Anonymous
2026-06-13 02:09:13
(22 hours ago)
49.145.216.131 - - [13/Jun/2026:04:08:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by ...
show more
49.145.216.131 - - [13/Jun/2026:04:08:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
49.145.216.131 - - [13/Jun/2026:04:08:53 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
49.145.216.131 - - [13/Jun/2026:04:09:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12.1; WordPress/6.2; http://site90482101.com"
49.145.216.131 - - [13/Jun/2026:04:09:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12.1; WordPress/6.2; http://site90482101.com"
49.145.216.131 - - [13/Jun/2026:04:09:13 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-12 07:20:39
(1 day ago)
[ns3.backorder.gr] httpd-xmlrpc-post: sites=blazos.com; logs=/var/log/httpd/domains/blazos.com.log; ...
show more
[ns3.backorder.gr] httpd-xmlrpc-post: sites=blazos.com; logs=/var/log/httpd/domains/blazos.com.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-12 06:42:31
(1 day ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-12 06:14:48
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 02:14:42.105373 2026] [security2:error] [pid 20598:tid 20598] [client 49.145.216.131:44160] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.216.131 (+1 hits since last alert)|barecreationsaz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "barecreationsaz.com"] [uri "/xmlrpc.php"] [unique_id "aiuj0sGCJ4bgk3d0M0TkqgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 05:11:42
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 01:11:37.355082 2026] [security2:error] [pid 16166:tid 16186] [client 49.145.216.131:42383] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.216.131 (+1 hits since last alert)|quantumgaze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "quantumgaze.com"] [uri "/xmlrpc.php"] [unique_id "aiuVCSLJHbgP76tF4V_umwAAAZE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-12 04:58:09
(1 day ago)
trying wp-login.php/xmlrpc.php 34 times in 1 minutes
Brute-Force
Web App Attack
Anonymous
2026-06-10 16:45:16
(3 days ago)
[redacted] 49.145.216.131 - - [10/Jun/2026:18:44:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" " ...
show more
[redacted] 49.145.216.131 - - [10/Jun/2026:18:44:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack/12.1; WordPress/6.2; http://site45133061.com"
[redacted] 49.145.216.131 - - [10/Jun/2026:18:44:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 49.145.216.131 - - [10/Jun/2026:18:44:34 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack/12.5; WordPress/6.2; http://site52881302.com"
[redacted] 49.145.216.131 - - [10/Jun/2026:18:44:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack/12.0; WordPress/6.3; http://site50738191.com"
[redacted] 49.145.216.131 - - [10/Jun/2026:18:44:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack/12.1; WordPress/6.2; http://site96928377.com"
[redacted] 49.145.216.131 - - [10/Jun/2026:18:44:54 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 49.145.216.131 - - [10/Jun/2026:18:44:55 +0200] "POST /xmlrpc.php HTTP/1.1"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
konseptit
2026-06-10 15:44:39
(3 days ago)
(wordpress) Failed wordpress login from 49.145.216.131 (PH/Philippines/dsl.49.145.216.131.pldt.net)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-10 11:08:42
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 07:08:37.791512 2026] [security2:error] [pid 28815:tid 28815] [client 49.145.216.131:43096] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.216.131 (+1 hits since last alert)|greensandbeans.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "greensandbeans.us"] [uri "/xmlrpc.php"] [unique_id "ailFtXyjfJPKlC4s2ApuNgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-09 22:30:30
(4 days ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-08 22:30:29
(5 days ago)
Brute-Force
Web App Attack
๐ซ๐ฎ
YF
2026-06-08 18:00:46
(5 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 17:45:21
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 13:45:15.102821 2026] [security2:error] [pid 23559:tid 23559] [client 49.145.216.131:43731] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.216.131 (+1 hits since last alert)|jazziiafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jazziiafoundation.org"] [uri "/xmlrpc.php"] [unique_id "aib_qyf2RS2lytkUBewoTAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 16:43:47
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 12:43:39.119641 2026] [security2:error] [pid 7381:tid 7518] [client 49.145.216.131:42895] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.216.131 (+1 hits since last alert)|duplexgoldmine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "duplexgoldmine.com"] [uri "/xmlrpc.php"] [unique_id "aibxO6msxNwMip4fo_zcrAAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 15:12:06
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 49.145.216.131 (dsl.49.145.216.131.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 11:12:00.745814 2026] [security2:error] [pid 1566:tid 1566] [client 49.145.216.131:44792] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.145.216.131 (+1 hits since last alert)|radicalchange.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "radicalchange.org"] [uri "/xmlrpc.php"] [unique_id "aibbwCSuzwfitNRXETB-TgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack