๐บ๐ธ
TPI-Abuse
2026-06-25 18:28:35
(3 minutes ago)
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 14:28:27.701805 2026] [security2:error] [pid 27514:tid 27514] [client 160.20.40.146:2697] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.40.146 (+1 hits since last alert)|midway-island.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "midway-island.com"] [uri "/xmlrpc.php"] [unique_id "aj1zS3ZIrtmIBFvR_Q_X7QAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
applemooz
2026-06-25 18:26:27
(5 minutes ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 15:16:28
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 11:16:21.050397 2026] [security2:error] [pid 10277:tid 10277] [client 160.20.40.146:2720] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.40.146 (+1 hits since last alert)|georgesmarina.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "georgesmarina.com"] [uri "/xmlrpc.php"] [unique_id "aj1GRTJBsARDdJwfMmcWhQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-25 12:10:38
(6 hours ago)
[redacted] 160.20.40.146 - - [25/Jun/2026:14:09:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 160.20.40.146 - - [25/Jun/2026:14:09:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.4; http://site66775609.com"
[redacted] 160.20.40.146 - - [25/Jun/2026:14:10:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 160.20.40.146 - - [25/Jun/2026:14:10:15 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
[redacted] 160.20.40.146 - - [25/Jun/2026:14:10:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 160.20.40.146 - - [25/Jun/2026:14:10:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.1; http://site36985727.com"
...
show less
Hacking
Web App Attack
๐ง๐พ
lns.bz
2026-06-24 21:26:01
(21 hours ago)
Banned for trying to access xmlrpc [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 14:08:21
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 10:08:15.156006 2026] [security2:error] [pid 14127:tid 14127] [client 160.20.40.146:4546] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.40.146 (+1 hits since last alert)|shhcenter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "shhcenter.com"] [uri "/xmlrpc.php"] [unique_id "ajvkzwIEMFiZQrIlFHFF-gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-24 07:38:35
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 07:10:37
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 03:10:30.229844 2026] [security2:error] [pid 22846:tid 22846] [client 160.20.40.146:2389] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.40.146 (+1 hits since last alert)|ultratecnologia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ultratecnologia.com"] [uri "/xmlrpc.php"] [unique_id "ajuC5nycAjtSps21MVk9KAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-23 21:40:10
(1 day ago)
Attac
Brute-Force
๐ฉ๐ช
Marc
2026-06-23 21:37:48
(1 day ago)
160.20.40.146 - - [23/Jun/2026:23:37:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3709 "-" "Jetpack by ...
show more
160.20.40.146 - - [23/Jun/2026:23:37:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3709 "-" "Jetpack by WordPress.com" 160.20.40.146 - - [23/Jun/2026:23:37:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3709 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)" 160.20.40.146 - - [23/Jun/2026:23:37:47 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3708 "-" "Jetpack by WordPress.com"
show less
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-06-23 20:00:12
(1 day ago)
4.110 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-23 18:05:58
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 14:05:53.490613 2026] [security2:error] [pid 6637:tid 6637] [client 160.20.40.146:2333] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.40.146 (+1 hits since last alert)|christaylorjazzpianist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "christaylorjazzpianist.com"] [uri "/xmlrpc.php"] [unique_id "ajrLAY1GX9i5sCAp16vl8wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-23 18:00:12
(2 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 12:36:33
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 160.20.40.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 08:36:30.576306 2026] [security2:error] [pid 2885:tid 2885] [client 160.20.40.146:2752] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 160.20.40.146 (+1 hits since last alert)|luxandunion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "luxandunion.com"] [uri "/xmlrpc.php"] [unique_id "ajp9ztNFron18nlrGu6C5QAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-22 23:07:02
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack