Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=656; exact paths: /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 18:40:27
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 201.27.111.207 (201-27-111-207.dsl.telesp.net.b ...
show more
(mod_security) mod_security (id:240335) triggered by 201.27.111.207 (201-27-111-207.dsl.telesp.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 14:40:19.885991 2026] [security2:error] [pid 18185:tid 18185] [client 201.27.111.207:58089] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 201.27.111.207 (+1 hits since last alert)|arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "arsenalfordemocracy.com"] [uri "/xmlrpc.php"] [unique_id "amj3k4Lg0Vls6fsrOYlF1QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-07-28 16:30:42
(1 day ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐ช๐ธ
masterguru
2026-07-28 13:31:14
(2 days ago)
(xmlrpc) Failed xmlrpc access from 201.27.111.207 (BR/Brazil/201-27-111-207.dsl.telesp.net.br): 5 in ...
show more
(xmlrpc) Failed xmlrpc access from 201.27.111.207 (BR/Brazil/201-27-111-207.dsl.telesp.net.br): 5 in the last 3600 secs (0-122)
show less
Hacking
๐ฉ๐ช
neckaralb-admin.de
2026-07-28 13:30:11
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 10:58:48
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 201.27.111.207 (201-27-111-207.dsl.telesp.net.b ...
show more
(mod_security) mod_security (id:240335) triggered by 201.27.111.207 (201-27-111-207.dsl.telesp.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 06:58:44.422231 2026] [security2:error] [pid 1703374:tid 1703441] [client 201.27.111.207:50048] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 201.27.111.207 (+1 hits since last alert)|duplexgoldmine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "duplexgoldmine.com"] [uri "/xmlrpc.php"] [unique_id "amiLZAZBHN8g1RS6LsoZJgAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-27 20:51:46
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
ghostwarriors
2026-07-27 17:20:45
(2 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 17:15:19
(2 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 15:14:37
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 201.27.111.207 (201-27-111-207.dsl.telesp.net.b ...
show more
(mod_security) mod_security (id:240335) triggered by 201.27.111.207 (201-27-111-207.dsl.telesp.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:14:30.814842 2026] [security2:error] [pid 325003:tid 325003] [client 201.27.111.207:54030] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 201.27.111.207 (+1 hits since last alert)|michaelthompson.biz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "michaelthompson.biz"] [uri "/xmlrpc.php"] [unique_id "amd11hXm9tR2k4ssT6s_4wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-27 12:39:04
(3 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-07-27 12:08:29
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 19:37:13
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 201.27.111.207 (201-27-111-207.dsl.telesp.net.b ...
show more
(mod_security) mod_security (id:240335) triggered by 201.27.111.207 (201-27-111-207.dsl.telesp.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 15:37:08.197026 2026] [security2:error] [pid 2518952:tid 2518952] [client 201.27.111.207:64439] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 201.27.111.207 (+1 hits since last alert)|tomartsmedia.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tomartsmedia.org"] [uri "/xmlrpc.php"] [unique_id "amO-5P1U0T7O11hcWo36ogAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-07-23 18:35:06
(6 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-23 17:47:39
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 201.27.111.207 (201-27-111-207.dsl.telesp.net.b ...
show more
(mod_security) mod_security (id:240335) triggered by 201.27.111.207 (201-27-111-207.dsl.telesp.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 13:47:34.683936 2026] [security2:error] [pid 3576063:tid 3576080] [client 201.27.111.207:62669] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 201.27.111.207 (+1 hits since last alert)|datuinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "datuinc.com"] [uri "/xmlrpc.php"] [unique_id "amJTtmJlqOUfr8XJBigc7wAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack