๐บ๐ธ
TPI-Abuse
2026-06-29 08:14:13
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tz ...
show more
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tzulo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 04:14:06.857453 2026] [security2:error] [pid 2148:tid 2148] [client 173.249.255.119:57295] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 173.249.255.119 (+1 hits since last alert)|xyncom.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "xyncom.com"] [uri "/xmlrpc.php"] [unique_id "akIpTpLXuiOSOyqqQ5ZGmQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-29 06:39:38
(1 day ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ง๐ช
cmbplf
2026-06-29 01:58:01
(1 day ago)
4.489 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-29 00:16:25
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tz ...
show more
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tzulo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 20:16:21.761350 2026] [security2:error] [pid 28503:tid 28503] [client 173.249.255.119:52448] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 173.249.255.119 (+1 hits since last alert)|enjoymycondos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "enjoymycondos.com"] [uri "/xmlrpc.php"] [unique_id "akG5VZ9usA48G2_-D3yv8QAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-28 22:36:57
(1 day ago)
(wordpress) Failed wordpress login from 173.249.255.119 (US/United States/static-173-249-255-119.cus ...
show more
(wordpress) Failed wordpress login from 173.249.255.119 (US/United States/static-173-249-255-119.cust.tzulo.com)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-28 21:38:29
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tz ...
show more
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tzulo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 17:38:23.897438 2026] [security2:error] [pid 3667:tid 3667] [client 173.249.255.119:57934] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 173.249.255.119 (+1 hits since last alert)|zerotaxlab.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "zerotaxlab.com"] [uri "/xmlrpc.php"] [unique_id "akGUT4vXCALPlcREGfy1SQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-28 21:36:21
(1 day ago)
(wordpress) Failed wordpress login from 173.249.255.119 (US/United States/Illinois/Chicago/static-17 ...
show more
(wordpress) Failed wordpress login from 173.249.255.119 (US/United States/Illinois/Chicago/static-173-249-255-119.cust.tzulo.com/[redacted])
show less
Brute-Force
Anonymous
2026-06-28 21:05:05
(1 day ago)
[ns3.backorder.gr] httpd-xmlrpc-post: sites=blazos.com; logs=/var/log/httpd/domains/blazos.com.log; ...
show more
[ns3.backorder.gr] httpd-xmlrpc-post: sites=blazos.com; logs=/var/log/httpd/domains/blazos.com.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
cwytech
2026-06-28 12:54:02
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-xmlrpc-bf-high.
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-28 12:37:01
(2 days ago)
173.249.255.119 - - [28/Jun/2026:14:36:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12 ...
show more
173.249.255.119 - - [28/Jun/2026:14:36:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12.0; WordPress/6.4; http://site79915298.com"
173.249.255.119 - - [28/Jun/2026:14:36:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack by WordPress.com"
173.249.255.119 - - [28/Jun/2026:14:37:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
show less
Hacking
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-28 12:21:32
(2 days ago)
173.249.255.119 - - [28/Jun/2026:14:21:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/13 ...
show more
173.249.255.119 - - [28/Jun/2026:14:21:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/13.0; WordPress/6.1; http://site98100975.com"
173.249.255.119 - - [28/Jun/2026:14:21:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/13.0; WordPress/6.1; http://site43893418.com"
173.249.255.119 - - [28/Jun/2026:14:21:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 430 "-" "Jetpack/12.1; WordPress/6.1; http://site39036181.com"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 11:53:40
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tz ...
show more
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tzulo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 07:53:34.183583 2026] [security2:error] [pid 20123:tid 20123] [client 173.249.255.119:49734] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 173.249.255.119 (+1 hits since last alert)|jessicalevant.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jessicalevant.com"] [uri "/xmlrpc.php"] [unique_id "akELPtAED16V8Lj9rwM4UgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-28 11:50:47
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 10:41:11
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tz ...
show more
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tzulo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 06:41:03.042404 2026] [security2:error] [pid 29663:tid 29663] [client 173.249.255.119:57626] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 173.249.255.119 (+1 hits since last alert)|gasoilliquidsdaily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gasoilliquidsdaily.com"] [uri "/xmlrpc.php"] [unique_id "akD6P43c81iv9IPG2hMuSwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-28 05:37:37
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tz ...
show more
(mod_security) mod_security (id:240335) triggered by 173.249.255.119 (static-173-249-255-119.cust.tzulo.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 01:37:32.674574 2026] [security2:error] [pid 23839:tid 23839] [client 173.249.255.119:50215] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 173.249.255.119 (+1 hits since last alert)|difusionens.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "difusionens.org"] [uri "/xmlrpc.php"] [unique_id "akCzHAG6gmjNVDb4wP3hTwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack