๐บ๐ธ
TPI-Abuse
2026-07-22 08:29:55
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 45.229.105.229 (229.105.229.45.cgn.atplus.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 45.229.105.229 (229.105.229.45.cgn.atplus.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 04:29:48.188001 2026] [security2:error] [pid 12435:tid 12435] [client 45.229.105.229:1244] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.229.105.229 (+1 hits since last alert)|souldata.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "souldata.com"] [uri "/xmlrpc.php"] [unique_id "amB_fH8waZZPsyV8Sfqe8wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 03:39:24
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 45.229.105.229 (229.105.229.45.cgn.atplus.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 45.229.105.229 (229.105.229.45.cgn.atplus.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 23:39:21.526667 2026] [security2:error] [pid 241433:tid 241433] [client 45.229.105.229:51146] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.229.105.229 (+1 hits since last alert)|aroilcontrolsystem.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aroilcontrolsystem.com"] [uri "/xmlrpc.php"] [unique_id "amA7aWaJi3gQGh_GTbzmpQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-21 22:07:21
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
tecnicorioja
2026-07-21 22:00:20
(1 day ago)
POST /xmlrpc.php [21/Jul/2026:12:34:52
Brute-Force
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-21 19:12:08
(1 day ago)
45.229.105.229 - - [21/Jul/2026:15:10:42 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress. ...
show more
45.229.105.229 - - [21/Jul/2026:15:10:42 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
45.229.105.229 - - [21/Jul/2026:15:11:03 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
45.229.105.229 - - [21/Jul/2026:15:11:45 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
45.229.105.229 - - [21/Jul/2026:15:11:56 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
45.229.105.229 - - [21/Jul/2026:15:12:06 -0400] "POST /xmlrpc.php HTTP/1.1" 403 5049 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 18:35:21
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 45.229.105.229 (229.105.229.45.cgn.atplus.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 45.229.105.229 (229.105.229.45.cgn.atplus.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:35:18.117392 2026] [security2:error] [pid 31305:tid 31305] [client 45.229.105.229:23737] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.229.105.229 (+1 hits since last alert)|phalanxemail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "phalanxemail.net"] [uri "/xmlrpc.php"] [unique_id "al-75oxmBGWrfEeGOoxB9gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 15:11:10
(1 day ago)
(wordpress) Failed wordpress login from 45.229.105.229 (BR/Brazil/229.105.229.45.cgn.atplus.com.br)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-21 14:28:12
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 45.229.105.229 (229.105.229.45.cgn.atplus.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 45.229.105.229 (229.105.229.45.cgn.atplus.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 10:28:09.207716 2026] [security2:error] [pid 10026:tid 10026] [client 45.229.105.229:12373] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.229.105.229 (+1 hits since last alert)|incrp.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "incrp.org"] [uri "/xmlrpc.php"] [unique_id "al-B-T-0jfOh31MjeS-ycwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-07-21 07:37:49
(1 day ago)
babystudio4d.com 45.229.105.229 - - [21/Jul/2026:02:37:26 -0500] "POST /xmlrpc.php HTTP/1.1" 200 415 ...
show more
babystudio4d.com 45.229.105.229 - - [21/Jul/2026:02:37:26 -0500] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com" -
babystudio4d.com 45.229.105.229 - - [21/Jul/2026:02:37:37 -0500] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com" -
babystudio4d.com 45.229.105.229 - - [21/Jul/2026:02:37:48 -0500] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com" -
...
show less
Hacking
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-21 04:32:08
(1 day ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-21 03:16:17
(1 day ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 20:30:41
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 45.229.105.229 (229.105.229.45.cgn.atplus.com.b ...
show more
(mod_security) mod_security (id:240335) triggered by 45.229.105.229 (229.105.229.45.cgn.atplus.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 16:30:34.913071 2026] [security2:error] [pid 18576:tid 18576] [client 45.229.105.229:52566] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.229.105.229 (+1 hits since last alert)|t9teamsportinggoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "t9teamsportinggoods.com"] [uri "/xmlrpc.php"] [unique_id "al6Fanj472tgr2LG0AOjyQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-07-20 20:20:48
(2 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-20 20:05:39
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-07-20 20:03:39
(2 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack