Anonymous
2026-05-12 23:49:02
(3 weeks ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-05-12 22:50:52
(3 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
BR/Brazil/192-140-64-69.wtdtelecom-ba.com.br
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-05-11 15:51:14
(3 weeks ago)
Unauthorized access to webpage admin
Web App Attack
๐ฌ๐ง
Apache
2026-05-11 10:38:20
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 192.140.64.69 (BR/Brazil/192-140-64-69.wtdtelec ...
show more
(mod_security) mod_security (id:240335) triggered by 192.140.64.69 (BR/Brazil/192-140-64-69.wtdtelecom-ba.com.br): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 10:05:40
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 192.140.64.69 (192-140-64-69.wtdtelecom-ba.com. ...
show more
(mod_security) mod_security (id:240335) triggered by 192.140.64.69 (192-140-64-69.wtdtelecom-ba.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 06:05:33.863379 2026] [security2:error] [pid 5916:tid 5916] [client 192.140.64.69:17324] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.140.64.69 (+1 hits since last alert)|anchor07.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "anchor07.com"] [uri "/xmlrpc.php"] [unique_id "agGp7WHF3T0EJqGyQnGFHAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 07:03:19
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 192.140.64.69 (192-140-64-69.wtdtelecom-ba.com. ...
show more
(mod_security) mod_security (id:240335) triggered by 192.140.64.69 (192-140-64-69.wtdtelecom-ba.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 03:03:15.459640 2026] [security2:error] [pid 27337:tid 27337] [client 192.140.64.69:17339] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.140.64.69 (+1 hits since last alert)|agworldmissions.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "agworldmissions.org"] [uri "/xmlrpc.php"] [unique_id "agF_M5Uw8-XH6nnJWQwLpQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-05-11 05:05:11
(3 weeks ago)
2.015 requests from abuseipdb.com blacklisted IP (6mos2w3d)
Brute-Force
Bad Web Bot
๐ฉ๐ช
konseptit
2026-05-10 19:10:43
(3 weeks ago)
(wordpress) Failed wordpress login from 192.140.64.69 (BR/Brazil/192-140-64-69.wtdtelecom-ba.com.br)
Brute-Force
๐ฉ๐ช
ger-stg-sifi1
2026-05-10 05:20:53
(3 weeks ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ท
dynamix
2026-05-09 19:55:30
(3 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-05-09 06:05:25
(3 weeks ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (59/60 min)'; Requests=59
Port Scan
๐จ๐ฆ
Paulo Henrique dos Santos Nichio
2026-05-09 01:15:24
(3 weeks ago)
(ls_brute) LiteSpeed Brute Force Attack 192.140.64.69 (BR/Brazil/192-140-64-69.wtdtelecom-ba.com.br) ...
show more
(ls_brute) LiteSpeed Brute Force Attack 192.140.64.69 (BR/Brazil/192-140-64-69.wtdtelecom-ba.com.br): 3 in the last 600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026-05-08 22:14:59.719935 [WARN] [2654647] [T0] [192.140.64.69:17448-28#APVH_www.institutorecomecar.org:443] Brute force detected for IP [192.140.64.69], throttle.
2026-05-08 22:15:10.715281 [WARN] [2654647] [T0] [192.140.64.69:17448-29#APVH_www.institutorecomecar.org:443] Brute force detected for IP [192.140.64.69], throttle.
2026-05-08 22:15:21.722416 [WARN] [2654647] [T0] [192.140.64.69:17448-30#APVH_www.institutorecomecar.org:443] Brute force detected for IP [192.140.64.69], throttle.
show less
Port Scan
๐บ๐ธ
NicoID
2026-05-09 00:14:12
(3 weeks ago)
192.140.64.69 - - [08/May/2026:02:00:51 -0600] "POST /xmlrpc.php HTTP/1.1" 200 4472 "-" "Jetpack by ...
show more
192.140.64.69 - - [08/May/2026:02:00:51 -0600] "POST /xmlrpc.php HTTP/1.1" 200 4472 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
Anonymous
2026-05-08 10:04:39
(4 weeks ago)
Fail2ban filtered
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-06 10:07:20
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 192.140.64.69 (192-140-64-69.wtdtelecom-ba.com. ...
show more
(mod_security) mod_security (id:240335) triggered by 192.140.64.69 (192-140-64-69.wtdtelecom-ba.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 06:07:16.905817 2026] [security2:error] [pid 27788:tid 27788] [client 192.140.64.69:17017] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.140.64.69 (+1 hits since last alert)|casapapayasanmiguel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "casapapayasanmiguel.com"] [uri "/xmlrpc.php"] [unique_id "afsS1BdXKl63HwcipnZYegAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack