๐บ๐ธ
TPI-Abuse
2026-07-31 14:09:56
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 10:09:52.960734 2026] [security2:error] [pid 3824650:tid 3824650] [client 192.0.99.101:22842] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.101 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "amyssAOUjRxprEqm0DbfLQAAABM"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1785506992&nonce=4Tg0YTS4dN&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=IXKUHtKpVxVLxPq8bKeY5M7xGTc%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 14:47:01
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 10:46:58.170764 2026] [security2:error] [pid 24318:tid 24318] [client 192.0.99.101:4516] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.101 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "ahBsYqLqJ0lH7BX3VhrINAAAAAU"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1779461218&nonce=W76kH70Mfs&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=vmoN73esTjZbEvsRdjWfKrdwtrA%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 12:31:58
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 08:31:51.259788 2026] [security2:error] [pid 1325279:tid 1325279] [client 192.0.99.101:15184] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.101 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "adT5N-YQQNCD_UozRWmHDgAAABE"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1775565111&nonce=sjhfuvCZgU&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=CDxaH%2Br2xsCv7VC6e3nEQVRjwbs%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-09 13:56:13
(9 months ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 09 08:56:06.035942 2025] [security2:error] [pid 31989:tid 31989] [client 192.0.99.101:21746] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.101 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "aTgqdmF3vOgIL1BoEY3ITgAAABc"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1765288565&nonce=UDdcj35wDw&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=BhOpI6oc57qt8FNEaQvNtAyQFp8%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-08-27 12:53:56
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 27 08:53:48.155129 2024] [security2:error] [pid 29048:tid 29048] [client 192.0.99.101:43480] [client 192.0.99.101] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.101 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "Zs3MXFGAKT_wJRBPNeViuAAAAAQ"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1724763228&nonce=MyevGy6yAw&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=nmYneN8hqbQXinrJdKmyo2HuLW4%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-06-20 16:29:52
(2 years ago)
Unauthorized login attempts [ wordpress-xmlrpc]
Brute-Force
Web App Attack
Anonymous
2024-04-19 00:02:11
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ช๐ธ
10dencehispahard SL
2024-04-16 18:00:05
(2 years ago)
Unauthorized login attempts [ wordpress-xmlrpc]
Brute-Force
Web App Attack
Anonymous
2024-04-16 13:48:21
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ซ๐ท
tecnicorioja
2024-04-15 22:00:12
(2 years ago)
POST /xmlrpc.php [15/Apr/2024:03:50:18
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-03-09 13:38:03
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 09 08:37:50.227115 2024] [security2:error] [pid 1603] [client 192.0.99.101:21654] [client 192.0.99.101] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.101 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "ZexmLnWOa__ir2vOzxxyXgAAAAE"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1709991470&nonce=FuKRgwearU&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=j2VVCAQEiMkDiCFHZ%2FBU58h%2Fv30%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
10dencehispahard SL
2024-02-26 15:01:23
(2 years ago)
Unauthorized login attempts [ wordpress-xmlrpc]
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-02-17 05:02:28
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.101 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 17 00:02:24.234689 2024] [security2:error] [pid 30036] [client 192.0.99.101:32678] [client 192.0.99.101] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.101 (+1 hits since last alert)|solarizelouisville.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solarizelouisville.com"] [uri "/xmlrpc.php"] [unique_id "ZdA94GZHiqLE_Aw6OI-6DgAAABA"], referer: https://solarizelouisville.com/xmlrpc.php?for=jetpack&token=N3%2AGP42Z1%21gz%2ARmJa%40lJr5I1FNi%26vC%21Y%3A1%3A0×tamp=1708146144&nonce=9dhZu4l82r&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=DePFN%2BC1vMpyub4w9SBq1iv0MHM%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
wnbhosting.dk
2023-06-25 12:44:55
(3 years ago)
WP xmlrpc [2023-06-25T14:44:55+02:00]
Hacking
Web App Attack
๐ฉ๐ฐ
wnbhosting.dk
2023-01-23 16:49:39
(3 years ago)
WP xmlrpc [2023-01-23T12:49:39+01:00]
Hacking
Web App Attack