π«π·
dynamix
2026-06-24 21:51:13
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
π«π·
Kenshin869
2026-06-24 17:04:50
(1 week ago)
Wordpress unauthorized access attempt
Brute-Force
Anonymous
2026-06-24 16:34:55
(1 week ago)
[redacted] 178.149.85.43 - - [24/Jun/2026:18:34:09 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 178.149.85.43 - - [24/Jun/2026:18:34:09 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
[redacted] 178.149.85.43 - - [24/Jun/2026:18:34:18 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
[redacted] 178.149.85.43 - - [24/Jun/2026:18:34:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 178.149.85.43 - - [24/Jun/2026:18:34:41 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 178.149.85.43 - - [24/Jun/2026:18:34:51 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-24 03:07:38
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 178.149.85.43 (cable-178-149-85-43.dynamic.sbb. ...
show more
(mod_security) mod_security (id:240335) triggered by 178.149.85.43 (cable-178-149-85-43.dynamic.sbb.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 23:07:31.669174 2026] [security2:error] [pid 15306:tid 15337] [client 178.149.85.43:64423] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.149.85.43 (+1 hits since last alert)|vinylnotespodcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vinylnotespodcast.com"] [uri "/xmlrpc.php"] [unique_id "ajtJ83eIWisvCEVXlaobOQAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-23 15:53:45
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 178.149.85.43 (cable-178-149-85-43.dynamic.sbb. ...
show more
(mod_security) mod_security (id:240335) triggered by 178.149.85.43 (cable-178-149-85-43.dynamic.sbb.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 11:53:38.588997 2026] [security2:error] [pid 15075:tid 15088] [client 178.149.85.43:55070] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.149.85.43 (+1 hits since last alert)|bortec-corp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bortec-corp.com"] [uri "/xmlrpc.php"] [unique_id "ajqsAq4ohyHdNrdmGUz0HQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-06-23 15:45:00
(1 week ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
π²πΎ
Rizzy
2026-06-23 05:13:52
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-06-23 05:13:47
(1 week ago)
[redacted] 178.149.85.43 - - [23/Jun/2026:07:13:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "J ...
show more
[redacted] 178.149.85.43 - - [23/Jun/2026:07:13:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 178.149.85.43 - - [23/Jun/2026:07:13:14 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
[redacted] 178.149.85.43 - - [23/Jun/2026:07:13:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
[redacted] 178.149.85.43 - - [23/Jun/2026:07:13:35 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/12.1; WordPress/6.1; http://site25969925.com"
[redacted] 178.149.85.43 - - [23/Jun/2026:07:13:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
π«π·
Yepngo
2026-06-23 04:11:20
(1 week ago)
178.149.85.43 - - [23/Jun/2026:06:11:09 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "WordPress.co ...
show more
178.149.85.43 - - [23/Jun/2026:06:11:09 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "WordPress.com; https://wordpress.com"
178.149.85.43 - - [23/Jun/2026:06:11:20 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-22 13:51:13
(1 week ago)
[redacted] 178.149.85.43 - - [22/Jun/2026:15:50:29 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "J ...
show more
[redacted] 178.149.85.43 - - [22/Jun/2026:15:50:29 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack/12.0; WordPress/6.1; http://site95355179.com"
[redacted] 178.149.85.43 - - [22/Jun/2026:15:50:38 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
[redacted] 178.149.85.43 - - [22/Jun/2026:15:50:49 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 178.149.85.43 - - [22/Jun/2026:15:51:00 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack/12.1; WordPress/6.2; http://site15670965.com"
[redacted] 178.149.85.43 - - [22/Jun/2026:15:51:11 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
π«π·
dynamix
2026-06-22 12:50:32
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-21 04:31:21
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 178.149.85.43 (cable-178-149-85-43.dynamic.sbb. ...
show more
(mod_security) mod_security (id:240335) triggered by 178.149.85.43 (cable-178-149-85-43.dynamic.sbb.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 00:31:14.910118 2026] [security2:error] [pid 16436:tid 16436] [client 178.149.85.43:58792] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.149.85.43 (+1 hits since last alert)|designingdestinynow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "designingdestinynow.com"] [uri "/xmlrpc.php"] [unique_id "ajdpEsQkhNGDOtd4hIlkNAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-21 04:28:27
(1 week ago)
[redacted] 178.149.85.43 - - [21/Jun/2026:06:27:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "W ...
show more
[redacted] 178.149.85.43 - - [21/Jun/2026:06:27:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 178.149.85.43 - - [21/Jun/2026:06:27:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
[redacted] 178.149.85.43 - - [21/Jun/2026:06:28:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 178.149.85.43 - - [21/Jun/2026:06:28:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 178.149.85.43 - - [21/Jun/2026:06:28:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
π©πͺ
4server
2026-06-20 15:44:06
(1 week ago)
[SatJun2017:44:03.7068262026][security2:error][pid3743230:tid3743249][client178.149.85.43:0]ModSecur ...
show more
[SatJun2017:44:03.7068262026][security2:error][pid3743230:tid3743249][client178.149.85.43:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"scrspace.com\"][uri\"/xmlrpc.php\"][unique_id\"aja1Q9gLbX_PKmzQP6is9AAAAJA\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-19 18:49:11
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 178.149.85.43 (cable-178-149-85-43.dynamic.sbb. ...
show more
(mod_security) mod_security (id:240335) triggered by 178.149.85.43 (cable-178-149-85-43.dynamic.sbb.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 14:49:03.897498 2026] [security2:error] [pid 29505:tid 29505] [client 178.149.85.43:61164] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.149.85.43 (+1 hits since last alert)|greatwesternfirearms.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "greatwesternfirearms.com"] [uri "/xmlrpc.php"] [unique_id "ajWPH9BnYMRa5M2dwcszBAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack