๐บ๐ธ
TPI-Abuse
2026-03-04 13:21:01
(5 months ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 08:20:54.281805 2026] [security2:error] [pid 4671:tid 4671] [client 192.0.99.173:17052] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.173 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "aagxtqFkEdToIWx_6f_9LgAAAAE"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1772630454&nonce=XsIywZIP0x&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=DkIvrDNug4%2BswhHBPh0ZJVO%2FU6Y%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-10 13:36:45
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 10 09:36:40.313259 2025] [security2:error] [pid 272898:tid 272898] [client 192.0.99.173:14808] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.173 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "aEg06JRcFVF3_ZeVXOvomQAAAAc"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1749562600&nonce=vTbGTRYALQ&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=2CUJg7zhB0ZgKqoDwDJInVg1YLc%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-18 12:41:39
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 08:41:35.141158 2025] [security2:error] [pid 27956:tid 27956] [client 192.0.99.173:54632] [client 192.0.99.173] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.173 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "Z9lp_5QpzpOuWP-oW-t3bwAAAAM"], referer: http://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1742301695&nonce=zbY6fB60Ky&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=rEfgSimfWw6AwvGzSGC14zVkT3g%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2024-08-04 06:49:51
(2 years ago)
WordPress hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-06-24 03:49:08
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 23 23:49:03.511520 2024] [security2:error] [pid 29450] [client 192.0.99.173:64198] [client 192.0.99.173] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.173 (+1 hits since last alert)|solarizelouisville.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solarizelouisville.com"] [uri "/xmlrpc.php"] [unique_id "Znjsrxqhmg-lwZ9Gnuyb9wAAABQ"], referer: https://solarizelouisville.com/xmlrpc.php?for=jetpack&token=N3%2AGP42Z1%21gz%2ARmJa%40lJr5I1FNi%26vC%21Y%3A1%3A0×tamp=1719200943&nonce=BT35S20n0z&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=8jP8H8bVp%2FZ4%2BMjk5FcoPZAN9pw%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-27 18:14:55
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 27 14:14:50.109919 2024] [security2:error] [pid 25307] [client 192.0.99.173:18684] [client 192.0.99.173] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.173 (+1 hits since last alert)|www.adoniahenterprises.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.adoniahenterprises.com"] [uri "/xmlrpc.php"] [unique_id "ZlTNmppAvKtOMUValWgdUAAAAAE"], referer: https://www.adoniahenterprises.com/xmlrpc.php?for=jetpack&token=jVAvIuNaG2qd%25MO9St9d%5EyMBX7%25ZnLjy%3A1%3A0×tamp=1716833690&nonce=k6KY0EPTTw&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=Yk6%2FmhjmygxlSBzOHrAcVSW5Mas%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-05-15 12:36:39
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 ...
show more
(mod_security) mod_security (id:240335) triggered by 192.0.99.173 (wordpress.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 15 08:36:33.864965 2024] [security2:error] [pid 28378] [client 192.0.99.173:20050] [client 192.0.99.173] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 192.0.99.173 (+1 hits since last alert)|www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.dixiegeek.com"] [uri "/xmlrpc.php"] [unique_id "ZkSsUbeyJkF6A5QW0XZ6wwAAAAA"], referer: https://www.dixiegeek.com/xmlrpc.php?for=jetpack&token=1q9Je5bEbzwhrQxb5lIM%2A4y%21EWgzQ3%24m%3A1%3A0×tamp=1715776593&nonce=fUPxAtp3uZ&body-hash=METbiCw%2BtMQdctk0fdLMNlXOKKM%3D&signature=jkiLk4MQzs9FS%2FxilGjTR%2FqKxCU%3D
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-04-21 02:47:12
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2024-04-16 14:03:20
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ซ๐ท
tecnicorioja
2024-04-12 22:00:25
(2 years ago)
POST /xmlrpc.php [12/Apr/2024:03:53:39
Brute-Force
Web App Attack
๐ฉ๐ฐ
wnbhosting.dk
2023-04-24 12:55:05
(3 years ago)
WP xmlrpc [2023-04-24T14:55:05+02:00]
Hacking
Web App Attack
๐ฉ๐ฐ
wnbhosting.dk
2023-01-21 16:49:57
(3 years ago)
WP xmlrpc [2023-01-21T12:49:57+01:00]
Hacking
Web App Attack
๐ฉ๐ช
OiledAmoeba
2022-07-10 18:55:13
(4 years ago)
192.0.99.173 - - [11/Jul/2022:00:55:12 +0200] "www.ruhnke.cloud" "POST /xmlrpc.php?for=jetpack&token ...
