🇩🇪
yitzhaq
2026-09-09 18:36:29
(2 hours ago)
45.234.222.243 - - [09/Sep/2026:20:35:45 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4388 "-" "WordPress. ...
show more
45.234.222.243 - - [09/Sep/2026:20:35:45 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4388 "-" "WordPress.com; https://wordpress.com"
45.234.222.243 - - [09/Sep/2026:20:35:55 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4388 "-" "Jetpack/12.5; WordPress/6.1; http://site72848813.com"
45.234.222.243 - - [09/Sep/2026:20:36:06 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4389 "-" "Jetpack by WordPress.com"
45.234.222.243 - - [09/Sep/2026:20:36:16 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4388 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.2)"
45.234.222.243 - - [09/Sep/2026:20:36:27 +0200] "POST /xmlrpc.php HTTP/1.1" 403 4389 "-" "Jetpack by WordPress.com"
show less
Web App Attack
Brute-Force
🇺🇸
xmission.com
2026-09-09 17:21:06
(4 hours ago)
45.234.222.243 - - [09/Sep/2026:11:21:06 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by ...
show more
45.234.222.243 - - [09/Sep/2026:11:21:06 -0600] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com"
...
show less
Web App Attack
🇹🇷
ycoskun41
2026-09-09 11:46:11
(9 hours ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
🇩🇪
nyuuzyou
2026-09-09 11:22:25
(10 hours ago)
Client failed challenge verification, marked as suspicious. HTTP request received over TCP on applic ...
show more
Client failed challenge verification, marked as suspicious. HTTP request received over TCP on application ports 80/443. Observed 2026-09-09T11:22:25Z.
show less
Bad Web Bot
🇩🇪
konseptit
2026-09-08 15:41:41
(1 day ago)
(wordpress) Failed wordpress login from 45.234.222.243 (BR/Brazil/-)
Brute-Force
🇺🇸
TPI-Abuse
2026-07-31 13:48:05
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 45.234.222.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.234.222.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 09:47:56.878485 2026] [security2:error] [pid 3805756:tid 3805756] [client 45.234.222.243:59524] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.234.222.243 (+1 hits since last alert)|legacy-insight.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "legacy-insight.com"] [uri "/xmlrpc.php"] [unique_id "amynjGJE1GNI0Iwcyhw26wAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-30 16:53:57
(1 month ago)
[redacted] 45.234.222.243 - - [30/Jul/2026:18:53:14 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 45.234.222.243 - - [30/Jul/2026:18:53:14 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 45.234.222.243 - - [30/Jul/2026:18:53:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 45.234.222.243 - - [30/Jul/2026:18:53:35 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 45.234.222.243 - - [30/Jul/2026:18:53:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 45.234.222.243 - - [30/Jul/2026:18:53:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.1; http://site50545147.com"
...
show less
Hacking
Web App Attack
🇩🇪
neckaralb-admin.de
2026-07-30 16:22:50
(1 month ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-07-30 15:55:08
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 45.234.222.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.234.222.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 11:55:03.079418 2026] [security2:error] [pid 4114412:tid 4114412] [client 45.234.222.243:55797] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.234.222.243 (+1 hits since last alert)|casadelsolmexico.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "casadelsolmexico.net"] [uri "/xmlrpc.php"] [unique_id "amtz18TpWDAB87c0WAgl3wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-30 13:55:53
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 45.234.222.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.234.222.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 09:55:49.146834 2026] [security2:error] [pid 4141163:tid 4141163] [client 45.234.222.243:61142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.234.222.243 (+1 hits since last alert)|canebrakes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "canebrakes.com"] [uri "/xmlrpc.php"] [unique_id "amtX5ZIaPCFZBWYl6-aFyAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-29 18:57:44
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 45.234.222.243 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.234.222.243 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 14:57:38.264244 2026] [security2:error] [pid 1009833:tid 1009833] [client 45.234.222.243:52195] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.234.222.243 (+1 hits since last alert)|solarfarms.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solarfarms.info"] [uri "/xmlrpc.php"] [unique_id "ampNIoVO8Kws2T43uubonwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
alferez
2026-07-29 16:01:28
(1 month ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
🇩🇪
FD-IX
2026-07-29 14:00:11
(1 month ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
Anonymous
2026-07-29 13:04:27
(1 month ago)
Automated Apache suspicious-path probe detected in last 1m: hits=5; wp-login_hits=0; url=/xmlrpc.php ...
show more
Automated Apache suspicious-path probe detected in last 1m: hits=5; wp-login_hits=0; url=/xmlrpc.php; url=/xmlrpc.php; url=/xmlrpc.php; url=/xmlrpc.php; url=/xmlrpc.php
show less
Web App Attack
Anonymous
2026-07-29 12:21:18
(1 month ago)
WordPress Brute Force
Brute-Force