Anonymous
2026-08-25 14:09:28
(8 hours ago)
[redacted] 45.175.70.95 - - [25/Aug/2026:16:08:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 45.175.70.95 - - [25/Aug/2026:16:08:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
[redacted] 45.175.70.95 - - [25/Aug/2026:16:08:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
[redacted] 45.175.70.95 - - [25/Aug/2026:16:09:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 45.175.70.95 - - [25/Aug/2026:16:09:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 45.175.70.95 - - [25/Aug/2026:16:09:27 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 06:59:44
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 45.175.70.95 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.175.70.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 02:59:37.477609 2026] [security2:error] [pid 19225:tid 19225] [client 45.175.70.95:55102] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.175.70.95 (+1 hits since last alert)|t9teamsportinggoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "t9teamsportinggoods.com"] [uri "/xmlrpc.php"] [unique_id "ao09WepWEBO42rN4dNRFxAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Tha_14
2026-08-24 16:26:44
(1 day ago)
Limit on login attempts is reached
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-23 16:46:17
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 45.175.70.95 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.175.70.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 12:46:10.128503 2026] [security2:error] [pid 28383:tid 28383] [client 45.175.70.95:16799] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.175.70.95 (+1 hits since last alert)|mariarozella.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mariarozella.com"] [uri "/xmlrpc.php"] [unique_id "aosj0gLtxvR_vlMs_6lMmAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-08-22 04:30:58
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 19:39:30
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 45.175.70.95 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.175.70.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 15:39:26.105047 2026] [security2:error] [pid 3293:tid 3293] [client 45.175.70.95:19355] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.175.70.95 (+1 hits since last alert)|desertautoworks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "desertautoworks.com"] [uri "/xmlrpc.php"] [unique_id "aoipbqoz0yi16JZPN0P6tAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-21 16:37:26
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 45.175.70.95 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.175.70.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 12:37:21.852806 2026] [security2:error] [pid 31253:tid 31253] [client 45.175.70.95:58812] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.175.70.95 (+1 hits since last alert)|celebritybikinigossip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "celebritybikinigossip.com"] [uri "/xmlrpc.php"] [unique_id "aoh-wdD0wryFtLYN_mZAfQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
grassau.com
2026-08-15 22:40:23
(1 week ago)
(wordpress) Failed wordpress login from 45.175.70.95 (DO/Dominican Republic/Santiago Province/Santia ...
show more
(wordpress) Failed wordpress login from 45.175.70.95 (DO/Dominican Republic/Santiago Province/Santiago de los Caballeros/-)
show less
Brute-Force
πΊπΈ
IndigoRidge
2026-08-15 04:45:16
(1 week ago)
45.175.70.95 - - [15/Aug/2026:00:43:20 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5103 "-" "WordPress.co ...
show more
45.175.70.95 - - [15/Aug/2026:00:43:20 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5103 "-" "WordPress.com; https://wordpress.com"
45.175.70.95 - - [15/Aug/2026:00:43:51 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5103 "-" "WordPress.com; https://wordpress.com"
45.175.70.95 - - [15/Aug/2026:00:44:13 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5103 "-" "WordPress.com; https://wordpress.com"
45.175.70.95 - - [15/Aug/2026:00:45:05 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5103 "-" "WordPress.com; https://wordpress.com"
45.175.70.95 - - [15/Aug/2026:00:45:16 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5103 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
Anonymous
2026-08-13 07:54:14
(1 week ago)
[redacted] 45.175.70.95 - - [13/Aug/2026:09:53:07 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 45.175.70.95 - - [13/Aug/2026:09:53:07 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 45.175.70.95 - - [13/Aug/2026:09:53:41 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.1; http://site38248868.com"
[redacted] 45.175.70.95 - - [13/Aug/2026:09:53:51 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.4; http://site29659265.com"
[redacted] 45.175.70.95 - - [13/Aug/2026:09:54:02 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 45.175.70.95 - - [13/Aug/2026:09:54:13 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
π±π»
garmtech.com
2026-08-11 16:09:39
(2 weeks ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
π±π»
garmtech.com
2026-08-11 15:59:04
(2 weeks ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
π²πΎ
Rizzy
2026-08-05 09:24:20
(2 weeks ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-04 06:50:46
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 45.175.70.95 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.175.70.95 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 02:50:37.449885 2026] [security2:error] [pid 991495:tid 991495] [client 45.175.70.95:55926] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.175.70.95 (+1 hits since last alert)|primemanagementmn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "primemanagementmn.com"] [uri "/xmlrpc.php"] [unique_id "anGLvTVeRBynIKBR_9ulxQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-07-30 04:12:54
(3 weeks ago)
Multiple WAF Violations
Brute-Force
Web App Attack