show more
192.0.99.173 - - [11/Jul/2022:00:55:12 +0200] "www.ruhnke.cloud" "POST /xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657493711&nonce=t1UHPidrcC&body-hash=zM6wtlIR3F15tOMR6hYdh1YDU3A%3D&signature=FmuDTwUbhK9%2BLAXtHl1fyIFDlmM%3D HTTP/1.1" 500 0 "https://www.ruhnke.cloud/xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657493711&nonce=t1UHPidrcC&body-hash=zM6wtlIR3F15tOMR6hYdh1YDU3A%3D&signature=FmuDTwUbhK9%2BLAXtHl1fyIFDlmM%3D" "Jetpack by WordPress.com" "-" 0.455 "-"
...
show less
Brute-Force
๐ฉ๐ช
OiledAmoeba
2022-07-10 16:45:58
(4 years ago)
192.0.99.173 - - [10/Jul/2022:22:45:57 +0200] "www.ruhnke.cloud" "POST /xmlrpc.php?for=jetpack&token ...
show more
192.0.99.173 - - [10/Jul/2022:22:45:57 +0200] "www.ruhnke.cloud" "POST /xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657485956&nonce=SVCP8h76f1&body-hash=zM6wtlIR3F15tOMR6hYdh1YDU3A%3D&signature=RU9bjylvITJM8UKmtQHFsU6aihk%3D HTTP/1.1" 500 0 "https://www.ruhnke.cloud/xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657485956&nonce=SVCP8h76f1&body-hash=zM6wtlIR3F15tOMR6hYdh1YDU3A%3D&signature=RU9bjylvITJM8UKmtQHFsU6aihk%3D" "Jetpack by WordPress.com" "-" 0.424 "-"
...
show less
Brute-Force
๐ฉ๐ช
OiledAmoeba
2022-07-10 15:43:08
(4 years ago)
192.0.99.173 - - [10/Jul/2022:21:37:40 +0200] "www.ruhnke.cloud" "POST /xmlrpc.php?for=jetpack&token ...
show more
192.0.99.173 - - [10/Jul/2022:21:37:40 +0200] "www.ruhnke.cloud" "POST /xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657481859&nonce=8yaijdwl6b&body-hash=zM6wtlIR3F15tOMR6hYdh1YDU3A%3D&signature=JyJ%2FDKX7Wd%2Fa7J4zXwzVhQNKHgY%3D HTTP/1.1" 500 0 "https://www.ruhnke.cloud/xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657481859&nonce=8yaijdwl6b&body-hash=zM6wtlIR3F15tOMR6hYdh1YDU3A%3D&signature=JyJ%2FDKX7Wd%2Fa7J4zXwzVhQNKHgY%3D" "Jetpack by WordPress.com" "-" 0.419 "-"
192.0.99.173 - - [10/Jul/2022:21:43:07 +0200] "www.ruhnke.cloud" "POST /xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657482186&nonce=NB6bVegLeV&body-hash=zM6wtlIR3F15tOMR6hYdh1YDU3A%3D&signature=OVFUDtEuGOSl7jYuXlwuyzOfVmM%3D HTTP/1.1" 500 0 "https://www.ruhnke.cloud/xmlrpc.php?for=jetpack&token=yI%23s%25wmqLKwF%21%251wV%2Awt2sUbDMmapK%288%3A1%3A1×tamp=1657482186&nonce=NB6bVe
...
show less
Brute-Force