๐ฉ๐ช
lenz
2026-06-05 14:23:05
(5 days ago)
Jun 5 16:18:01 hosting wordpress(grupa-ddd.pl)[1201]: XML-RPC authentication failure for admin from ...
show more
Jun 5 16:18:01 hosting wordpress(grupa-ddd.pl)[1201]: XML-RPC authentication failure for admin from 176.236.194.161
Jun 5 16:19:14 hosting wordpress(grupa-ddd.pl)[1204]: XML-RPC authentication failure for admin from 176.236.194.161
Jun 5 16:21:25 hosting wordpress(grupa-ddd.pl)[1203]: XML-RPC authentication failure for admin from 176.236.194.161
Jun 5 16:22:42 hosting wordpress(grupa-ddd.pl)[2270]: XML-RPC authentication failure for admin from 176.236.194.161
Jun 5 16:23:04 hosting wordpress(grupa-ddd.pl)[1200]: XML-RPC authentication failure for admin from 176.236.194.161
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-06-05 14:17:16
(5 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 14:04:20
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 10:04:12.248562 2026] [security2:error] [pid 9721:tid 9721] [client 176.236.194.161:61668] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 176.236.194.161 (+1 hits since last alert)|vzan.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vzan.org"] [uri "/xmlrpc.php"] [unique_id "aiLXXOrLUbeOtHxC82V8TAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-05 11:15:04
(5 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
Anonymous
2026-06-05 09:13:24
(5 days ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-05 06:50:28
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 02:50:21.403145 2026] [security2:error] [pid 26841:tid 26841] [client 176.236.194.161:61198] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 176.236.194.161 (+1 hits since last alert)|globalweb123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "globalweb123.com"] [uri "/xmlrpc.php"] [unique_id "aiJxrU2qtzBE9jZtuxQfKAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 01:28:42
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 21:28:38.672431 2026] [security2:error] [pid 25509:tid 25509] [client 176.236.194.161:61471] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 176.236.194.161 (+1 hits since last alert)|theyoungstrategist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "theyoungstrategist.com"] [uri "/xmlrpc.php"] [unique_id "aiImRgm2RDyJy5AT95QHDwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-06-05 00:38:57
(6 days ago)
176.236.194.161 - - [05/Jun/2026:08:37:16 +0800] "POST /xmlrpc.php HTTP/1.1" 200 4437 "-" "WordPress ...
show more
176.236.194.161 - - [05/Jun/2026:08:37:16 +0800] "POST /xmlrpc.php HTTP/1.1" 200 4437 "-" "WordPress.com; https://wordpress.com"
176.236.194.161 - - [05/Jun/2026:08:37:29 +0800] "POST /xmlrpc.php HTTP/1.1" 200 4437 "-" "Jetpack/12.5; WordPress/6.4; http://site29984250.com"
176.236.194.161 - - [05/Jun/2026:08:38:56 +0800] "POST /xmlrpc.php HTTP/1.1" 200 4437 "-" "Jetpack/12.5; WordPress/6.2; http://site69030737.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-04 15:08:05
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 11:08:00.262731 2026] [security2:error] [pid 6044:tid 6044] [client 176.236.194.161:61285] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 176.236.194.161 (+1 hits since last alert)|bradleybarefoot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bradleybarefoot.com"] [uri "/xmlrpc.php"] [unique_id "aiGU0NDZAa0BO6OKx66IwgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 14:01:50
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 10:01:46.073083 2026] [security2:error] [pid 22908:tid 22935] [client 176.236.194.161:61275] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 176.236.194.161 (+1 hits since last alert)|greaternorthmiamihistory.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "greaternorthmiamihistory.org"] [uri "/xmlrpc.php"] [unique_id "aiGFSjjGfrMuPIMOZFdfewAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-06-04 12:45:45
(6 days ago)
176.236.194.161 - [04/Jun/2026:15:45:39 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "Jetpack/12.1 ...
show more
176.236.194.161 - [04/Jun/2026:15:45:39 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "Jetpack/12.1; WordPress/6.1; http://site72087339.com" "-"
176.236.194.161 - [04/Jun/2026:15:45:45 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-06-04 12:30:02
(6 days ago)
176.236.194.161 - [04/Jun/2026:15:29:54 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "WordPress.co ...
show more
176.236.194.161 - [04/Jun/2026:15:29:54 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "WordPress.com; https://wordpress.com" "-"
176.236.194.161 - [04/Jun/2026:15:30:01 +0300] "POST /xmlrpc.php HTTP/1.1" 403 428 "-" "Jetpack/12.1; WordPress/6.2; http://site17757273.com" "-"
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 11:09:38
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 07:09:30.449481 2026] [security2:error] [pid 26512:tid 26512] [client 176.236.194.161:61506] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 176.236.194.161 (+1 hits since last alert)|toepferlab.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "toepferlab.org"] [uri "/xmlrpc.php"] [unique_id "aiFc6lG-8b_nbKpb4zyiNwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 04:48:49
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 176.236.194.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 00:48:45.833037 2026] [security2:error] [pid 9928:tid 9928] [client 176.236.194.161:61385] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 176.236.194.161 (+1 hits since last alert)|williamfitzsimmons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "williamfitzsimmons.com"] [uri "/xmlrpc.php"] [unique_id "aiEDrRdWL9cO5quqim8KYwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-06-04 03:00:20
(1 week ago)
176.236.194.161 - - [04/Jun/2026
...
Brute-Force