๐ซ๐ท
applemooz
2026-07-23 21:07:11
(1 day ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 20:37:57
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 177.8.130.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 177.8.130.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 16:37:50.904922 2026] [security2:error] [pid 3840037:tid 3840080] [client 177.8.130.160:58151] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 177.8.130.160 (+1 hits since last alert)|darrylrichards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "darrylrichards.com"] [uri "/xmlrpc.php"] [unique_id "amJ7nu5ULsXDPOPYL6AingAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-07-23 20:04:56
(1 day ago)
(xmlrpc_405) XMLRPC-Bot 405 177.8.130.160 (BR/Brazil/-)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-23 17:33:42
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 177.8.130.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 177.8.130.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 13:33:38.462819 2026] [security2:error] [pid 110626:tid 110626] [client 177.8.130.160:56681] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 177.8.130.160 (+1 hits since last alert)|owldreamllc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "owldreamllc.com"] [uri "/xmlrpc.php"] [unique_id "amJQckheUxnlugQ7FkQvzAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 15:40:59
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 177.8.130.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 177.8.130.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 11:40:55.383458 2026] [security2:error] [pid 2783002:tid 2783002] [client 177.8.130.160:57168] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 177.8.130.160 (+1 hits since last alert)|jesussotoca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jesussotoca.com"] [uri "/xmlrpc.php"] [unique_id "amI2BwaSZZD1SVjCL8DtRQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-07-23 15:00:33
(2 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐ช๐ธ
alferez
2026-07-22 13:45:28
(3 days ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 20:28:09
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 177.8.130.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 177.8.130.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 16:28:03.911365 2026] [security2:error] [pid 12919:tid 12919] [client 177.8.130.160:57368] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 177.8.130.160 (+1 hits since last alert)|georgegourmet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "georgegourmet.com"] [uri "/xmlrpc.php"] [unique_id "al_WU7FKZJf_nQGNCpJUoQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-21 20:27:18
(3 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
LRob
2026-07-21 18:54:11
(4 days ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.co ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)
show less
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-20 18:20:38
(5 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 18:19:01
(5 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
Anonymous
2026-07-20 14:01:30
(5 days ago)
[osotir.org] httpd-xmlrpc-post: sites=www.logosparakliseos.gr; logs=/var/log/httpd/domains/logospara ...
show more
[osotir.org] httpd-xmlrpc-post: sites=www.logosparakliseos.gr; logs=/var/log/httpd/domains/logosparakliseos.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ฌ๐ง
NotCool
2026-07-20 13:37:50
(5 days ago)
(XMLRPC) WP XMLPRC Attack 177.8.130.160 (BR/Brazil/-): 50 in the last 3600 secs
Web App Attack
๐บ๐ธ
WeekendWeb
2026-07-20 11:46:16
(5 days ago)
Wordpress Vunerability attack
Web App Attack