanlidesign.com"] [uri "/xmlrpc.php"] [unique_id "akn4TSqvVDIfd8ycX3vp_AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-05 06:22:34
(3 weeks ago)
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-07-05 06:21:05
(3 weeks ago)
{"ClientAddr":"160.20.220.10:62694","ClientHost":"160.20.220.10","ClientPort":"62694","ClientUsernam ...
show more
{"ClientAddr":"160.20.220.10:62694","ClientHost":"160.20.220.10","ClientPort":"62694","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":776777519,"OriginContentSize":418,"OriginDuration":772032304,"OriginStatus":403,"Overhead":4745215,"RequestAddr":"www.cleveradmin.de","RequestContentSize":720,"RequestCount":336935,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-07-05T08:20:42.982527681+02:00","StartUTC":"2026-07-05T06:20:42.982527681Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-07-05T08:20:43+02:00"}
{"ClientAddr":"160.20.220.10:62694","ClientHost":"160.20.220.10","C
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-07-05 04:20:30
(3 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-05 03:53:42
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 160.20.220.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.220.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 23:53:35.062677 2026] [security2:error] [pid 21578:tid 21578] [client 160.20.220.10:63999] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.220.10 (+1 hits since last alert)|gerrytolentino.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gerrytolentino.net"] [uri "/xmlrpc.php"] [unique_id "aknVP9TUw5VcY3zuxx1dPwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-07-05 02:36:13
(3 weeks ago)
160.20.220.10 - - [05/Jul/2026:10:35:51 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by ...
show more
160.20.220.10 - - [05/Jul/2026:10:35:51 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
160.20.220.10 - - [05/Jul/2026:10:35:59 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
160.20.220.10 - - [05/Jul/2026:10:36:12 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
๐บ๐ธ
TAY
2026-07-05 01:35:48
(3 weeks ago)
160.20.220.10 - - [05/Jul/2026:09:35:27 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by ...
show more
160.20.220.10 - - [05/Jul/2026:09:35:27 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
160.20.220.10 - - [05/Jul/2026:09:35:37 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com"
160.20.220.10 - - [05/Jul/2026:09:35:47 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-04 19:53:23
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 160.20.220.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.220.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 15:53:15.697679 2026] [security2:error] [pid 4252:tid 4252] [client 160.20.220.10:61989] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.220.10 (+1 hits since last alert)|seskalee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "seskalee.com"] [uri "/xmlrpc.php"] [unique_id "aklkq0GHnE0D6yNBtxsJPAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-04 15:45:19
(3 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-07-04 15:03:20
(3 weeks ago)
Failed attempt detected by Fail2Ban in plesk-modsecurity jail
Web App Attack