Anonymous
2026-06-24 15:59:20
(4 days ago)
[redacted] 45.123.13.160 - - [24/Jun/2026:17:58:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 45.123.13.160 - - [24/Jun/2026:17:58:37 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 45.123.13.160 - - [24/Jun/2026:17:58:47 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 45.123.13.160 - - [24/Jun/2026:17:58:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 45.123.13.160 - - [24/Jun/2026:17:59:08 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 45.123.13.160 - - [24/Jun/2026:17:59:18 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
xmission.com
2026-06-24 15:58:38
(4 days ago)
45.123.13.160 - - [24/Jun/2026:09:58:38 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "WordPress.co ...
show more
45.123.13.160 - - [24/Jun/2026:09:58:38 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-24 14:16:28
(4 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
IN/India/-
Web App Attack
๐ซ๐ท
dynamix
2026-06-24 03:50:21
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-22 03:51:42
(6 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ช๐ธ
masterguru
2026-06-21 13:25:22
(1 week ago)
(xmlrpc) Failed xmlrpc access from 45.123.13.160 (IN/India/-): 5 in the last 3600 secs (0-122)
Hacking
๐ซ๐ท
Kenshin869
2026-06-21 12:49:53
(1 week ago)
Wordpress unauthorized access attempt
Brute-Force
๐ซ๐ท
dynamix
2026-06-21 05:45:15
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 17:06:39
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.123.13.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 45.123.13.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 13:06:27.241831 2026] [security2:error] [pid 13302:tid 13302] [client 45.123.13.160:29395] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.123.13.160 (+1 hits since last alert)|orcastrong.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "orcastrong.com"] [uri "/xmlrpc.php"] [unique_id "ajbIk34bn0qoIlr9RpdOMgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-20 17:06:10
(1 week ago)
Attac
Brute-Force
Anonymous
2026-06-20 17:04:05
(1 week ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-06-20 06:48:01
(1 week ago)
[redacted] 45.123.13.160 - - [20/Jun/2026:08:47:20 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "J ...
show more
[redacted] 45.123.13.160 - - [20/Jun/2026:08:47:20 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 45.123.13.160 - - [20/Jun/2026:08:47:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/12.5; WordPress/6.2; http://site81741701.com"
[redacted] 45.123.13.160 - - [20/Jun/2026:08:47:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
[redacted] 45.123.13.160 - - [20/Jun/2026:08:47:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 45.123.13.160 - - [20/Jun/2026:08:48:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-06-20 04:02:22
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 03:03:18
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.123.13.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 45.123.13.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 23:03:06.385681 2026] [security2:error] [pid 26414:tid 26421] [client 45.123.13.160:56754] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.123.13.160 (+1 hits since last alert)|fastestcopyright.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fastestcopyright.com"] [uri "/xmlrpc.php"] [unique_id "ajYC6gkmzL8PWvjtDfudpwAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 16:31:03
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.123.13.160 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 45.123.13.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 12:30:53.455378 2026] [security2:error] [pid 1913:tid 2040] [client 45.123.13.160:5738] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.123.13.160 (+1 hits since last alert)|tnccivic.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tnccivic.org"] [uri "/xmlrpc.php"] [unique_id "ajVuvU5laSZ1tVvtpFoXjAAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack