Anonymous
2026-06-11 11:00:18
(7 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 09:14:09
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (191.96.115.79.hathway.com): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (191.96.115.79.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 05:14:03.414360 2026] [security2:error] [pid 29990:tid 29990] [client 115.96.191.79:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 115.96.191.79 (+1 hits since last alert)|pixacast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pixacast.com"] [uri "/xmlrpc.php"] [unique_id "aip8W7s0fLOop9SGTRASIAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 08:42:54
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (191.96.115.79.hathway.com): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (191.96.115.79.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 04:42:49.419013 2026] [security2:error] [pid 11228:tid 11228] [client 115.96.191.79:57100] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 115.96.191.79 (+1 hits since last alert)|tomkatkaraoke.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tomkatkaraoke.com"] [uri "/xmlrpc.php"] [unique_id "aip1Cb3UbfDn6V5e0ujK1gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-06-11 08:25:28
(10 hours ago)
Wordpress Vunerability attack
Web App Attack
๐ซ๐ท
dynamix
2026-06-11 07:07:52
(11 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-06-11 06:08:59
(12 hours ago)
[da.kdns.gr] httpd-xmlrpc-post: sites=onar-pension.gr; logs=/var/log/httpd/domains/onar-pension.gr.l ...
show more
[da.kdns.gr] httpd-xmlrpc-post: sites=onar-pension.gr; logs=/var/log/httpd/domains/onar-pension.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-06-10 14:32:53
(1 day ago)
6.180 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ซ๐ท
masterguru
2026-06-10 09:21:56
(1 day ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-10 09:15:25
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (191.96.115.79.hathway.com): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (191.96.115.79.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 05:15:19.707437 2026] [security2:error] [pid 11506:tid 11506] [client 115.96.191.79:50413] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 115.96.191.79 (+1 hits since last alert)|godcanuseyou.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "godcanuseyou.com"] [uri "/xmlrpc.php"] [unique_id "aikrJzYyTWR-W-2rvnT_IgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 08:53:39
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (191.96.115.79.hathway.com): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (191.96.115.79.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 04:53:30.893422 2026] [security2:error] [pid 18454:tid 18454] [client 115.96.191.79:55569] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 115.96.191.79 (+1 hits since last alert)|varnadorefamily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "varnadorefamily.com"] [uri "/xmlrpc.php"] [unique_id "aikmCk1JJ9BGJCaBzQVOhQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2026-06-10 07:55:03
(1 day ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:42:43
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (191.96.115.79.hathway.com): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (191.96.115.79.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:42:38.071747 2026] [security2:error] [pid 7386:tid 7386] [client 115.96.191.79:54062] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 115.96.191.79 (+1 hits since last alert)|blindshine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "blindshine.com"] [uri "/xmlrpc.php"] [unique_id "aifgDs2w9uNJZh59_SnOfgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-06-09 09:02:54
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (IN/India/191.96.115.79.hathway.c ...
show more
(mod_security) mod_security (id:240335) triggered by 115.96.191.79 (IN/India/191.96.115.79.hathway.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack