Anonymous
2026-06-06 02:53:10
(5 hours ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-05 06:27:49
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.149.96.169 (dsl.49.149.96.169.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.149.96.169 (dsl.49.149.96.169.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 02:27:41.867452 2026] [security2:error] [pid 17527:tid 17527] [client 49.149.96.169:59629] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.149.96.169 (+1 hits since last alert)|thinkingepic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thinkingepic.com"] [uri "/xmlrpc.php"] [unique_id "aiJsXVS4ZEETjlNoPvqF7AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-05 04:31:43
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
Kenshin869
2026-06-04 06:02:38
(2 days ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
WeekendWeb
2026-06-04 05:20:51
(2 days ago)
Wordpress Vunerability attack
Web App Attack
๐ซ๐ท
masterguru
2026-06-04 03:49:31
(2 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 49.149.96.169 (PH/Philippines/dsl.49.149.96.169.pldt.net) ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 49.149.96.169 (PH/Philippines/dsl.49.149.96.169.pldt.net): 10 in the last 3600 secs (0-201)
show less
Hacking
Anonymous
2026-06-03 08:01:13
(3 days ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-03 00:10:37
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 49.149.96.169 (dsl.49.149.96.169.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:240335) triggered by 49.149.96.169 (dsl.49.149.96.169.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 20:10:31.793241 2026] [security2:error] [pid 6651:tid 6676] [client 49.149.96.169:60533] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.149.96.169 (+1 hits since last alert)|woodamy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "woodamy.com"] [uri "/xmlrpc.php"] [unique_id "ah9w96M8VPTylZqSzuhrrgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-06-01 05:40:21
(5 days ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
Anonymous
2026-05-31 07:21:34
(6 days ago)
[redacted] 49.149.96.169 - - [31/May/2026:09:20:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 49.149.96.169 - - [31/May/2026:09:20:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 49.149.96.169 - - [31/May/2026:09:20:51 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.3; http://site76394074.com"
[redacted] 49.149.96.169 - - [31/May/2026:09:21:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.3; http://site35063111.com"
[redacted] 49.149.96.169 - - [31/May/2026:09:21:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 49.149.96.169 - - [31/May/2026:09:21:33 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-05-31 01:54:10
(6 days ago)
Attac
Brute-Force
Anonymous
2026-05-30 23:44:45
(6 days ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=tmg.gr; logs=/var/log/httpd/domains/tmg.gr.log; samples=/xm ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=tmg.gr; logs=/var/log/httpd/domains/tmg.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 12:29:42
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 49.149.96.169 (dsl.49.149.96.169.pldt.net): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 49.149.96.169 (dsl.49.149.96.169.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 08:29:35.094229 2026] [security2:error] [pid 18846:tid 18846] [client 49.149.96.169:61704] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pulleasy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pulleasy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahmGr2kIrQsRxvGM511b9AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-26 05:22:29
(1 week ago)
Attac
Brute-Force
๐บ๐ฆ
URAN Publishing Service
2024-11-19 12:27:28
(1 year ago)
49.149.96.169 - - [19/Nov/2024:14:27:26 +0200] "GET /wp-login.php HTTP/1.1" 404 2862 "-" "Mozilla/5. ...
show more
49.149.96.169 - - [19/Nov/2024:14:27:26 +0200] "GET /wp-login.php HTTP/1.1" 404 2862 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
49.149.96.169 - - [19/Nov/2024:14:27:27 +0200] "GET /xmlrpc.php HTTP/1.1" 404 542 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; rv:11.0) like Gecko"
...
show less
Web App Attack