Anonymous
2026-07-29 07:00:00
(2 days ago)
Automated Apache web application probing in selected 24h window; attempts=148, unique_paths=1, error ...
show more
Automated Apache web application probing in selected 24h window; attempts=148, unique_paths=1, error_responses=142; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(2 days ago)
Apache probe; attempts=148; exact paths: /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 22:11:05
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 182.52.137.66 (node-r42.pool-182-52.dynamic.nt- ...
show more
(mod_security) mod_security (id:240335) triggered by 182.52.137.66 (node-r42.pool-182-52.dynamic.nt-isp.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 18:10:56.554229 2026] [security2:error] [pid 2897041:tid 2897041] [client 182.52.137.66:63422] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 182.52.137.66 (+1 hits since last alert)|esysapps.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "esysapps.com"] [uri "/xmlrpc.php"] [unique_id "amko8OIaqm1UsMMs0gliHwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-28 19:56:05
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ช๐ธ
alferez
2026-07-28 14:21:26
(3 days ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2026-07-28 13:18:18
(3 days ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.co ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)
show less
Brute-Force
Web App Attack
๐ฉ๐ช
rh24
2026-07-28 13:17:57
(3 days ago)
(xmlrpc_405) XMLRPC-Bot 405 182.52.137.66 (TH/Thailand/node-r42.pool-182-52.dynamic.nt-isp.net)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-28 12:51:22
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 182.52.137.66 (node-r42.pool-182-52.dynamic.nt- ...
show more
(mod_security) mod_security (id:240335) triggered by 182.52.137.66 (node-r42.pool-182-52.dynamic.nt-isp.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 08:51:17.499554 2026] [security2:error] [pid 404414:tid 404465] [client 182.52.137.66:49799] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 182.52.137.66 (+1 hits since last alert)|eceinal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eceinal.com"] [uri "/xmlrpc.php"] [unique_id "amilxQYn_xQaLXbW2A_2LwAAAYU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 10:48:58
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 182.52.137.66 (node-r42.pool-182-52.dynamic.nt- ...
show more
(mod_security) mod_security (id:240335) triggered by 182.52.137.66 (node-r42.pool-182-52.dynamic.nt-isp.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 06:48:53.913016 2026] [security2:error] [pid 1407083:tid 1407083] [client 182.52.137.66:59035] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 182.52.137.66 (+1 hits since last alert)|innovacionesnimba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "innovacionesnimba.com"] [uri "/xmlrpc.php"] [unique_id "amiJFfY8G0YwfAcZcqDfgQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 09:46:56
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 182.52.137.66 (node-r42.pool-182-52.dynamic.nt- ...
show more
(mod_security) mod_security (id:240335) triggered by 182.52.137.66 (node-r42.pool-182-52.dynamic.nt-isp.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 05:46:47.763173 2026] [security2:error] [pid 1140145:tid 1140145] [client 182.52.137.66:50717] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 182.52.137.66 (+1 hits since last alert)|fundaciondamashcc.org.ec|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fundaciondamashcc.org.ec"] [uri "/xmlrpc.php"] [unique_id "amh6h7602q_xHHLFSrnI5QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 05:59:04
(3 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-07-28 04:46:24
(3 days ago)
[redacted] 182.52.137.66 - - [28/Jul/2026:06:45:43 +0200] "POST /xmlrpc.php HTTP/1.1" 403 1682 "-" " ...
show more
[redacted] 182.52.137.66 - - [28/Jul/2026:06:45:43 +0200] "POST /xmlrpc.php HTTP/1.1" 403 1682 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 182.52.137.66 - - [28/Jul/2026:06:45:51 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Jetpack by WordPress.com"
[redacted] 182.52.137.66 - - [28/Jul/2026:06:46:01 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "WordPress.com; https://wordpress.com"
[redacted] 182.52.137.66 - - [28/Jul/2026:06:46:12 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Jetpack by WordPress.com"
[redacted] 182.52.137.66 - - [28/Jul/2026:06:46:23 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
jsjdmediallc
2026-07-28 01:20:05
(4 days ago)
Auto-blocked: score 511 (threshold 10). Tier: HIGH. Hits: 101. Flags: xmlrpc, xmlrpc-burst, single-p ...
show more
Auto-blocked: score 511 (threshold 10). Tier: HIGH. Hits: 101. Flags: xmlrpc, xmlrpc-burst, single-path-flood. Paths: /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php, /xmlrpc.php
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 00:31:52
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 182.52.137.66 (node-r42.pool-182-52.dynamic.nt- ...
show more
(mod_security) mod_security (id:240335) triggered by 182.52.137.66 (node-r42.pool-182-52.dynamic.nt-isp.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 20:31:43.184853 2026] [security2:error] [pid 80601:tid 80601] [client 182.52.137.66:59972] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 182.52.137.66 (+1 hits since last alert)|healthmarkcounseling.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "healthmarkcounseling.com"] [uri "/xmlrpc.php"] [unique_id "amf4b1XK-arkNARdONbnBwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-07-27 23:29:20
(4 days ago)
182.52.137.66 - - [28/Jul/2026:07:28:59 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by ...
show more
182.52.137.66 - - [28/Jul/2026:07:28:59 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com"
182.52.137.66 - - [28/Jul/2026:07:29:09 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com"
182.52.137.66 - - [28/Jul/2026:07:29:19 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force