๐ช๐ธ
alferez
2026-06-15 01:04:40
(2 days ago)
Multiple WP Login Attack
Brute-Force
Anonymous
2026-06-13 05:12:13
(4 days ago)
Attac
Brute-Force
๐จ๐ฆ
polycoda
2026-06-13 04:13:16
(4 days ago)
AutoBlock: ๐ WordPress Login Brute Force (20X or 30X) (Decay-Based)
Brute-Force
Web App Attack
๐ซ๐ท
Lunix
2026-06-13 01:55:27
(4 days ago)
Brute-Force
Web App Attack
๐ฉ๐ช
burlacu.org
2026-06-13 00:27:01
(4 days ago)
Nginx multi-log analysis detected: wordpress_scan. Evidence: XMLRPC abuse with 26 requests. Blocked ...
show more
Nginx multi-log analysis detected: wordpress_scan. Evidence: XMLRPC abuse with 26 requests. Blocked automatically.
show less
Web App Attack
Bad Web Bot
Anonymous
2026-06-13 00:23:04
(4 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-06-12 22:51:14
(4 days ago)
[redacted] 61.3.116.225 - - [13/Jun/2026:00:50:31 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 61.3.116.225 - - [13/Jun/2026:00:50:31 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 61.3.116.225 - - [13/Jun/2026:00:50:42 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 61.3.116.225 - - [13/Jun/2026:00:50:51 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 61.3.116.225 - - [13/Jun/2026:00:51:02 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
[redacted] 61.3.116.225 - - [13/Jun/2026:00:51:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.2; http://site70922773.com"
...
show less
Hacking
Web App Attack
๐ฌ๐ง
Apache
2026-06-12 19:21:04
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 61.3.116.225 (IN/India/-): 5 in the last 300 se ...
show more
(mod_security) mod_security (id:240335) triggered by 61.3.116.225 (IN/India/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 16:29:09
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 61.3.116.225 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 61.3.116.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 12:29:02.230333 2026] [security2:error] [pid 1925:tid 1925] [client 61.3.116.225:58609] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.3.116.225 (+1 hits since last alert)|mkdesignndetailing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mkdesignndetailing.com"] [uri "/xmlrpc.php"] [unique_id "aiwzziPm9xSEfQai5xLmpAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
NotCool
2026-06-12 14:02:37
(5 days ago)
(XMLRPC) WP XMLPRC Attack 61.3.116.225 (IN/India/-): 50 in the last 3600 secs
Web App Attack
๐ง๐ช
brechtr
2026-06-12 13:23:15
(5 days ago)
[Press84-BanHammer] bad username โ Sourced from: brechtryckaert.com โ Request: POST /xmlrpc.php
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-12 11:54:37
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 61.3.116.225 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 61.3.116.225 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 07:54:33.291289 2026] [security2:error] [pid 1350:tid 1366] [client 61.3.116.225:62324] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 61.3.116.225 (+1 hits since last alert)|utahhoaservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "utahhoaservices.com"] [uri "/xmlrpc.php"] [unique_id "aivzec5icRaeesLQlv3EaAAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack