๐ณ๐ฑ
Site.eu
2026-08-24 15:20:14
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ฎ
YF
2026-08-24 15:00:42
(1 day ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
brantknudson.org
2026-08-24 14:48:49
(1 day ago)
Request path 'POST /xmlrpc.php HTTP/1.1'
Web App Attack
Hacking
๐ซ๐ท
dwmp
2026-08-23 15:26:55
(2 days ago)
WordPress login Brute-Force
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-23 13:20:16
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-08-23 12:28:16
(2 days ago)
(xmlrpc_405) XMLRPC-Bot 405 43.241.65.106 (IN/India/106.65.241.43-in-addr.arpa-mithriltele.net)
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-23 05:20:32
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 43.241.65.106 (106.65.241.43-in-addr.arpa-mithr ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.65.106 (106.65.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:20:27.404030 2026] [security2:error] [pid 31021:tid 31021] [client 43.241.65.106:50058] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.65.106 (+1 hits since last alert)|k2servicesinc.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "k2servicesinc.net"] [uri "/xmlrpc.php"] [unique_id "aoqDG7KBgnPZR0kwmufS-wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 04:25:36
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 43.241.65.106 (106.65.241.43-in-addr.arpa-mithr ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.65.106 (106.65.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 00:25:29.074534 2026] [security2:error] [pid 13700:tid 13700] [client 43.241.65.106:51297] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.65.106 (+1 hits since last alert)|schlegelcreative.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "schlegelcreative.com"] [uri "/xmlrpc.php"] [unique_id "aop2OZrGo99g3KL9OqgN5wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 04:25:31
(3 days ago)
43.241.65.106 - - [23/Aug/2026:06:24:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418
43.241.65.106 - - ...
show more
43.241.65.106 - - [23/Aug/2026:06:24:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418
43.241.65.106 - - [23/Aug/2026:06:25:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418
...
show less
Brute-Force
Bad Web Bot
Anonymous
2026-08-21 15:14:53
(4 days ago)
43.241.65.106 - - [21/Aug/2026:17:14:48 +0200] "POST /xmlrpc.php HTTP/1.1" 302 -
43.241.65.106 - - [ ...
show more
43.241.65.106 - - [21/Aug/2026:17:14:48 +0200] "POST /xmlrpc.php HTTP/1.1" 302 -
43.241.65.106 - - [21/Aug/2026:17:14:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418
...
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-16 12:54:32
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 43.241.65.106 (106.65.241.43-in-addr.arpa-mithr ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.65.106 (106.65.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 08:54:25.807908 2026] [security2:error] [pid 30359:tid 30370] [client 43.241.65.106:50744] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.65.106 (+1 hits since last alert)|gabegabel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gabegabel.com"] [uri "/xmlrpc.php"] [unique_id "aoGzAYPMIOOcAett23I7cwAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-16 08:46:49
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-14 14:54:42
(1 week ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-08-14 14:11:57
(1 week ago)
[redacted] 43.241.65.106 - - [14/Aug/2026:16:11:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "W ...
show more
[redacted] 43.241.65.106 - - [14/Aug/2026:16:11:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 43.241.65.106 - - [14/Aug/2026:16:11:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 43.241.65.106 - - [14/Aug/2026:16:11:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 43.241.65.106 - - [14/Aug/2026:16:11:24 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 43.241.65.106 - - [14/Aug/2026:16:11:34 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 43.241.65.106 - - [14/Aug/2026:16:11:35 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack/13.0; WordPress/6.1; http://site53054583.com"
[redacted] 43.241.65.106 - - [14/Aug/2026:16:11:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 12:27:19
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 43.241.65.106 (106.65.241.43-in-addr.arpa-mithr ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.65.106 (106.65.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 08:27:12.650135 2026] [security2:error] [pid 10929:tid 10929] [client 43.241.65.106:50999] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.65.106 (+1 hits since last alert)|handankoc.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "handankoc.net"] [uri "/xmlrpc.php"] [unique_id "an8JoKUgxtYlD4rh52mSgAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack