Anonymous
2026-07-29 07:00:00
(2 days ago)
Apache probe; attempts=54; exact paths: /xmlrpc.php
Web App Attack
π±π»
garmtech.com
2026-07-23 05:20:08
(1 week ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
πΊπΈ
TAY
2026-07-23 00:47:28
(1 week ago)
39.34.46.194 - - [23/Jul/2026:08:47:07 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by W ...
show more
39.34.46.194 - - [23/Jul/2026:08:47:07 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack by WordPress.com"
39.34.46.194 - - [23/Jul/2026:08:47:17 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "WordPress.com; https://wordpress.com"
39.34.46.194 - - [23/Jul/2026:08:47:28 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
Anonymous
2026-07-23 00:47:18
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-23 00:16:31
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 20:16:23.414942 2026] [security2:error] [pid 1608074:tid 1608074] [client 39.34.46.194:64313] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.46.194 (+1 hits since last alert)|glassclublake.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "glassclublake.com"] [uri "/xmlrpc.php"] [unique_id "amFdV4J3Ce6OHeIMkd1m1gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-22 22:18:54
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 18:18:47.716634 2026] [security2:error] [pid 1587341:tid 1587341] [client 39.34.46.194:61970] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.46.194 (+1 hits since last alert)|proyectando.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "proyectando.com"] [uri "/xmlrpc.php"] [unique_id "amFBx41O9ZJ-YmOZ58h4dgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-22 20:10:58
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 16:10:55.125854 2026] [security2:error] [pid 3362849:tid 3362849] [client 39.34.46.194:49568] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.46.194 (+1 hits since last alert)|solucionesmercadeodigital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solucionesmercadeodigital.com"] [uri "/xmlrpc.php"] [unique_id "amEjz07QWjCYGDVUqqqq_AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
AWW-Admin
2026-05-19 06:26:34
(2 months ago)
(wordpress) Failed wordpress login from 39.34.46.194 (PK/Pakistan/-)
Brute-Force
πΊπΈ
TPI-Abuse
2026-05-19 00:00:50
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 20:00:44.677801 2026] [security2:error] [pid 12170:tid 12170] [client 39.34.46.194:55487] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.46.194 (+1 hits since last alert)|dupagekanewildliferemoval.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dupagekanewildliferemoval.com"] [uri "/xmlrpc.php"] [unique_id "aguoLCfuaj5oUrpi7VSUDgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-18 21:12:34
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 17:12:27.516963 2026] [security2:error] [pid 17004:tid 17004] [client 39.34.46.194:59369] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.46.194 (+1 hits since last alert)|wsffjatc.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wsffjatc.org"] [uri "/xmlrpc.php"] [unique_id "aguAuzlII89o4dFNk4q0PQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-18 16:16:40
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 12:16:37.545779 2026] [security2:error] [pid 32220:tid 32220] [client 39.34.46.194:57445] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.46.194 (+1 hits since last alert)|415test.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "415test.com"] [uri "/xmlrpc.php"] [unique_id "ags7ZYxZ_8aBUTko-8k55QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
rh24
2026-05-18 14:59:47
(2 months ago)
(xmlrpc_405) XMLRPC-Bot 405 39.34.46.194 (PK/Pakistan/-)
Hacking
πΊπΈ
TPI-Abuse
2026-05-18 14:34:33
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 10:34:30.184305 2026] [security2:error] [pid 22481:tid 22481] [client 39.34.46.194:53082] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.46.194 (+1 hits since last alert)|midcityrotary.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "midcityrotary.org"] [uri "/xmlrpc.php"] [unique_id "agsjdiOmMWG7iAQgijQXQgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-18 11:46:21
(2 months ago)
Attac
Brute-Force
πΊπΈ
TPI-Abuse
2026-05-18 11:17:51
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.46.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 07:17:43.622287 2026] [security2:error] [pid 31592:tid 31592] [client 39.34.46.194:63957] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.46.194 (+1 hits since last alert)|intrinsicdiscovery.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "intrinsicdiscovery.com"] [uri "/xmlrpc.php"] [unique_id "agr1V6hpyOm23GC1QVoAZQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack