Anonymous
2026-07-23 15:45:47
(2 days ago)
[redacted] 64.207.254.42 - - [23/Jul/2026:17:45:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 64.207.254.42 - - [23/Jul/2026:17:45:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.2; http://site20029109.com"
[redacted] 64.207.254.42 - - [23/Jul/2026:17:45:14 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
[redacted] 64.207.254.42 - - [23/Jul/2026:17:45:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.4; http://site97179348.com"
[redacted] 64.207.254.42 - - [23/Jul/2026:17:45:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 64.207.254.42 - - [23/Jul/2026:17:45:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 15:22:26
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net ...
show more
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 11:22:19.611686 2026] [security2:error] [pid 3637564:tid 3637736] [client 64.207.254.42:57558] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.207.254.42 (+1 hits since last alert)|smarterproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "smarterproductions.com"] [uri "/xmlrpc.php"] [unique_id "amIxq1c0ydpnZKdQJ3X1fQAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 23:35:40
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net ...
show more
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 19:35:36.923526 2026] [security2:error] [pid 1061878:tid 1061878] [client 64.207.254.42:57644] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.207.254.42 (+1 hits since last alert)|jennyfiore.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jennyfiore.com"] [uri "/xmlrpc.php"] [unique_id "amFTyDUIEYBasFPnfZDP0AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bsoft.de
2026-07-22 23:31:54
(2 days ago)
64.207.254.42 - - [23/Jul/2026:01:31:33 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.co ...
show more
64.207.254.42 - - [23/Jul/2026:01:31:33 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
64.207.254.42 - - [23/Jul/2026:01:31:44 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
64.207.254.42 - - [23/Jul/2026:01:31:53 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.1; http://site10503574.com"
show less
Web App Attack
๐บ๐ธ
TAY
2026-07-22 17:11:01
(3 days ago)
64.207.254.42 - - [23/Jul/2026:01:10:40 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "WordPress.c ...
show more
64.207.254.42 - - [23/Jul/2026:01:10:40 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "WordPress.com; https://wordpress.com"
64.207.254.42 - - [23/Jul/2026:01:10:50 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
64.207.254.42 - - [23/Jul/2026:01:11:01 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5867 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-22 13:58:55
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net ...
show more
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 09:58:50.889002 2026] [security2:error] [pid 452315:tid 452315] [client 64.207.254.42:57233] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.207.254.42 (+1 hits since last alert)|brianwhitty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "brianwhitty.com"] [uri "/xmlrpc.php"] [unique_id "amDMmvKrm2QmYsCQdLnWhAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 08:40:00
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net ...
show more
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 04:39:53.981058 2026] [security2:error] [pid 25062:tid 25062] [client 64.207.254.42:59026] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.207.254.42 (+1 hits since last alert)|drwolberg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "drwolberg.com"] [uri "/xmlrpc.php"] [unique_id "amCB2ZnHSe4LkZBMU3cQFAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 07:36:54
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net ...
show more
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 03:36:49.005559 2026] [security2:error] [pid 1659654:tid 1659654] [client 64.207.254.42:53826] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.207.254.42 (+1 hits since last alert)|takeapawsboston.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "takeapawsboston.com"] [uri "/xmlrpc.php"] [unique_id "amBzEdVqD0TwEiW_qnyGfgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 23:27:03
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net ...
show more
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 19:26:57.129667 2026] [security2:error] [pid 556825:tid 556825] [client 64.207.254.42:57189] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.207.254.42 (+1 hits since last alert)|lighthousescm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lighthousescm.com"] [uri "/xmlrpc.php"] [unique_id "amAAQSua9_mXP8W9dckBFgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-07-21 23:24:03
(3 days ago)
64.207.254.42 - - [22/Jul/2026:07:23:42 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack/12. ...
show more
64.207.254.42 - - [22/Jul/2026:07:23:42 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack/12.0; WordPress/6.4; http://site64737626.com"
64.207.254.42 - - [22/Jul/2026:07:23:53 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "WordPress.com; https://wordpress.com"
64.207.254.42 - - [22/Jul/2026:07:24:03 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5941 "-" "Jetpack/13.0; WordPress/6.1; http://site12898696.com"
...
show less
Brute-Force
๐บ๐ธ
IndigoRidge
2026-07-11 06:02:47
(2 weeks ago)
64.207.254.42 - - [11/Jul/2026:02:01:42 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.c ...
show more
64.207.254.42 - - [11/Jul/2026:02:01:42 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
64.207.254.42 - - [11/Jul/2026:02:02:03 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
64.207.254.42 - - [11/Jul/2026:02:02:25 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
64.207.254.42 - - [11/Jul/2026:02:02:35 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
64.207.254.42 - - [11/Jul/2026:02:02:46 -0400] "POST /xmlrpc.php HTTP/1.1" 200 5072 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 11:17:51
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net ...
show more
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 07:17:44.951870 2026] [security2:error] [pid 26716:tid 26716] [client 64.207.254.42:55479] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.207.254.42 (+1 hits since last alert)|jazziiafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jazziiafoundation.org"] [uri "/xmlrpc.php"] [unique_id "alDU2NNcZ_E90GCl-9f9jgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-10 09:43:40
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 06:13:51
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net ...
show more
(mod_security) mod_security (id:240335) triggered by 64.207.254.42 (wsip-64-207-254-42.tu.ok.cox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 02:13:46.293601 2026] [security2:error] [pid 23620:tid 23620] [client 64.207.254.42:54960] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.207.254.42 (+1 hits since last alert)|arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "arsenalfordemocracy.com"] [uri "/xmlrpc.php"] [unique_id "alCNmrh9hDm1vaP0BBOMSQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-07-01 06:01:23
(3 weeks ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force