๐ฌ๐ง
openstrike.co.uk
2026-06-04 05:13:40
(5 hours ago)
9 attacks on PHP URLs:
POST /wp/xmlrpc.php HTTP/1.1
Web App Attack
๐ฌ๐ง
andypiper
2026-06-04 01:02:51
(9 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
DrLex0
2026-06-04 00:56:40
(9 hours ago)
WordPress xmlrpc exploit attempt
52.159.247.48 443 - [04/Jun/2026:00:56:40 +0000] "POST /wp/xmlrpc. ...
show more
WordPress xmlrpc exploit attempt
52.159.247.48 443 - [04/Jun/2026:00:56:40 +0000] "POST /wp/xmlrpc.php HTTP/1.1" 400 3905 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 00:55:42
(9 hours ago)
52.159.247.48 - - [04/Jun/2026:02:55:41 +0200] "POST /wp/ HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Window ...
show more
52.159.247.48 - - [04/Jun/2026:02:55:41 +0200] "POST /wp/ HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฌ๐ง
spamverify.com
2026-06-04 00:22:44
(10 hours ago)
Honeypot Hit: xmlrpc.php
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 00:02:19
(10 hours ago)
Attac
Brute-Force
๐ธ๐ฌ
ipidentify
2026-06-03 23:43:27
(10 hours ago)
2026-06-03T23:43:27Z POST /wp/xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 23:12:28
(11 hours ago)
(mod_security) mod_security (id:240335) triggered by 52.159.247.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 52.159.247.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 19:12:25.489917 2026] [security2:error] [pid 16710:tid 16730] [client 52.159.247.48:7066] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 52.159.247.48 (+1 hits since last alert)|wwwhst.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wwwhst.com"] [uri "/wp/xmlrpc.php"] [unique_id "aiC02VuPhCTl9T_LSP0fkQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 23:11:45
(11 hours ago)
52.159.247.48 - - [03/Jun/2026:23:11:45 +0000] "POST /wp/xmlrpc.php HTTP/1.1" 404 19664 "-" "Mozilla ...
show more
52.159.247.48 - - [03/Jun/2026:23:11:45 +0000] "POST /wp/xmlrpc.php HTTP/1.1" 404 19664 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-06-03 22:40:01
(11 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-03 22:27:32
(12 hours ago)
[ThuJun0400:27:29.6521052026][security2:error][pid2389940:tid2390055][client52.159.247.48:0]ModSecur ...
show more
[ThuJun0400:27:29.6521052026][security2:error][pid2389940:tid2390055][client52.159.247.48:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"bno.ch\"][uri\"/wp/xmlrpc.php\"][unique_id\"aiCqURLRXyI7-yYIaZlVegAAANM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
Hazzard
2026-06-03 22:27:13
(12 hours ago)
(wordpress) Failed wordpress login from 52.159.247.48 (US/United States/California/San Jose/-/[redac ...
show more
(wordpress) Failed wordpress login from 52.159.247.48 (US/United States/California/San Jose/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-03 22:18:37
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 52.159.247.48 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 52.159.247.48 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 18:18:32.460594 2026] [security2:error] [pid 15599:tid 15599] [client 52.159.247.48:6760] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 52.159.247.48 (+1 hits since last alert)|platinumcapitalpartners.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "platinumcapitalpartners.net"] [uri "/wp/xmlrpc.php"] [unique_id "aiCoOLCJEz4I6OmaPj0NoQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-06-03 22:18:08
(12 hours ago)
xmlrpc exploit on 409.today/wp/xmlrpc.php โ WellSpr.ing/NetSentinel civic-AI security layer
Brute-Force
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-06-03 22:11:22
(12 hours ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack