Anonymous
2026-07-29 07:00:00
(2 days ago)
Apache probe; attempts=161; exact paths: /xmlrpc.php
Web App Attack
πΊπΈ
TAY
2026-07-27 15:38:25
(4 days ago)
169.148.95.94 - - [27/Jul/2026:23:38:02 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by ...
show more
169.148.95.94 - - [27/Jul/2026:23:38:02 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
169.148.95.94 - - [27/Jul/2026:23:38:12 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "WordPress.com; https://wordpress.com"
169.148.95.94 - - [27/Jul/2026:23:38:23 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack/12.0; WordPress/6.1; http://site74402416.com"
...
show less
Brute-Force
πͺπΈ
masterguru
2026-07-26 17:33:41
(5 days ago)
(xmlrpc) Failed xmlrpc access from 169.148.95.94 (SA/Saudi Arabia/-): 5 in the last 3600 secs (0-122 ...
show more
(xmlrpc) Failed xmlrpc access from 169.148.95.94 (SA/Saudi Arabia/-): 5 in the last 3600 secs (0-122)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-07-26 16:00:32
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 169.148.95.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 169.148.95.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 12:00:26.181153 2026] [security2:error] [pid 2862966:tid 2862966] [client 169.148.95.94:55486] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 169.148.95.94 (+1 hits since last alert)|huntingforebears.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "huntingforebears.com"] [uri "/xmlrpc.php"] [unique_id "amYvGjxp9kYBtTDam9ypBAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
jsjdmediallc
2026-07-25 17:00:08
(6 days ago)
Auto-blocked: score 336 (threshold 10). Tier: HIGH. Hits: 66. Flags: xmlrpc, xmlrpc-burst, single-pa ...
show more
Auto-blocked: score 336 (threshold 10). Tier: HIGH. Hits: 66. Flags: xmlrpc, xmlrpc-burst, single-path-flood. Paths: /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-25 16:10:06
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 169.148.95.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 169.148.95.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 12:09:57.740804 2026] [security2:error] [pid 2281557:tid 2281557] [client 169.148.95.94:54018] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 169.148.95.94 (+1 hits since last alert)|michaelkivisto.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "michaelkivisto.com"] [uri "/xmlrpc.php"] [unique_id "amTf1cvckPE-t5Bmo6wg4QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-07-25 14:22:37
(6 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 169.148.95.94 (SA/Saudi Arabia/-): 10 in the last 3600 se ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 169.148.95.94 (SA/Saudi Arabia/-): 10 in the last 3600 secs (0-201)
show less
Hacking
Anonymous
2026-07-24 18:08:31
(1 week ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=www.totzaki.gr; logs=/var/log/httpd/domains/totzaki.gr.log; ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=www.totzaki.gr; logs=/var/log/httpd/domains/totzaki.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
Anonymous
2026-07-24 13:25:13
(1 week ago)
[redacted] 169.148.95.94 - - [24/Jul/2026:15:24:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 169.148.95.94 - - [24/Jul/2026:15:24:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.1; http://site91293604.com"
[redacted] 169.148.95.94 - - [24/Jul/2026:15:24:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
[redacted] 169.148.95.94 - - [24/Jul/2026:15:24:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
[redacted] 169.148.95.94 - - [24/Jul/2026:15:25:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 169.148.95.94 - - [24/Jul/2026:15:25:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 07:44:59
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 169.148.95.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 169.148.95.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 03:44:52.973810 2026] [security2:error] [pid 1984057:tid 1984057] [client 169.148.95.94:57886] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 169.148.95.94 (+1 hits since last alert)|diegogamazo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "diegogamazo.com"] [uri "/xmlrpc.php"] [unique_id "amMX9PXNnC3lSjNsJ1NNZwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
konseptit
2026-07-24 07:44:06
(1 week ago)
(wordpress) Failed wordpress login from 169.148.95.94 (SA/Saudi Arabia/-)
Brute-Force
πͺπΈ
alferez
2026-07-23 16:57:23
(1 week ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-22 17:41:08
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 169.148.95.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 169.148.95.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 13:41:01.331998 2026] [security2:error] [pid 1564443:tid 1564443] [client 169.148.95.94:50453] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 169.148.95.94 (+1 hits since last alert)|fundaciondamashcc.org.ec|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fundaciondamashcc.org.ec"] [uri "/xmlrpc.php"] [unique_id "amEArZp-_PlBCiaxr2Y4cgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-22 17:00:15
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 169.148.95.94 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 169.148.95.94 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 13:00:06.730153 2026] [security2:error] [pid 393242:tid 393242] [client 169.148.95.94:52325] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 169.148.95.94 (+1 hits since last alert)|assheton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "assheton.com"] [uri "/xmlrpc.php"] [unique_id "amD3FttQZnm3iHsGRaCopAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack