Anonymous
2026-06-24 11:53:40
(1 hour ago)
[redacted] 49.37.43.61 - - [24/Jun/2026:13:52:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jet ...
show more
[redacted] 49.37.43.61 - - [24/Jun/2026:13:52:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.3; http://site50459842.com"
[redacted] 49.37.43.61 - - [24/Jun/2026:13:53:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 49.37.43.61 - - [24/Jun/2026:13:53:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 49.37.43.61 - - [24/Jun/2026:13:53:27 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 49.37.43.61 - - [24/Jun/2026:13:53:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-24 09:46:00
(3 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-24 08:11:25
(4 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.37.43.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 49.37.43.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 04:11:14.279129 2026] [security2:error] [pid 32227:tid 32227] [client 49.37.43.61:61084] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.37.43.61 (+1 hits since last alert)|margroberts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "margroberts.com"] [uri "/xmlrpc.php"] [unique_id "ajuRIl518PduVsUl4y9lcgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 11:05:29
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.37.43.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 49.37.43.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 07:05:19.377284 2026] [security2:error] [pid 3379:tid 3379] [client 49.37.43.61:58732] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.37.43.61 (+1 hits since last alert)|gracebaptisthartsville.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gracebaptisthartsville.com"] [uri "/xmlrpc.php"] [unique_id "ajpob6p8O5V1jb_26IKSPQAAAF4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-23 09:22:09
(1 day ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
WeekendWeb
2026-06-23 08:00:29
(1 day ago)
Wordpress Vunerability attack
Web App Attack
๐ฉ๐ช
reznekcs
2026-06-23 06:26:58
(1 day ago)
F2B wordpress ban. Logs: 49.37.43.61 - - [23/Jun/2026:08:26:47 +0200] "POST /xmlrpc.php HTTP/1.1" 20 ...
show more
F2B wordpress ban. Logs: 49.37.43.61 - - [23/Jun/2026:08:26:47 +0200] "POST /xmlrpc.php HTTP/1.1" 200 458 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
49.37.43.61 - - [23/Jun/2026:08:26:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 458 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)"
show less
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-23 05:41:31
(1 day ago)
49.37.43.61 - - [23/Jun/2026:07:41:08 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6398 "-" "Jetpack/13.0; ...
show more
49.37.43.61 - - [23/Jun/2026:07:41:08 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6398 "-" "Jetpack/13.0; WordPress/6.1; http://site41518529.com"
49.37.43.61 - - [23/Jun/2026:07:41:19 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6398 "-" "Jetpack/12.0; WordPress/6.1; http://site60910936.com"
49.37.43.61 - - [23/Jun/2026:07:41:30 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6398 "-" "WordPress.com; https://wordpress.com"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 05:28:39
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.37.43.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 49.37.43.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 01:28:27.065775 2026] [security2:error] [pid 24427:tid 24427] [client 49.37.43.61:60706] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.37.43.61 (+1 hits since last alert)|gemco-mfg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gemco-mfg.com"] [uri "/xmlrpc.php"] [unique_id "ajoZe6rS93CuoiQ5QFmDpAAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-23 05:26:02
(1 day ago)
49.37.43.61 - - [23/Jun/2026:07:25:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6398 "-" "Jetpack by Wo ...
show more
49.37.43.61 - - [23/Jun/2026:07:25:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6398 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
49.37.43.61 - - [23/Jun/2026:07:25:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6398 "-" "Jetpack by WordPress.com"
49.37.43.61 - - [23/Jun/2026:07:26:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6398 "-" "WordPress.com; https://wordpress.com"
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-06-23 04:56:38
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ท
Kenshin869
2026-06-22 13:24:21
(1 day ago)
Wordpress unauthorized access attempt
Brute-Force
๐ฉ๐ช
4server
2026-06-22 11:30:48
(2 days ago)
[MonJun2213:30:38.8405402026][security2:error][pid1827430:tid1827557][client49.37.43.61:0]ModSecurit ...
show more
[MonJun2213:30:38.8405402026][security2:error][pid1827430:tid1827557][client49.37.43.61:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"restaurantgandria.ch\"][uri\"/xmlrpc.php\"][unique_id\"ajkc3hUVHgRsD6qTKKGVcgAAARA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 10:05:43
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 49.37.43.61 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 49.37.43.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 06:05:31.979190 2026] [security2:error] [pid 13119:tid 13119] [client 49.37.43.61:56328] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.37.43.61 (+1 hits since last alert)|tracytappan.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tracytappan.net"] [uri "/xmlrpc.php"] [unique_id "ajkI6-_zf6vp69qQP_ba2AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 05:14:10
(2 days ago)
Attac
Brute-Force