๐ณ๐ฑ
tmiland
2026-07-23 12:35:12
(1 day ago)
(wordpress_xmlrpc) WordPress XMLPRC Attack 94.59.163.134 (AE/United Arab Emirates/bba-94-59-163-134. ...
show more
(wordpress_xmlrpc) WordPress XMLPRC Attack 94.59.163.134 (AE/United Arab Emirates/bba-94-59-163-134.alshamil.net.ae): 3 in the last 3600 secs; IP: 94.59.163.134; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 94.59.163.134 - - [23/Jul/2026:14:34:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "WordPress.com; https://wordpress.com" 94.59.163.134 - - [23/Jul/2026:14:34:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack/12.0; WordPress/6.1; http://site35589807.com" 94.59.163.134 - - [23/Jul/2026:14:35:10 +0200] "POST /xmlrpc.php HTTP/1.1" 200 415 "-" "Jetpack by WordPress.com"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-23 10:39:32
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 94.59.163.134 (bba-94-59-163-134.alshamil.net.a ...
show more
(mod_security) mod_security (id:240335) triggered by 94.59.163.134 (bba-94-59-163-134.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 06:39:26.173074 2026] [security2:error] [pid 2669233:tid 2669233] [client 94.59.163.134:61276] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.59.163.134 (+1 hits since last alert)|exhaustthelimits.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "exhaustthelimits.org"] [uri "/xmlrpc.php"] [unique_id "amHvXlQZwpeQ31giUYNEiQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-23 09:49:38
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 10:21:18
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 94.59.163.134 (bba-94-59-163-134.alshamil.net.a ...
show more
(mod_security) mod_security (id:240335) triggered by 94.59.163.134 (bba-94-59-163-134.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 06:21:13.602374 2026] [security2:error] [pid 15041:tid 15053] [client 94.59.163.134:65228] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.59.163.134 (+1 hits since last alert)|iamfluff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iamfluff.com"] [uri "/xmlrpc.php"] [unique_id "amCZmQNn1fN-uRtmzz_CUAAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
giulio gorobey
2026-07-21 17:18:04
(3 days ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /xmlrpc.php
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-21 15:57:25
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-18 14:40:35
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 94.59.163.134 (bba-94-59-163-134.alshamil.net.a ...
show more
(mod_security) mod_security (id:240335) triggered by 94.59.163.134 (bba-94-59-163-134.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 10:40:29.702883 2026] [security2:error] [pid 324032:tid 324032] [client 94.59.163.134:61865] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.59.163.134 (+1 hits since last alert)|greenmountainfeeds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "greenmountainfeeds.com"] [uri "/xmlrpc.php"] [unique_id "aluQXa460SSvUNGy5qFATwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-08 18:10:57
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 94.59.163.134 (bba-94-59-163-134.alshamil.net.a ...
show more
(mod_security) mod_security (id:240335) triggered by 94.59.163.134 (bba-94-59-163-134.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 08 14:10:51.341889 2026] [security2:error] [pid 23062:tid 23062] [client 94.59.163.134:49375] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.59.163.134 (+1 hits since last alert)|ardath.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ardath.net"] [uri "/xmlrpc.php"] [unique_id "ak6SqyaZhOwQDZaDc8wpQgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-07-08 12:35:22
(2 weeks ago)
(wordpress) Failed wordpress login from 94.59.163.134 (AE/United Arab Emirates/bba-94-59-163-134.als ...
show more
(wordpress) Failed wordpress login from 94.59.163.134 (AE/United Arab Emirates/bba-94-59-163-134.alshamil.net.ae)
show less
Brute-Force
๐ฉ๐ช
dbmwebdesign
2026-07-07 17:35:18
(2 weeks ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-06 16:55:58
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 94.59.163.134 (bba-94-59-163-134.alshamil.net.a ...
show more
(mod_security) mod_security (id:240335) triggered by 94.59.163.134 (bba-94-59-163-134.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 06 12:55:50.355961 2026] [security2:error] [pid 16509:tid 16509] [client 94.59.163.134:62319] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 94.59.163.134 (+1 hits since last alert)|motherlyhomecare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "motherlyhomecare.com"] [uri "/xmlrpc.php"] [unique_id "akveFpoGdCxSZkSiFmMu2gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack