๐บ๐ธ
gui-ying233
2026-08-22 18:08:22
(1 day ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-12 18:36:50
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 14:36:46.216991 2026] [security2:error] [pid 2175778:tid 2175778] [client 45.118.159.201:48454] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.118.159.201 (+1 hits since last alert)|redlitephotos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "redlitephotos.com"] [uri "/xmlrpc.php"] [unique_id "alPevnftqmT0eQlKQHqMmAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-12 18:18:48
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 14:18:43.174050 2026] [security2:error] [pid 28255:tid 28255] [client 45.118.159.201:47534] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.118.159.201 (+1 hits since last alert)|avalderlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "avalderlaw.com"] [uri "/xmlrpc.php"] [unique_id "alPag1aOeuK3_Ugn55qDsQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
n2nguyenn2nguyen
2026-07-12 17:30:50
(1 month ago)
Blocked by YFC Security on https://brixzly.com โ type: xmlrpc_attempts
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 09:07:05
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 05:06:58.038517 2026] [security2:error] [pid 28074:tid 28074] [client 45.118.159.201:48004] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.118.159.201 (+1 hits since last alert)|naturalhomebuilders.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "naturalhomebuilders.com"] [uri "/xmlrpc.php"] [unique_id "alIHsqHoM-_74vJXF2AmPwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-07-11 07:59:16
(1 month ago)
45.118.159.201 - - [11/Jul/2026:09:58:54 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3419 "-" "Jetpack/13 ...
show more
45.118.159.201 - - [11/Jul/2026:09:58:54 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3419 "-" "Jetpack/13.0; WordPress/6.4; http://site66129079.com" 45.118.159.201 - - [11/Jul/2026:09:59:05 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3466 "-" "Jetpack by WordPress.com" 45.118.159.201 - - [11/Jul/2026:09:59:15 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3465 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 18:58:49
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 14:58:42.647607 2026] [security2:error] [pid 3060:tid 3060] [client 45.118.159.201:47607] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.118.159.201 (+1 hits since last alert)|georgesmarina.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "georgesmarina.com"] [uri "/xmlrpc.php"] [unique_id "alFA4vE8VKvGz1J4OBo-aAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-05-20 13:44:26
(3 months ago)
(wordpress) Failed wordpress login from 45.118.159.201 (IN/India/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-20 09:01:21
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 05:01:14.601797 2026] [security2:error] [pid 6851:tid 6851] [client 45.118.159.201:34210] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.118.159.201 (+1 hits since last alert)|modalguitarist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "modalguitarist.com"] [uri "/xmlrpc.php"] [unique_id "ag14WlTxtMj7j1UviQawYQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-05-20 06:25:24
(3 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
Jason Howell
2026-05-20 04:59:29
(3 months ago)
45.118.159.201 - - [19/May/2026:23:58:46 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2999 "-" "Jetpack by ...
show more
45.118.159.201 - - [19/May/2026:23:58:46 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2999 "-" "Jetpack by WordPress.com"
45.118.159.201 - - [19/May/2026:23:58:56 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2997 "-" "Jetpack/12.1; WordPress/6.1; http://site84903288.com"
45.118.159.201 - - [19/May/2026:23:59:07 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2999 "-" "Jetpack by WordPress.com"
45.118.159.201 - - [19/May/2026:23:59:17 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2997 "-" "WordPress.com; https://wordpress.com"
45.118.159.201 - - [19/May/2026:23:59:28 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2997 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ซ๐ท
Kenshin869
2026-05-19 15:45:23
(3 months ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-19 15:22:01
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.118.159.201 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 11:21:57.199057 2026] [security2:error] [pid 13048:tid 13048] [client 45.118.159.201:34427] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.118.159.201 (+1 hits since last alert)|serranoscoffee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "serranoscoffee.com"] [uri "/xmlrpc.php"] [unique_id "agyAFTU6rIFgHth0fXU3ZAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-19 15:20:55
(3 months ago)
[redacted] 45.118.159.201 - - [19/May/2026:17:19:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" " ...
show more
[redacted] 45.118.159.201 - - [19/May/2026:17:19:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 45.118.159.201 - - [19/May/2026:17:19:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
[redacted] 45.118.159.201 - - [19/May/2026:17:20:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/12.1; WordPress/6.1; http://site99142429.com"
[redacted] 45.118.159.201 - - [19/May/2026:17:20:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 45.118.159.201 - - [19/May/2026:17:20:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/12.5; WordPress/6.4; http://site27985146.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-05-19 14:14:24
(3 months ago)
Attac
Brute-Force