๐ฉ๐ช
Marc
2026-07-20 12:34:05
(19 hours ago)
59.93.96.59 - - [20/Jul/2026:14:33:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4669 "-" "Jetpack by Wo ...
show more
59.93.96.59 - - [20/Jul/2026:14:33:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4669 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)" 59.93.96.59 - - [20/Jul/2026:14:33:54 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4670 "-" "WordPress.com; https://wordpress.com" 59.93.96.59 - - [20/Jul/2026:14:34:05 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4670 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 12:06:34
(19 hours ago)
(mod_security) mod_security (id:240335) triggered by 59.93.96.59 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 59.93.96.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 08:06:28.703688 2026] [security2:error] [pid 30302:tid 30302] [client 59.93.96.59:62694] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.93.96.59 (+1 hits since last alert)|difusionens.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "difusionens.org"] [uri "/xmlrpc.php"] [unique_id "al4PRCOBZCc0Wno1hsnRtgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 11:02:38
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 59.93.96.59 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 59.93.96.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 07:02:30.769734 2026] [security2:error] [pid 25240:tid 25240] [client 59.93.96.59:57157] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.93.96.59 (+1 hits since last alert)|airdriedrivingschool.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "airdriedrivingschool.com"] [uri "/xmlrpc.php"] [unique_id "al4ARgUcUkYJZWrDvr1DqgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 09:48:44
(22 hours ago)
(mod_security) mod_security (id:240335) triggered by 59.93.96.59 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 59.93.96.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 05:48:36.611004 2026] [security2:error] [pid 30620:tid 30638] [client 59.93.96.59:64939] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.93.96.59 (+1 hits since last alert)|tkfay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tkfay.com"] [uri "/xmlrpc.php"] [unique_id "al3u9OjpUjYC3LVDIfaIzgAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-07-20 07:40:05
(1 day ago)
Wordfence waf block on kcuar
Web App Attack
Anonymous
2026-07-20 06:48:07
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ณ๐ฑ
debestelapp
2026-07-20 06:25:07
(1 day ago)
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-20 06:07:26
(1 day ago)
59.93.96.59 - - [20/Jul/2026:02:05:39 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5803 "-" "WordPress.com ...
show more
59.93.96.59 - - [20/Jul/2026:02:05:39 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5803 "-" "WordPress.com; https://wordpress.com"
59.93.96.59 - - [20/Jul/2026:02:05:50 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5803 "-" "WordPress.com; https://wordpress.com"
59.93.96.59 - - [20/Jul/2026:02:06:01 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5803 "-" "WordPress.com; https://wordpress.com"
59.93.96.59 - - [20/Jul/2026:02:07:16 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5803 "-" "WordPress.com; https://wordpress.com"
59.93.96.59 - - [20/Jul/2026:02:07:25 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5803 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 05:50:08
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 59.93.96.59 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:240335) triggered by 59.93.96.59 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 01:50:02.211166 2026] [security2:error] [pid 8460:tid 8460] [client 59.93.96.59:60115] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 59.93.96.59 (+1 hits since last alert)|redlitephotos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "redlitephotos.com"] [uri "/xmlrpc.php"] [unique_id "al23CgwGSbK9QljfdqQQlgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
applemooz
2026-07-20 05:45:46
(1 day ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐ซ๐ท
geeek
2023-11-06 12:05:08
(2 years ago)
Port scanning: 445 TCP Blocked
Port Scan