π«π·
applemooz
2026-08-27 08:52:55
(23 hours ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
π©πͺ
abdubhai
2026-08-26 09:42:24
(1 day ago)
39.60.92.130 - - [26/Aug/2026:14
...
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-25 10:35:12
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 39.60.92.130 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.60.92.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:35:08.858947 2026] [security2:error] [pid 32702:tid 32702] [client 39.60.92.130:49882] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.60.92.130 (+1 hits since last alert)|gracebaptisthartsville.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gracebaptisthartsville.com"] [uri "/xmlrpc.php"] [unique_id "ao1v3HZfnJiT9D6QTvwCIQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 09:09:27
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 39.60.92.130 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.60.92.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:09:22.585248 2026] [security2:error] [pid 32063:tid 32063] [client 39.60.92.130:53598] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.60.92.130 (+1 hits since last alert)|aifactoid.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aifactoid.com"] [uri "/xmlrpc.php"] [unique_id "ao1bwg9pH-YpvVV1I0QOgQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-08-25 08:35:12
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
πΊπΈ
Lee Daniel
2026-08-21 12:02:55
(6 days ago)
[21/Aug/2026:08:02:11.614417 --0400] aog@Q5tBXP-t-77eYH7JWgAAAQk 39.60.92.130 57452 127.0.0.1 7081
[ ...
show more
[21/Aug/2026:08:02:11.614417 --0400] aog@Q5tBXP-t-77eYH7JWgAAAQk 39.60.92.130 57452 127.0.0.1 7081
[21/Aug/2026:08:02:22.501880 --0400] aog@Tvn@0F-egkXXeBFt8gAAAEM 39.60.92.130 39088 127.0.0.1 7081
[21/Aug/2026:08:02:33.399264 --0400] aog@WZtBXP-t-77eYH7J2gAAAQ4 39.60.92.130 47556 127.0.0.1 7081
[21/Aug/2026:08:02:44.483539 --0400] aog@ZJtBXP-t-77eYH7J@QAAAQw 39.60.92.130 57606 127.0.0.1 7081
[21/Aug/2026:08:02:55.342305 --0400] aog@b-n@0F-egkXXeBFuNAAAAEM 39.60.92.130 47932 127.0.0.1 7081
...
show less
DDoS Attack
Brute-Force
Anonymous
2026-08-19 17:35:52
(1 week ago)
39.60.92.130 - - [19/Aug/2026:19:35:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by Wo ...
show more
39.60.92.130 - - [19/Aug/2026:19:35:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
39.60.92.130 - - [19/Aug/2026:19:35:33 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
39.60.92.130 - - [19/Aug/2026:19:35:39 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12.1; WordPress/6.1; http://site85733942.com"
39.60.92.130 - - [19/Aug/2026:19:35:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12.1; WordPress/6.1; http://site85733942.com"
39.60.92.130 - - [19/Aug/2026:19:35:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
Web App Attack
π«π·
dynamix
2026-08-19 14:49:01
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
π«π·
dynamix
2026-08-18 14:44:47
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 14:17:42
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 39.60.92.130 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.60.92.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 10:17:36.055075 2026] [security2:error] [pid 26910:tid 26910] [client 39.60.92.130:60791] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.60.92.130 (+1 hits since last alert)|billwegener.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "billwegener.net"] [uri "/xmlrpc.php"] [unique_id "aoRpgAatN3Pp07fBRXxQgwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
integrantservices.com
2026-08-18 12:22:15
(1 week ago)
(wordpress) Failed wordpress login from 39.60.92.130 (PK/Pakistan/-)
Brute-Force
π©πͺ
ghostwarriors
2026-08-13 17:20:24
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FD-IX
2026-08-13 17:07:34
(2 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
π©πͺ
F242
2026-08-09 08:14:52
(2 weeks ago)
Wordpress Login or XMLRPC abuse
Web App Attack
π«π·
Lunix
2026-08-08 17:40:53
(2 weeks ago)
Brute-Force
Web App Attack