๐ช๐ธ
Gem
2026-06-05 22:10:00
(14 hours ago)
Unauthorized web scan.
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-06-04 22:58:54
(1 day ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
Anonymous
2026-06-04 21:49:40
(1 day ago)
"POST /wp/xmlrpc.php HTTP/1.1"
Hacking
Web App Attack
๐ฉ๐ช
findlab
2026-06-04 21:40:01
(1 day ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 21:00:33
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 20.51.61.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 20.51.61.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 17:00:28.662080 2026] [security2:error] [pid 18807:tid 18807] [client 20.51.61.16:42775] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 20.51.61.16 (+1 hits since last alert)|dylanwalsh.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dylanwalsh.net"] [uri "/wp/xmlrpc.php"] [unique_id "aiHnbFyc_eitvYJZjJfhogAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-06-04 20:50:00
(1 day ago)
IPBlock protected site ID [3390-wh].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-06-04 20:31:46
(1 day ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 20:10:38
(1 day ago)
20.51.61.16 - - [04/Jun/2026:20:10:37 +0000] "POST /wp/xmlrpc.php HTTP/1.1" 404 34282 "-" "Mozilla/5 ...
show more
20.51.61.16 - - [04/Jun/2026:20:10:37 +0000] "POST /wp/xmlrpc.php HTTP/1.1" 404 34282 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 19:27:08
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 20.51.61.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 20.51.61.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 15:27:04.728257 2026] [security2:error] [pid 8400:tid 8400] [client 20.51.61.16:42142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 20.51.61.16 (+1 hits since last alert)|capecodweddingideas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "capecodweddingideas.com"] [uri "/wp/xmlrpc.php"] [unique_id "aiHRiFi8qFF0gIhNqUjXtQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-06-04 19:22:39
(1 day ago)
Honeypot triggered on tcpdata.com - Attempted to access /wp/xmlrpc.php (wordpress_xmlrpc). User-Agen ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /wp/xmlrpc.php (wordpress_xmlrpc). User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
show less
Web App Attack
๐น๐ผ
tye
2026-06-04 19:21:04
(1 day ago)
Wazuh Alert Evidence: 20.51.61.16 (20.51.61.16) - - [05/Jun/2026:03:21:02 +0800] "POST /wp/xmlrpc.ph ...
show more
Wazuh Alert Evidence: 20.51.61.16 (20.51.61.16) - - [05/Jun/2026:03:21:02 +0800] "POST /wp/xmlrpc.php HTTP/1.1" 404 3522 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
dklueh79
2026-06-04 19:06:24
(1 day ago)
Probe for vulnerabilities. Path attempted: /wp/xmlrpc.php
Web App Attack
๐ง๐ท
Francisco Carlos
2026-06-04 18:47:59
(1 day ago)
Honeypot captured 1 automated attack/scan requests (JR Save Tech). Types: shell-upload, wordpress. S ...
show more
Honeypot captured 1 automated attack/scan requests (JR Save Tech). Types: shell-upload, wordpress. Sample: GET /wp/xmlrpc.php
show less
Hacking
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-04 18:45:56
(1 day ago)
[ThuJun0420:45:48.9407072026][security2:error][pid1297297:tid1297719][client20.51.61.16:0]ModSecurit ...
show more
[ThuJun0420:45:48.9407072026][security2:error][pid1297297:tid1297719][client20.51.61.16:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"367\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"facil-services.ch\"][uri\"/wp/xmlrpc.php\"][unique_id\"aiHH3CE4CjeZ93kpf5mwjQAAAFM\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 18:35:34
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 20.51.61.16 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 20.51.61.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 14:35:31.496530 2026] [security2:error] [pid 18794:tid 18794] [client 20.51.61.16:43734] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 20.51.61.16 (+1 hits since last alert)|alan-droege.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "alan-droege.com"] [uri "/wp/xmlrpc.php"] [unique_id "aiHFc3S4hyKhlh2bQ2zAPwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack