🇧🇪
cmbplf
2026-09-09 18:55:35
(5 hours ago)
5.160 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
🇫🇷
SpaceHost-Server
2026-05-02 22:38:53
(4 months ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-05-01 23:56:55
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 19:56:51.606378 2026] [security2:error] [pid 19597:tid 19597] [client 2.50.137.75:53379] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.75 (+1 hits since last alert)|briannalls.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "briannalls.com"] [uri "/xmlrpc.php"] [unique_id "afU9w5N1Z3Giu0isgdTFAgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-01 22:21:56
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 18:21:49.645912 2026] [security2:error] [pid 8039:tid 8061] [client 2.50.137.75:51337] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.75 (+1 hits since last alert)|worldecom.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "worldecom.org"] [uri "/xmlrpc.php"] [unique_id "afUnfZANM6dXRn2B8t7GggAAARA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-01 18:55:17
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 14:55:12.467845 2026] [security2:error] [pid 4702:tid 4755] [client 2.50.137.75:55748] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.75 (+1 hits since last alert)|rockabyecotons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rockabyecotons.com"] [uri "/xmlrpc.php"] [unique_id "afT3EPznlNu8GeNIH-T1DwAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-05-01 18:55:08
(4 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇬🇧
consul.to
2026-05-01 17:25:45
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-05-01 16:26:13
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 12:26:09.829274 2026] [security2:error] [pid 25194:tid 25194] [client 2.50.137.75:65420] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.75 (+1 hits since last alert)|medusakenya.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "medusakenya.com"] [uri "/xmlrpc.php"] [unique_id "afTUIWzRG-lDWX0ianum3gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-01 13:28:48
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 09:28:43.050057 2026] [security2:error] [pid 1262:tid 1262] [client 2.50.137.75:58856] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.75 (+1 hits since last alert)|morninginc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "morninginc.com"] [uri "/xmlrpc.php"] [unique_id "afSqi1LKsKBrREfy721eqAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
SweetHoneyPress
2026-05-01 10:03:22
(4 months ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=600104 | UA: WordPress.com; https://wordpress.com
Web App Attack
Brute-Force
🇪🇸
SweetHoneyPress
2026-05-01 09:48:12
(4 months ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=600008 | UA: Jetpack by WordPress.com
Web App Attack
Brute-Force
Anonymous
2026-05-01 08:27:03
(4 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-05-01 07:07:34
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 03:07:29.860617 2026] [security2:error] [pid 23648:tid 23648] [client 2.50.137.75:49984] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.75 (+1 hits since last alert)|pinebrookdesign.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pinebrookdesign.com"] [uri "/xmlrpc.php"] [unique_id "afRRMYxfhshYTeEvrhKjxAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
konseptit
2026-05-01 05:01:43
(4 months ago)
(wordpress) Failed wordpress login from 2.50.137.75 (AE/United Arab Emirates/bba-2-50-137-75.alshami ...
show more
(wordpress) Failed wordpress login from 2.50.137.75 (AE/United Arab Emirates/bba-2-50-137-75.alshamil.net.ae)
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-05-01 02:24:34
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): ...
show more
(mod_security) mod_security (id:240335) triggered by 2.50.137.75 (bba-2-50-137-75.alshamil.net.ae): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 22:24:30.081126 2026] [security2:error] [pid 20346:tid 20346] [client 2.50.137.75:63683] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 2.50.137.75 (+1 hits since last alert)|abilityengraving.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abilityengraving.com"] [uri "/xmlrpc.php"] [unique_id "afQO3s4OOV6YuLMiAifqiAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack