πΊπΈ
TPI-Abuse
2026-06-12 18:53:56
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 188.71.207.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 188.71.207.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 14:53:48.229753 2026] [security2:error] [pid 31242:tid 31242] [client 188.71.207.96:20353] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 188.71.207.96 (+1 hits since last alert)|warpedweed.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "warpedweed.com"] [uri "/xmlrpc.php"] [unique_id "aixVvAA_qaJCF5jD3xRg6AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-12 18:41:09
(10 hours ago)
188.71.207.96 - - [12/Jun/2026:20:40:48 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by W ...
show more
188.71.207.96 - - [12/Jun/2026:20:40:48 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
188.71.207.96 - - [12/Jun/2026:20:40:47 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
188.71.207.96 - - [12/Jun/2026:20:40:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
188.71.207.96 - - [12/Jun/2026:20:40:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
188.71.207.96 - - [12/Jun/2026:20:41:07 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
Web App Attack
π«π·
Lunix
2026-06-12 18:05:58
(10 hours ago)
Brute-Force
Web App Attack
π«π·
dynamix
2026-06-12 11:12:20
(17 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
WeekendWeb
2026-06-12 11:11:43
(17 hours ago)
Wordpress Vunerability attack
Web App Attack
π«π·
dynamix
2026-06-11 09:48:57
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-06-11 07:49:01
(1 day ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=hparxo.gr; logs=/var/log/httpd/domains/hparxo.gr.log; sample ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=hparxo.gr; logs=/var/log/httpd/domains/hparxo.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-11 05:12:39
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 188.71.207.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 188.71.207.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 01:12:32.188536 2026] [security2:error] [pid 8245:tid 8245] [client 188.71.207.96:57045] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 188.71.207.96 (+1 hits since last alert)|cathybermanmft.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cathybermanmft.com"] [uri "/xmlrpc.php"] [unique_id "aipDwBWgUs4reAvWyjc3JQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 15:34:01
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 188.71.207.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 188.71.207.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 11:33:57.125670 2026] [security2:error] [pid 32055:tid 32055] [client 188.71.207.96:50288] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 188.71.207.96 (+1 hits since last alert)|savingspools.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "savingspools.com"] [uri "/xmlrpc.php"] [unique_id "aimD5XLE_svlDvSpfBc4YgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 12:28:58
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 188.71.207.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 188.71.207.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 08:28:55.171402 2026] [security2:error] [pid 26155:tid 26155] [client 188.71.207.96:15688] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 188.71.207.96 (+1 hits since last alert)|timetemple.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "timetemple.org"] [uri "/xmlrpc.php"] [unique_id "ailYh1eGu4qfnEJe1kTZ5wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ger-stg-sifi1
2026-06-10 10:03:37
(2 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-21 16:16:20
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 188.71.207.96 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 188.71.207.96 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 12:16:12.511904 2026] [security2:error] [pid 32474:tid 32474] [client 188.71.207.96:61328] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 188.71.207.96 (+1 hits since last alert)|honigcpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "honigcpa.com"] [uri "/xmlrpc.php"] [unique_id "ag8vzL6UbfmNsD4ufSlOVQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-21 13:00:11
(3 weeks ago)
Attac
Brute-Force
π¦πΊ
screwlooseit.com.au
2026-05-19 15:26:08
(3 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
KW/Kuwait/-
Web App Attack
π³π±
Site.eu
2026-05-19 14:13:22
(3 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH