πΊπΈ
TPI-Abuse
2026-08-20 02:20:46
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 22:20:42.176238 2026] [security2:error] [pid 14842:tid 14842] [client 45.231.35.2:54729] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.231.35.2 (+1 hits since last alert)|localpetsitters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "localpetsitters.com"] [uri "/xmlrpc.php"] [unique_id "aoZkerFJClmL46zK0kQkwgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-08-20 02:02:36
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-08-20 00:14:13
(1 week ago)
[redacted] 45.231.35.2 - - [20/Aug/2026:02:13:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jet ...
show more
[redacted] 45.231.35.2 - - [20/Aug/2026:02:13:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.1; http://site62029956.com"
[redacted] 45.231.35.2 - - [20/Aug/2026:02:13:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 45.231.35.2 - - [20/Aug/2026:02:13:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
[redacted] 45.231.35.2 - - [20/Aug/2026:02:14:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.1; http://site68929465.com"
[redacted] 45.231.35.2 - - [20/Aug/2026:02:14:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.3; http://site32373925.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-08-19 19:59:12
(1 week ago)
[redacted] 45.231.35.2 - - [19/Aug/2026:21:58:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jet ...
show more
[redacted] 45.231.35.2 - - [19/Aug/2026:21:58:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.2; http://site28185045.com"
[redacted] 45.231.35.2 - - [19/Aug/2026:21:58:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 45.231.35.2 - - [19/Aug/2026:21:58:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 45.231.35.2 - - [19/Aug/2026:21:59:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 45.231.35.2 - - [19/Aug/2026:21:59:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-14 04:46:31
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 00:46:24.913131 2026] [security2:error] [pid 14200:tid 14200] [client 45.231.35.2:59150] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.231.35.2 (+1 hits since last alert)|tell-me-first.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tell-me-first.com"] [uri "/xmlrpc.php"] [unique_id "an6doPH8BOiuGNgLrcCi9AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
integrantservices.com
2026-08-14 04:12:18
(2 weeks ago)
(wordpress) Failed wordpress login from 45.231.35.2 (PE/Peru/-)
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-14 01:54:52
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 21:54:45.427686 2026] [security2:error] [pid 6421:tid 6463] [client 45.231.35.2:52674] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.231.35.2 (+1 hits since last alert)|vinylnotespodcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vinylnotespodcast.com"] [uri "/xmlrpc.php"] [unique_id "an51ZTbha5NTBc1o0L0GSAAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-08-14 01:52:24
(2 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-08-14 00:51:01
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 20:50:58.171948 2026] [security2:error] [pid 14354:tid 14354] [client 45.231.35.2:60589] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.231.35.2 (+1 hits since last alert)|jessicalevant.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jessicalevant.com"] [uri "/xmlrpc.php"] [unique_id "an5mcpE4rZZp4x6aaXtQgQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-13 02:53:47
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 22:53:41.091395 2026] [security2:error] [pid 1057616:tid 1057616] [client 45.231.35.2:51374] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.231.35.2 (+1 hits since last alert)|davesievers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "davesievers.com"] [uri "/xmlrpc.php"] [unique_id "an0xtbMiA2pWZcwHRa7TLgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-08-12 01:09:54
(3 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
π΅π±
Budyn
2026-08-11 02:45:23
(3 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: definitelynotahoneypot.online | URI: /xmlrpc.php | UA: Jetpack/12.1; WordPress/6.2; http://site48628423.com | BODY: <?xml version="1.0"?><methodCall><methodName>metaWeblog.newPost</methodName><params><param><value><string>1</string></value></param><param><value><string>79455</string></value></param><param><value><string>79455</string></value></param><param><value><struct><member><name>title</name><value><string>s2ha0j3g7dwbnv</string></value></member><member><name>description</name><value>
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-11 01:18:23
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 21:18:18.727992 2026] [security2:error] [pid 23885:tid 23885] [client 45.231.35.2:56426] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.231.35.2 (+1 hits since last alert)|hertzan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hertzan.com"] [uri "/xmlrpc.php"] [unique_id "anp4WtsFtFfPexSFc1T1gQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-05 09:04:15
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 45.231.35.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 05 05:04:08.559568 2026] [security2:error] [pid 3577698:tid 3577698] [client 45.231.35.2:64450] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.231.35.2 (+1 hits since last alert)|ideaofauniversity.website|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ideaofauniversity.website"] [uri "/xmlrpc.php"] [unique_id "anL8iNhg0Qwl_fZclOAzxwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-04 04:35:46
(4 weeks ago)
(wordpress) Failed wordpress login from 45.231.35.2 (PE/Peru/-)
Brute-Force