๐ฉ๐ช
dbmwebdesign
2026-07-22 00:00:42
(6 hours ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 22:31:59
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 18:31:51.956761 2026] [security2:error] [pid 10566:tid 10566] [client 80.77.189.39:17857] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.77.189.39 (+1 hits since last alert)|prayers4america.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "prayers4america.com"] [uri "/xmlrpc.php"] [unique_id "al_zV1fMPtwboz9betNBXAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-21 20:57:57
(9 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-21 15:01:44
(15 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
LB/Lebanon/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 14:04:56
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 10:04:49.408821 2026] [security2:error] [pid 16820:tid 16820] [client 80.77.189.39:33222] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.77.189.39 (+1 hits since last alert)|jillbauman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jillbauman.com"] [uri "/xmlrpc.php"] [unique_id "al98gdX6E2rDtxNDEPktVAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-07-21 12:29:32
(18 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 03:01:49
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 23:01:42.929548 2026] [security2:error] [pid 11165:tid 11165] [client 80.77.189.39:58803] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.77.189.39 (+1 hits since last alert)|nolaanime.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nolaanime.com"] [uri "/xmlrpc.php"] [unique_id "al7hFswCQo_VuCFb6vONPgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-07-21 02:33:06
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (LB/Lebanon/-): 5 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (LB/Lebanon/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 21:45:05
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 17:44:58.224605 2026] [security2:error] [pid 29904:tid 29904] [client 80.77.189.39:60236] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.77.189.39 (+1 hits since last alert)|se-advisorsgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "se-advisorsgroup.com"] [uri "/xmlrpc.php"] [unique_id "al6W2lb2EflRsr5Wa4tafQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
applemooz
2026-07-20 21:41:17
(1 day ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 20:43:56
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 80.77.189.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 16:43:52.728546 2026] [security2:error] [pid 31810:tid 31810] [client 80.77.189.39:17906] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 80.77.189.39 (+1 hits since last alert)|thefrontporchoffering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thefrontporchoffering.com"] [uri "/xmlrpc.php"] [unique_id "al6IiLseiD6rFUqcW7FjJgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-20 15:38:40
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-07-20 15:38:11
(1 day ago)
[redacted] 80.77.189.39 - - [20/Jul/2026:17:37:31 +0200] "POST /xmlrpc.php HTTP/1.1" 403 1682 "-" "J ...
show more
[redacted] 80.77.189.39 - - [20/Jul/2026:17:37:31 +0200] "POST /xmlrpc.php HTTP/1.1" 403 1682 "-" "Jetpack by WordPress.com"
[redacted] 80.77.189.39 - - [20/Jul/2026:17:37:38 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Jetpack by WordPress.com"
[redacted] 80.77.189.39 - - [20/Jul/2026:17:37:49 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
[redacted] 80.77.189.39 - - [20/Jul/2026:17:37:59 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
[redacted] 80.77.189.39 - - [20/Jul/2026:17:38:10 +0200] "POST /xmlrpc.php HTTP/1.1" 403 0 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TAY
2026-07-20 15:37:32
(1 day ago)
80.77.189.39 - - [20/Jul/2026:23:37:08 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5918 "-" "Jetpack/12.5 ...
show more
80.77.189.39 - - [20/Jul/2026:23:37:08 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5918 "-" "Jetpack/12.5; WordPress/6.4; http://site37364559.com"
80.77.189.39 - - [20/Jul/2026:23:37:18 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5918 "-" "Jetpack/13.0; WordPress/6.4; http://site87993788.com"
80.77.189.39 - - [20/Jul/2026:23:37:31 +0800] "POST /xmlrpc.php HTTP/1.1" 200 5918 "-" "Jetpack/12.5; WordPress/6.1; http://site31854723.com"
...
show less
Brute-Force
๐ฉ๐ช
ghostwarriors
2026-07-20 15:20:34
(1 day ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack