๐ฉ๐ช
ghostwarriors
2026-07-21 19:50:24
(3 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 19:23:10
(3 hours ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 15:51:32
(7 hours ago)
(mod_security) mod_security (id:240335) triggered by 77.98.66.56 (nmal-25-b2-v4wan-166417-cust55.vm2 ...
show more
(mod_security) mod_security (id:240335) triggered by 77.98.66.56 (nmal-25-b2-v4wan-166417-cust55.vm24.cable.virginm.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 11:51:27.618333 2026] [security2:error] [pid 22125:tid 22125] [client 77.98.66.56:61182] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 77.98.66.56 (+1 hits since last alert)|josephshv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "josephshv.com"] [uri "/xmlrpc.php"] [unique_id "al-Vf_uFPTdQxCNw3J3PCwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-20 23:27:33
(23 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-20 21:55:37
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 77.98.66.56 (nmal-25-b2-v4wan-166417-cust55.vm2 ...
show more
(mod_security) mod_security (id:240335) triggered by 77.98.66.56 (nmal-25-b2-v4wan-166417-cust55.vm24.cable.virginm.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 17:55:28.864289 2026] [security2:error] [pid 3021631:tid 3021631] [client 77.98.66.56:50148] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 77.98.66.56 (+1 hits since last alert)|incrp.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "incrp.org"] [uri "/xmlrpc.php"] [unique_id "al6ZUHGMz6ge-k2syDLxoQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-07-20 18:19:21
(1 day ago)
(wordpress) Failed wordpress login from 77.98.66.56 (GB/United Kingdom/nmal-25-b2-v4wan-166417-cust5 ...
show more
(wordpress) Failed wordpress login from 77.98.66.56 (GB/United Kingdom/nmal-25-b2-v4wan-166417-cust55.vm24.cable.virginm.net)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-20 14:15:56
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 77.98.66.56 (nmal-25-b2-v4wan-166417-cust55.vm2 ...
show more
(mod_security) mod_security (id:240335) triggered by 77.98.66.56 (nmal-25-b2-v4wan-166417-cust55.vm24.cable.virginm.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 10:15:51.159805 2026] [security2:error] [pid 16341:tid 16341] [client 77.98.66.56:58601] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 77.98.66.56 (+1 hits since last alert)|canebrakes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "canebrakes.com"] [uri "/xmlrpc.php"] [unique_id "al4tl8PyoM7X1TXCdAyw8gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-19 20:24:22
(2 days ago)
77.98.66.56 - - [19/Jul/2026:16:22:34 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5701 "-" "WordPress.com ...
show more
77.98.66.56 - - [19/Jul/2026:16:22:34 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5701 "-" "WordPress.com; https://wordpress.com"
77.98.66.56 - - [19/Jul/2026:16:23:17 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5701 "-" "WordPress.com; https://wordpress.com"
77.98.66.56 - - [19/Jul/2026:16:23:28 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5701 "-" "WordPress.com; https://wordpress.com"
77.98.66.56 - - [19/Jul/2026:16:23:49 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5701 "-" "WordPress.com; https://wordpress.com"
77.98.66.56 - - [19/Jul/2026:16:24:21 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5701 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-19 17:50:13
(2 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
GB/United Kingdom/nmal-25-b2-v4wan-166417-cust55.vm24.cabl ...
show more
Blocked by CSF 13 firewall - Rule: XMLRPC
GB/United Kingdom/nmal-25-b2-v4wan-166417-cust55.vm24.cable.virginm.net
show less
Web App Attack
Anonymous
2026-07-19 16:47:55
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ท
dynamix
2026-07-19 14:07:05
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 09:08:17
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 77.98.66.56 (nmal-25-b2-v4wan-166417-cust55.vm2 ...
show more
(mod_security) mod_security (id:240335) triggered by 77.98.66.56 (nmal-25-b2-v4wan-166417-cust55.vm24.cable.virginm.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 05:08:13.763155 2026] [security2:error] [pid 5771:tid 5771] [client 77.98.66.56:59351] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 77.98.66.56 (+1 hits since last alert)|cuulphotos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cuulphotos.com"] [uri "/xmlrpc.php"] [unique_id "alyT_XdgJgLtiTi_60G7ygAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-19 09:07:42
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-18 14:26:57
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 77.98.66.56 (nmal-25-b2-v4wan-166417-cust55.vm2 ...
show more
(mod_security) mod_security (id:240335) triggered by 77.98.66.56 (nmal-25-b2-v4wan-166417-cust55.vm24.cable.virginm.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 10:26:50.164963 2026] [security2:error] [pid 10440:tid 10440] [client 77.98.66.56:63940] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 77.98.66.56 (+1 hits since last alert)|se-advisorsgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "se-advisorsgroup.com"] [uri "/xmlrpc.php"] [unique_id "aluNKvnNmoMygwrTEWln9wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-18 13:53:38
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack