๐ฆ๐บ
screwlooseit.com.au
2026-06-23 23:20:54
(6 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/52-36-31-64.static.reverse.lstn.net
Web App Attack
Anonymous
2026-06-23 23:10:03
(6 days ago)
Bot / scanning and/or hacking attempts: GET /xmlrpc.php HTTP/1.1, GET /?rest_route=/wp/v2/users HTTP ...
show more
Bot / scanning and/or hacking attempts: GET /xmlrpc.php HTTP/1.1, GET /?rest_route=/wp/v2/users HTTP/1.1, POST /xmlrpc.php HTTP/1.1, GET / HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
bigwavedave
2026-06-23 23:00:22
(6 days ago)
Wordpress Attack
Web App Attack
๐ซ๐ท
Kenshin869
2026-06-23 22:50:46
(6 days ago)
Wordpress unauthorized access attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-23 22:38:34
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 64.31.36.52 (52-36-31-64.static.reverse.lstn.ne ...
show more
(mod_security) mod_security (id:240335) triggered by 64.31.36.52 (52-36-31-64.static.reverse.lstn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 18:38:27.260905 2026] [security2:error] [pid 20906:tid 20906] [client 64.31.36.52:52042] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.31.36.52 (+1 hits since last alert)|agrollum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "agrollum.com"] [uri "/xmlrpc.php"] [unique_id "ajsK49ofaa6H9VgmhG_VXQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-23 22:36:19
(6 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 64.31.36.52 (US/United States/52-36-31-64.static.reverse. ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 64.31.36.52 (US/United States/52-36-31-64.static.reverse.lstn.net): 10 in the last 3600 secs (0-193)
show less
Hacking
๐ฉ๐ช
LRob.fr
2026-06-23 22:30:03
(6 days ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-23 22:11:50
(6 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-23 21:36:27
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 64.31.36.52 (52-36-31-64.static.reverse.lstn.ne ...
show more
(mod_security) mod_security (id:240335) triggered by 64.31.36.52 (52-36-31-64.static.reverse.lstn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 17:36:14.513908 2026] [security2:error] [pid 32123:tid 32136] [client 64.31.36.52:63031] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 64.31.36.52 (+1 hits since last alert)|hearthandhomestudio.art|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hearthandhomestudio.art"] [uri "/xmlrpc.php"] [unique_id "ajr8TvWaKGvOGZm7YsuzfwAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-23 20:47:43
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐ซ๐ท
dynamix
2026-06-23 20:03:23
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-06-23 17:28:56
(1 week ago)
64.31.36.52 - - [23/Jun/2026:19:28:43 +0200] "POST /xmlrpc.php HTTP/1.1" 404 3361 "-" "Mozilla/5.0 ( ...
show more
64.31.36.52 - - [23/Jun/2026:19:28:43 +0200] "POST /xmlrpc.php HTTP/1.1" 404 3361 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 OPR/114.0.0.0"
64.31.36.52 - - [23/Jun/2026:19:28:44 +0200] "POST /xmlrpc.php HTTP/1.1" 404 3361 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
64.31.36.52 - - [23/Jun/2026:19:28:44 +0200] "POST /xmlrpc.php HTTP/1.1" 404 3361 "-" "Mozilla/5.0 (Linux; Android 11; Nokia G50) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.6312.61 Mobile Safari/537.36"
64.31.36.52 - - [23/Jun/2026:19:28:45 +0200] "POST /xmlrpc.php HTTP/1.1" 404 3361 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:121.0) Gecko/20100101 Firefox/121.0"
64.31.36.52 - - [23/Jun/2026:19:28:46 +0200] "POST /xmlrpc.php HTTP/1.1" 404 3361 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
64.31.36.52 - - [23/Jun/2026:19:28:46 +0200] "POST /xmlrpc
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-01 13:34:53
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 64.31.36.52 (52-36-31-64.static.reverse.lstn.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 64.31.36.52 (52-36-31-64.static.reverse.lstn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 01 08:34:49.856011 2026] [security2:error] [pid 20044:tid 20044] [client 64.31.36.52:40864] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mikethehomehelper.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mikethehomehelper.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aX9WeW42mlay--6jQv_X1QAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-12 04:57:06
(6 months ago)
(mod_security) mod_security (id:210492) triggered by 64.31.36.52 (52-36-31-64.static.reverse.lstn.ne ...
show more
(mod_security) mod_security (id:210492) triggered by 64.31.36.52 (52-36-31-64.static.reverse.lstn.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 23:57:00.538579 2025] [security2:error] [pid 29504:tid 29512] [client 64.31.36.52:50853] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/parameters.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adprospb.com"] [uri "/web/app_dev.php/_profiler/open"] [unique_id "aTugnNMjXmcZyK_qHmorFAAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-05-11 23:26:04
(1 year ago)
1.296 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot