Anonymous
2026-06-23 13:40:54
(2 days ago)
[redacted] 179.159.208.168 - - [23/Jun/2026:15:40:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" ...
show more
[redacted] 179.159.208.168 - - [23/Jun/2026:15:40:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 179.159.208.168 - - [23/Jun/2026:15:40:22 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
[redacted] 179.159.208.168 - - [23/Jun/2026:15:40:32 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 179.159.208.168 - - [23/Jun/2026:15:40:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
[redacted] 179.159.208.168 - - [23/Jun/2026:15:40:53 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/12.1; WordPress/6.3; http://site23016301.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-20 13:07:01
(5 days ago)
[redacted] 179.159.208.168 - - [20/Jun/2026:15:06:18 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 179.159.208.168 - - [20/Jun/2026:15:06:18 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.4; http://site76484177.com"
[redacted] 179.159.208.168 - - [20/Jun/2026:15:06:28 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 179.159.208.168 - - [20/Jun/2026:15:06:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
[redacted] 179.159.208.168 - - [20/Jun/2026:15:06:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.3; http://site57419287.com"
[redacted] 179.159.208.168 - - [20/Jun/2026:15:07:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-06-20 12:36:11
(5 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-06-20 11:55:31
(5 days ago)
[ssd1.kdns.gr] httpd-xmlrpc-post: sites=nbmedical.gr; logs=/var/log/httpd/domains/nbmedical.gr.log; ...
show more
[ssd1.kdns.gr] httpd-xmlrpc-post: sites=nbmedical.gr; logs=/var/log/httpd/domains/nbmedical.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐จ๐ฆ
Dunham Support
2026-06-18 17:38:33
(6 days ago)
(wordpress) Failed wordpress login from 179.159.208.168 (BR/Brazil/b39fd0a8.virtua.com.br)
Brute-Force
Anonymous
2026-06-18 14:50:08
(1 week ago)
[redacted] 179.159.208.168 - - [18/Jun/2026:16:49:24 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 179.159.208.168 - - [18/Jun/2026:16:49:24 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 179.159.208.168 - - [18/Jun/2026:16:49:35 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 179.159.208.168 - - [18/Jun/2026:16:49:45 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 179.159.208.168 - - [18/Jun/2026:16:49:56 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 179.159.208.168 - - [18/Jun/2026:16:50:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-16 19:25:09
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 16:32:23
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 179.159.208.168 (b39fd0a8.virtua.com.br): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 179.159.208.168 (b39fd0a8.virtua.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 12:32:15.081955 2026] [security2:error] [pid 16639:tid 16639] [client 179.159.208.168:52626] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 179.159.208.168 (+1 hits since last alert)|roguetechtalks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "roguetechtalks.com"] [uri "/xmlrpc.php"] [unique_id "aiGoj4Vjj5-f3drXfU1dCQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-04 14:59:26
(3 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-06-04 14:58:29
(3 weeks ago)
179.159.208.168 - - [04/Jun/2026:16:58:08 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12 ...
show more
179.159.208.168 - - [04/Jun/2026:16:58:08 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12.5; WordPress/6.1; http://site97093959.com"
179.159.208.168 - - [04/Jun/2026:16:58:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12.5; WordPress/6.1; http://site97093959.com"
179.159.208.168 - - [04/Jun/2026:16:58:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12.1; WordPress/6.2; http://site80618300.com"
179.159.208.168 - - [04/Jun/2026:16:58:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12.1; WordPress/6.2; http://site80618300.com"
179.159.208.168 - - [04/Jun/2026:16:58:27 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 13:18:09
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 179.159.208.168 (b39fd0a8.virtua.com.br): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 179.159.208.168 (b39fd0a8.virtua.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 09:18:02.500854 2026] [security2:error] [pid 19787:tid 19787] [client 179.159.208.168:53149] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 179.159.208.168 (+1 hits since last alert)|abcollie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abcollie.com"] [uri "/xmlrpc.php"] [unique_id "aiF7CrzBOim8Sj4pYY4uHAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 16:30:11
(3 weeks ago)
[ns65.kdns.gr] httpd-xmlrpc-post: sites=villafleria.gr; logs=/var/log/httpd/domains/villafleria.gr.l ...
show more
[ns65.kdns.gr] httpd-xmlrpc-post: sites=villafleria.gr; logs=/var/log/httpd/domains/villafleria.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-03 15:25:57
(3 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
BR/Brazil/b39fd0a8.virtua.com.br
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 13:26:18
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 179.159.208.168 (b39fd0a8.virtua.com.br): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 179.159.208.168 (b39fd0a8.virtua.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 09:26:11.799724 2026] [security2:error] [pid 30386:tid 30386] [client 179.159.208.168:63847] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 179.159.208.168 (+1 hits since last alert)|innovacionesnimba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "innovacionesnimba.com"] [uri "/xmlrpc.php"] [unique_id "aiArc3uBi2Wa5oaIZPC0awAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 11:52:23
(3 weeks ago)
Attac
Brute-Force