๐ณ๐ฑ
Site.eu
2026-07-02 07:41:59
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฆ๐บ
screwlooseit.com.au
2026-07-02 05:18:53
(2 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
ZM/Zambia/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 04:50:09
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 00:50:04.488029 2026] [security2:error] [pid 14444:tid 14444] [client 165.56.14.216:61688] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 165.56.14.216 (+1 hits since last alert)|mariettacaseyclub.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mariettacaseyclub.org"] [uri "/xmlrpc.php"] [unique_id "akXt_CuKxEk_iVrbkM8P5wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-07-01 22:13:12
(3 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 21:51:04
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 17:50:58.487983 2026] [security2:error] [pid 22604:tid 22608] [client 165.56.14.216:22491] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thecraftsycat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thecraftsycat.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akWLwsp0KfxogUJ-5lvxIgAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-07-01 19:30:38
(3 days ago)
165.56.14.216 - - [02/Jul/2026:03:30:17 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "WordPress.c ...
show more
165.56.14.216 - - [02/Jul/2026:03:30:17 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "WordPress.com; https://wordpress.com"
165.56.14.216 - - [02/Jul/2026:03:30:27 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
165.56.14.216 - - [02/Jul/2026:03:30:38 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack/12.0; WordPress/6.4; http://site96479639.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-01 18:01:18
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 14:01:12.511607 2026] [security2:error] [pid 13818:tid 13818] [client 165.56.14.216:4630] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 165.56.14.216 (+1 hits since last alert)|evelynkay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "evelynkay.com"] [uri "/xmlrpc.php"] [unique_id "akVV6Ioj_osuOoht1BwEyQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-07-01 14:17:53
(3 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
Anonymous
2026-07-01 04:55:04
(3 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 03:13:10
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 23:13:01.854737 2026] [security2:error] [pid 2462:tid 2462] [client 165.56.14.216:39279] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 165.56.14.216 (+1 hits since last alert)|oowoah.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "oowoah.com"] [uri "/xmlrpc.php"] [unique_id "akSFvZ7pnYm8cfySdz1hnwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Kenshin869
2026-07-01 03:11:04
(3 days ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-30 22:05:17
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 18:05:13.408350 2026] [security2:error] [pid 2165:tid 2165] [client 165.56.14.216:19842] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 165.56.14.216 (+1 hits since last alert)|famagustacyprus.eu|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "famagustacyprus.eu"] [uri "/xmlrpc.php"] [unique_id "akQ9mffmJlkotxU3GlYBrQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-06-30 12:01:28
(4 days ago)
165.56.14.216 - - [30/Jun/2026:1
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-30 11:59:06
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 165.56.14.216 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 07:59:02.679578 2026] [security2:error] [pid 16143:tid 16143] [client 165.56.14.216:31267] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 165.56.14.216 (+1 hits since last alert)|eye7graphics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eye7graphics.com"] [uri "/xmlrpc.php"] [unique_id "akOvhhrxxLrjbZsKHeQuZgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-30 08:23:25
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack