๐จ๐ฆ
polycoda
2026-08-24 02:49:31
(3 hours ago)
AutoBlock: ๐ WordPress Login Brute Force (20X or 30X) (Decay-Based)
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-08-23 22:49:49
(7 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
ID/Indonesia/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 14:59:07
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 36.69.83.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 36.69.83.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:58:51.158600 2026] [security2:error] [pid 15343:tid 15343] [client 36.69.83.19:59098] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.69.83.19 (+1 hits since last alert)|natickvillagerentals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "natickvillagerentals.com"] [uri "/xmlrpc.php"] [unique_id "aosKq_1iBVjBgi53V9m3-wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-08-23 11:07:13
(19 hours ago)
36.69.83.19 - - [23/Aug/2026:13:06:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6384 "-" "Jetpack/13.0; ...
show more
36.69.83.19 - - [23/Aug/2026:13:06:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6384 "-" "Jetpack/13.0; WordPress/6.4; http://site62029127.com"
36.69.83.19 - - [23/Aug/2026:13:07:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6384 "-" "Jetpack/12.1; WordPress/6.2; http://site14277183.com"
36.69.83.19 - - [23/Aug/2026:13:07:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6384 "-" "WordPress.com; https://wordpress.com"
show less
Hacking
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-08-23 10:51:47
(19 hours ago)
36.69.83.19 - - [23/Aug/2026:12:51:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6384 "-" "WordPress.com ...
show more
36.69.83.19 - - [23/Aug/2026:12:51:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6384 "-" "WordPress.com; https://wordpress.com"
36.69.83.19 - - [23/Aug/2026:12:51:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6384 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
36.69.83.19 - - [23/Aug/2026:12:51:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6384 "-" "Jetpack/13.0; WordPress/6.2; http://site80909303.com"
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-08-23 07:18:09
(22 hours ago)
(xmlrpc) Apache: Failed xmlrpc access from 36.69.83.19 (ID/Indonesia/-): 10 in the last 3600 secs (0 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 36.69.83.19 (ID/Indonesia/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐ฉ๐ช
dbmwebdesign
2026-08-23 06:50:13
(23 hours ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 04:26:14
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 36.69.83.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 36.69.83.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 00:26:01.861660 2026] [security2:error] [pid 31625:tid 31625] [client 36.69.83.19:53125] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.69.83.19 (+1 hits since last alert)|realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "realclean.net"] [uri "/xmlrpc.php"] [unique_id "aop2WQ7e3vSXS1kSLoP_ZAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 03:31:47
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 36.69.83.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 36.69.83.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 23:31:30.327079 2026] [security2:error] [pid 30047:tid 30047] [client 36.69.83.19:53324] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.69.83.19 (+1 hits since last alert)|varnadorefamily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "varnadorefamily.com"] [uri "/xmlrpc.php"] [unique_id "aoppkug130QSjkGJwnr6bAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-08-22 12:33:27
(1 day ago)
Wordpress Vunerability attack
Web App Attack
Anonymous
2026-08-22 11:01:03
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 09:32:33
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 36.69.83.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 36.69.83.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 05:32:21.556278 2026] [security2:error] [pid 457:tid 457] [client 36.69.83.19:49305] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.69.83.19 (+1 hits since last alert)|36sovereignchambers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "36sovereignchambers.com"] [uri "/xmlrpc.php"] [unique_id "aolspVhV5uyV9fhh2v9HLgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 05:25:29
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 36.69.83.19 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 36.69.83.19 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 01:25:20.152312 2026] [security2:error] [pid 2438:tid 2438] [client 36.69.83.19:53192] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.69.83.19 (+1 hits since last alert)|rwabutazafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rwabutazafoundation.org"] [uri "/xmlrpc.php"] [unique_id "aokywAa5nhOu5XZEt83pfgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-08-22 03:34:40
(2 days ago)
1.166 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
Anonymous
2026-08-22 02:42:28
(2 days ago)
(wordpress) Failed wordpress login from 36.69.83.19 (ID/Indonesia/-)
Brute-Force