Anonymous
2026-06-26 03:48:18
(7 hours ago)
Fail2Ban WordPress login brute-force detected
Brute-Force
Web App Attack
Anonymous
2026-06-25 18:15:55
(16 hours ago)
39.61.45.3 - - [25/Jun/2026:20:15:33 +0200] "POST /xmlrpc.php HTTP/1.1" 200 798 "-" "Jetpack by Word ...
show more
39.61.45.3 - - [25/Jun/2026:20:15:33 +0200] "POST /xmlrpc.php HTTP/1.1" 200 798 "-" "Jetpack by WordPress.com"
39.61.45.3 - - [25/Jun/2026:20:15:34 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
39.61.45.3 - - [25/Jun/2026:20:15:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 798 "-" "Jetpack/12.5; WordPress/6.4; http://site94769032.com"
39.61.45.3 - - [25/Jun/2026:20:15:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12.5; WordPress/6.4; http://site94769032.com"
39.61.45.3 - - [25/Jun/2026:20:15:53 +0200] "POST /xmlrpc.php HTTP/1.1" 200 798 "-" "Jetpack/13.0; WordPress/6.2; http://site88518391.com"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 11:59:50
(23 hours ago)
(mod_security) mod_security (id:240335) triggered by 39.61.45.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 39.61.45.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 07:59:45.031751 2026] [security2:error] [pid 3377:tid 3377] [client 39.61.45.3:43715] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.61.45.3 (+1 hits since last alert)|fishleadership.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fishleadership.org"] [uri "/xmlrpc.php"] [unique_id "aj0YMWD4iNIXPF2ZDVKEygAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-23 17:29:10
(2 days ago)
Attac
Brute-Force
Anonymous
2026-06-22 15:06:06
(3 days ago)
Trying to access config files
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-21 13:49:10
(4 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
PK/Pakistan/-
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-21 12:50:41
(4 days ago)
(wordpress) Failed wordpress login from 39.61.45.3 (PK/Pakistan/-)
Brute-Force
Anonymous
2026-06-21 10:06:04
(5 days ago)
Trying to access config files
Web App Attack
๐ฉ๐ช
rh24
2026-06-20 18:16:12
(5 days ago)
(wordpress) Failed wordpress login from 39.61.45.3 (PK/Pakistan/-): (CF_ENABLE)
Brute-Force
๐ซ๐ท
dynamix
2026-06-20 15:49:02
(5 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 15:45:27
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 39.61.45.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 39.61.45.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 11:45:23.566482 2026] [security2:error] [pid 32176:tid 32176] [client 39.61.45.3:57957] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.61.45.3 (+1 hits since last alert)|geodogs.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "geodogs.org"] [uri "/xmlrpc.php"] [unique_id "ai7Mk4sbcBhzngjnLIdYnQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-14 04:10:48
(1 week ago)
(wordpress) Failed wordpress login from 39.61.45.3 (PK/Pakistan/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-13 16:37:14
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 39.61.45.3 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 39.61.45.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 12:37:10.054198 2026] [security2:error] [pid 25066:tid 25073] [client 39.61.45.3:27587] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.61.45.3 (+1 hits since last alert)|sparkhypnotherapy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sparkhypnotherapy.com"] [uri "/xmlrpc.php"] [unique_id "ai2HNkiub_G8VJ20s8DBNgAAAMM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-16 11:02:40
(1 month ago)
Attac
Brute-Force
๐บ๐ธ
Jason Howell
2026-05-11 16:47:31
(1 month ago)
39.61.45.3 - - [11/May/2026:11:44:48 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2969 "-" "Jetpack by Wor ...
show more
39.61.45.3 - - [11/May/2026:11:44:48 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2969 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
39.61.45.3 - - [11/May/2026:11:45:20 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2969 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
39.61.45.3 - - [11/May/2026:11:46:25 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2968 "-" "Jetpack/12.0; WordPress/6.1; http://site28123582.com"
39.61.45.3 - - [11/May/2026:11:46:58 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2970 "-" "Jetpack by WordPress.com"
39.61.45.3 - - [11/May/2026:11:47:30 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2969 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
...
show less
Web App Attack