🇩🇪
FD-IX
2026-08-07 10:07:13
(4 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 09:26:01
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 05:25:53.751508 2026] [security2:error] [pid 1891752:tid 1891752] [client 175.45.29.5:59524] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||deolu.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "deolu.org"] [uri "/wp-json/wp/v2/users"] [unique_id "anWkoVzgwwGaY8Nd4oLXsAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-07 08:47:14
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:47:07.230473 2026] [security2:error] [pid 2729255:tid 2729255] [client 175.45.29.5:49865] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 175.45.29.5 (+1 hits since last alert)|owldreamllc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "owldreamllc.com"] [uri "/xmlrpc.php"] [unique_id "anWbiyUnJFzDCiisRVG8BgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-06 03:27:50
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 23:27:41.746330 2026] [security2:error] [pid 23842:tid 23842] [client 175.45.29.5:54298] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 175.45.29.5 (+1 hits since last alert)|stinsonbeachsurfandkayak.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "stinsonbeachsurfandkayak.com"] [uri "/xmlrpc.php"] [unique_id "anP_LYbNuvx0l3bj8Rd0JwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-08-06 03:26:18
(4 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-08-06 01:54:27
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 21:54:19.278664 2026] [security2:error] [pid 1725240:tid 1725240] [client 175.45.29.5:58110] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 175.45.29.5 (+1 hits since last alert)|rimaine.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rimaine.org"] [uri "/xmlrpc.php"] [unique_id "anPpSzcfAK6FUitJaeT4VwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-08-04 09:08:26
(1 month ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
HK/Hong Kong/-
Web App Attack
🇺🇸
WeekendWeb
2026-08-04 09:08:16
(1 month ago)
Wordpress Vunerability attack
Web App Attack
🇩🇪
Marc
2026-08-04 03:48:33
(1 month ago)
175.45.29.5 - - [04/Aug/2026:05:48:11 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4840 "-" "Jetpack by Wo ...
show more
175.45.29.5 - - [04/Aug/2026:05:48:11 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4840 "-" "Jetpack by WordPress.com" 175.45.29.5 - - [04/Aug/2026:05:48:21 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4842 "-" "Jetpack by WordPress.com" 175.45.29.5 - - [04/Aug/2026:05:48:32 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4841 "-" "Jetpack/12.5; WordPress/6.4; http://site82519904.com"
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-03 09:56:05
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 05:55:56.882188 2026] [security2:error] [pid 3837035:tid 3837035] [client 175.45.29.5:60727] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 175.45.29.5 (+1 hits since last alert)|thehealthyplaceclayton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thehealthyplaceclayton.com"] [uri "/xmlrpc.php"] [unique_id "anBlrB7HiDGMDJkswD3iZgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-08-03 04:51:42
(1 month ago)
Probing websites for vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-08-02 18:31:36
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 02 14:31:29.089002 2026] [security2:error] [pid 22869:tid 22869] [client 175.45.29.5:59644] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 175.45.29.5 (+1 hits since last alert)|lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lysedzija.com"] [uri "/xmlrpc.php"] [unique_id "am-NAQbDsBNFy-oJpvjD4AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-07-27 07:55:28
(1 month ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 07:19:24
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 175.45.29.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 03:19:15.277624 2026] [security2:error] [pid 100723:tid 100723] [client 175.45.29.5:58514] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 175.45.29.5 (+1 hits since last alert)|gracebaptisthartsville.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gracebaptisthartsville.com"] [uri "/xmlrpc.php"] [unique_id "amcGc7l61Gknt54NgVifRQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-07-27 07:15:02
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack