๐ซ๐ท
dynamix
2026-07-27 11:36:44
(13 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 10:56:48
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 06:56:43.126116 2026] [security2:error] [pid 3554304:tid 3554304] [client 180.191.98.236:59804] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.236 (+1 hits since last alert)|wildlandconservancy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wildlandconservancy.com"] [uri "/xmlrpc.php"] [unique_id "amNE6-ZMUTsL5hkCjyRv0wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-07-24 10:00:46
(3 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐ฉ๐ช
Elygor77
2026-07-24 06:52:03
(3 days ago)
WordPress xmlrpc.php brute-force: 21 malicious requests observed (auto-report via server-monitor).
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 07:00:29
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 03:00:22.618177 2026] [security2:error] [pid 1209137:tid 1209137] [client 180.191.98.236:52586] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.236 (+1 hits since last alert)|roguetechink.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "roguetechink.com"] [uri "/xmlrpc.php"] [unique_id "amBqhhYwF-bq6gouNn03nAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-22 04:16:38
(5 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 03:10:58
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 23:10:54.043733 2026] [security2:error] [pid 792674:tid 792674] [client 180.191.98.236:64408] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.236 (+1 hits since last alert)|ritterlien.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ritterlien.com"] [uri "/xmlrpc.php"] [unique_id "amA0vp5SBm3m3KaxFVMLBwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-22 00:56:14
(5 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐ฉ๐ช
rh24
2026-07-22 00:34:19
(6 days ago)
(xmlrpc_405) XMLRPC-Bot 405 180.191.98.236 (PH/Philippines/-)
Hacking
Anonymous
2026-07-19 11:26:22
(1 week ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=www.pidalio.gr; logs=/var/log/httpd/domains/pidalio.gr.log; ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=www.pidalio.gr; logs=/var/log/httpd/domains/pidalio.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-19 09:13:23
(1 week ago)
180.191.98.236 - - [19/Jul/2026:05:12:27 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress. ...
show more
180.191.98.236 - - [19/Jul/2026:05:12:27 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
180.191.98.236 - - [19/Jul/2026:05:12:38 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
180.191.98.236 - - [19/Jul/2026:05:13:00 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
180.191.98.236 - - [19/Jul/2026:05:13:11 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
180.191.98.236 - - [19/Jul/2026:05:13:22 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 07:51:04
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 03:50:58.336562 2026] [security2:error] [pid 27082:tid 27082] [client 180.191.98.236:50376] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.236 (+1 hits since last alert)|k2servicesinc.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "k2servicesinc.net"] [uri "/xmlrpc.php"] [unique_id "alyB4itthiOg1fw6-kOgpAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 04:44:24
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 00:44:18.620997 2026] [security2:error] [pid 18114:tid 18114] [client 180.191.98.236:49671] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.236 (+1 hits since last alert)|talentstar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "talentstar.com"] [uri "/xmlrpc.php"] [unique_id "alxWIuSb233fWJH-dKaZXwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-19 04:34:10
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 03:17:25
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 180.191.98.236 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 23:17:17.573443 2026] [security2:error] [pid 6776:tid 6776] [client 180.191.98.236:8797] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 180.191.98.236 (+1 hits since last alert)|casadelsolmexico.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "casadelsolmexico.net"] [uri "/xmlrpc.php"] [unique_id "alxBvUT7_0gP7-GsmHfZkgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack