Anonymous
2026-06-12 07:29:10
(3 days ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-12 06:31:34
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 49.36.177.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 49.36.177.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 02:31:20.117050 2026] [security2:error] [pid 2857:tid 2857] [client 49.36.177.67:13154] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.36.177.67 (+1 hits since last alert)|yanlidesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yanlidesign.com"] [uri "/xmlrpc.php"] [unique_id "aiunuL1fgv60LEKEtP74XgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-12 04:13:57
(3 days ago)
49.36.177.67 - - [12/Jun/2026:06:13:35 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack by Wo ...
show more
49.36.177.67 - - [12/Jun/2026:06:13:35 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack by WordPress.com"
49.36.177.67 - - [12/Jun/2026:06:13:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
49.36.177.67 - - [12/Jun/2026:06:13:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack/12.1; WordPress/6.1; http://site62761690.com"
49.36.177.67 - - [12/Jun/2026:06:13:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12.1; WordPress/6.1; http://site62761690.com"
49.36.177.67 - - [12/Jun/2026:06:13:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 624 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-12 03:32:52
(3 days ago)
[redacted] 49.36.177.67 - - [12/Jun/2026:05:31:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Wo ...
show more
[redacted] 49.36.177.67 - - [12/Jun/2026:05:31:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 49.36.177.67 - - [12/Jun/2026:05:32:03 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 49.36.177.67 - - [12/Jun/2026:05:32:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
[redacted] 49.36.177.67 - - [12/Jun/2026:05:32:34 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 49.36.177.67 - - [12/Jun/2026:05:32:48 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-06-12 03:03:34
(3 days ago)
Failed attempt detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
Marc
2026-06-12 01:30:12
(3 days ago)
49.36.177.67 - - [12/Jun/2026:03:28:41 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3465 "-" "Jetpack by W ...
show more
49.36.177.67 - - [12/Jun/2026:03:28:41 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3465 "-" "Jetpack by WordPress.com" 49.36.177.67 - - [12/Jun/2026:03:28:50 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3465 "-" "Jetpack/12.5; WordPress/6.3; http://site59829922.com" 49.36.177.67 - - [12/Jun/2026:03:30:11 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3466 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
abdubhai
2026-06-12 01:21:05
(3 days ago)
49.36.177.67 - - [12/Jun/2026:06
...
Brute-Force
๐ฉ๐ช
abdubhai
2026-06-12 00:59:32
(3 days ago)
49.36.177.67 - - [12/Jun/2026:05
...
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-11 21:25:32
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 49.36.177.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 49.36.177.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 17:25:17.477017 2026] [security2:error] [pid 12998:tid 12998] [client 49.36.177.67:32642] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.36.177.67 (+1 hits since last alert)|rentkase.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rentkase.com"] [uri "/xmlrpc.php"] [unique_id "aisnvYqIXy-7gZBNJnq0lwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-11 21:00:05
(3 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-11 20:35:06
(3 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 16:15:48
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 49.36.177.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 49.36.177.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 12:15:37.474005 2026] [security2:error] [pid 17909:tid 17909] [client 49.36.177.67:2913] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.36.177.67 (+1 hits since last alert)|lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lysedzija.com"] [uri "/xmlrpc.php"] [unique_id "airfKVJoeLxgE8vs_WPnsAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 13:06:54
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 49.36.177.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 49.36.177.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 09:06:44.883885 2026] [security2:error] [pid 7938:tid 7938] [client 49.36.177.67:17698] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.36.177.67 (+1 hits since last alert)|major33.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "major33.com"] [uri "/xmlrpc.php"] [unique_id "aiqy5AH8MRq0pOPKAWi-HwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-11 13:05:31
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 07:44:14
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 49.36.177.67 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 49.36.177.67 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 03:44:00.568296 2026] [security2:error] [pid 32331:tid 32331] [client 49.36.177.67:44002] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.36.177.67 (+1 hits since last alert)|whodatnation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whodatnation.com"] [uri "/xmlrpc.php"] [unique_id "aipnQFlVZzHlkvaONKFlkAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack