๐ซ๐ท
dynamix
2026-06-23 12:42:20
(3 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-06-23 06:33:27
(9 hours ago)
49.47.216.99 - - [23/Jun/2026:14:33:05 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5979 "-" "Jetpack/12.1 ...
show more
49.47.216.99 - - [23/Jun/2026:14:33:05 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5979 "-" "Jetpack/12.1; WordPress/6.2; http://site66836406.com"
49.47.216.99 - - [23/Jun/2026:14:33:18 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5979 "-" "WordPress.com; https://wordpress.com"
49.47.216.99 - - [23/Jun/2026:14:33:26 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5979 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
๐ซ๐ท
SpaceHost-Server
2026-06-22 22:33:24
(17 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-22 13:42:03
(1 day ago)
Wordfence waf block on lostswordfish
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 09:41:40
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.47.216.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 49.47.216.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 05:41:31.043628 2026] [security2:error] [pid 2570:tid 2570] [client 49.47.216.99:8733] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.47.216.99 (+1 hits since last alert)|verdeprofundo.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "verdeprofundo.net"] [uri "/xmlrpc.php"] [unique_id "ajkDS4o3-DFHS5mLduCEcgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-22 09:41:06
(1 day ago)
13.808 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-06-22 08:24:44
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
Anonymous
2026-06-22 07:34:04
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 06:16:59
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.47.216.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 49.47.216.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 02:16:50.278379 2026] [security2:error] [pid 16677:tid 16677] [client 49.47.216.99:62768] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.47.216.99 (+1 hits since last alert)|clayrivers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "clayrivers.com"] [uri "/xmlrpc.php"] [unique_id "ajjTUgsKYfO1DXDhrCU-vgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-22 05:02:20
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TAY
2026-06-22 04:46:35
(1 day ago)
49.47.216.99 - - [22/Jun/2026:12:42:21 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5924 "-" "Jetpack by W ...
show more
49.47.216.99 - - [22/Jun/2026:12:42:21 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5924 "-" "Jetpack by WordPress.com"
49.47.216.99 - - [22/Jun/2026:12:44:28 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5924 "-" "WordPress.com; https://wordpress.com"
49.47.216.99 - - [22/Jun/2026:12:46:35 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5924 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-22 04:33:22
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.47.216.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 49.47.216.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 00:33:10.384141 2026] [security2:error] [pid 8331:tid 8331] [client 49.47.216.99:57437] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.47.216.99 (+1 hits since last alert)|aifactoid.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aifactoid.com"] [uri "/xmlrpc.php"] [unique_id "aji7Bvjofjtrnu9WgEZyywAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 08:23:26
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 49.47.216.99 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 49.47.216.99 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 04:23:15.800956 2026] [security2:error] [pid 30021:tid 30021] [client 49.47.216.99:52681] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.47.216.99 (+1 hits since last alert)|iostation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iostation.com"] [uri "/xmlrpc.php"] [unique_id "ajZN824cpuNsh_NgPYkt7wAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-20 08:21:47
(3 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ฉ๐ช
konseptit
2026-06-20 06:19:37
(3 days ago)
(wordpress) Failed wordpress login from 49.47.216.99 (IN/India/-)
Brute-Force