Anonymous
2026-06-12 16:01:16
(1 day ago)
[redacted] 196.130.80.44 - - [12/Jun/2026:18:00:33 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 196.130.80.44 - - [12/Jun/2026:18:00:33 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 196.130.80.44 - - [12/Jun/2026:18:00:43 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.2; http://site98313162.com"
[redacted] 196.130.80.44 - - [12/Jun/2026:18:00:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
[redacted] 196.130.80.44 - - [12/Jun/2026:18:01:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
[redacted] 196.130.80.44 - - [12/Jun/2026:18:01:15 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-12 15:30:31
(1 day ago)
[redacted] 196.130.80.44 - - [12/Jun/2026:17:29:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "W ...
show more
[redacted] 196.130.80.44 - - [12/Jun/2026:17:29:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 196.130.80.44 - - [12/Jun/2026:17:29:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
[redacted] 196.130.80.44 - - [12/Jun/2026:17:30:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.4; http://site72888235.com"
[redacted] 196.130.80.44 - - [12/Jun/2026:17:30:19 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.1; http://site65676744.com"
[redacted] 196.130.80.44 - - [12/Jun/2026:17:30:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-12 15:00:56
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 196.130.80.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.130.80.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 11:00:50.651881 2026] [security2:error] [pid 1400:tid 1400] [client 196.130.80.44:57817] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.130.80.44 (+1 hits since last alert)|xyncom.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "xyncom.com"] [uri "/xmlrpc.php"] [unique_id "aiwfIuJlOlQgn4hWkHbdqgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
rh24
2026-06-12 14:28:13
(1 day ago)
(xmlrpc_405) XMLRPC-Bot 405 196.130.80.44 (EG/Egypt/-)
Hacking
πΊπΈ
TPI-Abuse
2026-06-12 12:58:07
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 196.130.80.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.130.80.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 08:58:03.459201 2026] [security2:error] [pid 4668:tid 4668] [client 196.130.80.44:52870] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.130.80.44 (+1 hits since last alert)|desdier.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "desdier.com"] [uri "/xmlrpc.php"] [unique_id "aiwCW1dYp1vXe4-jPZstygAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-06-11 21:05:06
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-11 20:07:19
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 196.130.80.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.130.80.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 16:07:11.808647 2026] [security2:error] [pid 26557:tid 26557] [client 196.130.80.44:56414] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.130.80.44 (+1 hits since last alert)|avvmarchetticollini.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "avvmarchetticollini.it"] [uri "/xmlrpc.php"] [unique_id "aisVb-gtd8Rd0X3rYEmp_AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 21:14:53
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 196.130.80.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.130.80.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 17:14:48.871031 2026] [security2:error] [pid 6048:tid 6048] [client 196.130.80.44:53890] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.130.80.44 (+1 hits since last alert)|tracytappan.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tracytappan.net"] [uri "/xmlrpc.php"] [unique_id "ainTyJ8r2uQwJIrPYN169wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 15:12:22
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 196.130.80.44 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 196.130.80.44 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:12:14.270570 2026] [security2:error] [pid 4985:tid 4985] [client 196.130.80.44:59964] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 196.130.80.44 (+1 hits since last alert)|yogawithbubba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yogawithbubba.com"] [uri "/xmlrpc.php"] [unique_id "aigtTogZoWQNXgCvtrVq6QAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 14:06:05
(4 days ago)
Trying to access config files
Web App Attack