Anonymous
2026-06-26 19:05:30
(5 hours ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=aidshep2018.gr; logs=/var/log/httpd/domains/aidshep2018.gr. ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=aidshep2018.gr; logs=/var/log/httpd/domains/aidshep2018.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-26 19:02:06
(5 hours ago)
(wordpress) Failed wordpress login from 103.87.94.140 (IN/India/-)
Brute-Force
๐ฆ๐บ
screwlooseit.com.au
2026-06-26 18:24:22
(6 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
IN/India/-
Web App Attack
๐ซ๐ฎ
YF
2026-06-26 18:00:31
(6 hours ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-26 12:29:09
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 08:29:05.414757 2026] [security2:error] [pid 32584:tid 32584] [client 103.87.94.140:63411] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.87.94.140 (+1 hits since last alert)|sharawi-gum.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sharawi-gum.com"] [uri "/xmlrpc.php"] [unique_id "aj5wkXK9DUTqXY-3vXQoIAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-26 11:54:04
(12 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 10:13:15
(14 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 06:13:09.987362 2026] [security2:error] [pid 26825:tid 26854] [client 103.87.94.140:58171] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.87.94.140 (+1 hits since last alert)|hmpdecors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hmpdecors.com"] [uri "/xmlrpc.php"] [unique_id "aj5QtSCB6SH5XBhe9kRhUgAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Alvino
2026-06-26 10:03:35
(14 hours ago)
Blocked due to abuseScore: 32
Web Spam
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 09:30:24
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 05:30:15.319797 2026] [security2:error] [pid 5967:tid 5967] [client 103.87.94.140:59624] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.87.94.140 (+1 hits since last alert)|dancingbearprinting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dancingbearprinting.com"] [uri "/xmlrpc.php"] [unique_id "aj5Gp6gRmzpK4_VDOlxEcgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Dolphi
2026-06-26 04:00:06
(20 hours ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 17:51:17
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 13:51:11.922853 2026] [security2:error] [pid 10218:tid 10218] [client 103.87.94.140:63641] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.87.94.140 (+1 hits since last alert)|wokedreamer.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wokedreamer.com"] [uri "/xmlrpc.php"] [unique_id "aj1qj9uqFdiM0pKY14pICgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 16:41:18
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 12:41:09.698492 2026] [security2:error] [pid 1455:tid 1455] [client 103.87.94.140:59573] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.87.94.140 (+1 hits since last alert)|feiz.church|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "feiz.church"] [uri "/xmlrpc.php"] [unique_id "aj1aJSXNYMJnrD9vGHuY6wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 13:47:02
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 103.87.94.140 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 09:46:56.775727 2026] [security2:error] [pid 14745:tid 14745] [client 103.87.94.140:49816] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.87.94.140 (+1 hits since last alert)|roguetechhub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "roguetechhub.com"] [uri "/xmlrpc.php"] [unique_id "aj0xUPC_HBcThXyAAqX3jwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-25 13:39:22
(1 day ago)
4.408 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ซ๐ท
masterguru
2026-06-25 12:43:01
(1 day ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking