Anonymous
2026-06-22 12:19:03
(18 seconds ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 05:41:43
(6 hours ago)
(mod_security) mod_security (id:240335) triggered by 64.233.237.249 (233-64-249-237.static.clv.wideo ...
show more
(mod_security) mod_security (id:240335) triggered by 64.233.237.249 (233-64-249-237.static.clv.wideopenwest.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 01:41:39.632738 2026] [security2:error] [pid 24078:tid 24078] [client 64.233.237.249:65467] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.233.237.249 (+1 hits since last alert)|furbabieslivesmatter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "furbabieslivesmatter.com"] [uri "/xmlrpc.php"] [unique_id "ajjLE5KJLsw3EaqkjZaluwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-22 03:52:35
(8 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-21 23:25:24
(12 hours ago)
(wordpress) Failed wordpress login from 64.233.237.249 (US/United States/233-64-249-237.static.clv.w ...
show more
(wordpress) Failed wordpress login from 64.233.237.249 (US/United States/233-64-249-237.static.clv.wideopenwest.com)
show less
Brute-Force
Anonymous
2026-06-21 20:04:36
(16 hours ago)
[redacted] 64.233.237.249 - - [21/Jun/2026:22:03:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 64.233.237.249 - - [21/Jun/2026:22:03:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.1; http://site80554584.com"
[redacted] 64.233.237.249 - - [21/Jun/2026:22:04:03 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
[redacted] 64.233.237.249 - - [21/Jun/2026:22:04:13 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.4; http://site47579375.com"
[redacted] 64.233.237.249 - - [21/Jun/2026:22:04:24 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 64.233.237.249 - - [21/Jun/2026:22:04:34 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.3; http://site74676962.com"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
Tha_14
2026-06-11 13:45:57
(1 week ago)
Limit on login attempts is reached
Brute-Force
Anonymous
2026-06-11 13:45:42
(1 week ago)
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-05-31 21:17:27
(3 weeks ago)
(wordpress) Failed wordpress login from 64.233.237.249 (US/United States/233-64-249-237.static.clv.w ...
show more
(wordpress) Failed wordpress login from 64.233.237.249 (US/United States/233-64-249-237.static.clv.wideopenwest.com)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-31 20:47:45
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 64.233.237.249 (233-64-249-237.static.clv.wideo ...
show more
(mod_security) mod_security (id:240335) triggered by 64.233.237.249 (233-64-249-237.static.clv.wideopenwest.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 16:47:40.357863 2026] [security2:error] [pid 8317:tid 8324] [client 64.233.237.249:63378] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.233.237.249 (+1 hits since last alert)|managementlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "managementlaw.com"] [uri "/xmlrpc.php"] [unique_id "ahyebCZ68qP099nwHXwa-QAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-28 02:00:40
(3 weeks ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-28 01:19:58
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 64.233.237.249 (233-64-249-237.static.clv.wideo ...
show more
(mod_security) mod_security (id:240335) triggered by 64.233.237.249 (233-64-249-237.static.clv.wideopenwest.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 21:19:53.009712 2026] [security2:error] [pid 25352:tid 25352] [client 64.233.237.249:52823] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.233.237.249 (+1 hits since last alert)|robinsnestingplace.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "robinsnestingplace.net"] [uri "/xmlrpc.php"] [unique_id "aheYOcXYbt3rrfpt1fHJ0gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 21:44:38
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 64.233.237.249 (233-64-249-237.static.clv.wideo ...
show more
(mod_security) mod_security (id:240335) triggered by 64.233.237.249 (233-64-249-237.static.clv.wideopenwest.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 17:44:30.477365 2026] [security2:error] [pid 18519:tid 18519] [client 64.233.237.249:54219] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.233.237.249 (+1 hits since last alert)|grexicon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "grexicon.com"] [uri "/xmlrpc.php"] [unique_id "ahdlvnNclwHgRvEYXhjPLAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack