๐ฑ๐ป
garmtech.com
2026-06-25 16:39:36
(1 day ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐ซ๐ท
dynamix
2026-06-25 16:13:57
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 13:58:08
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum. ...
show more
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 09:58:02.348080 2026] [security2:error] [pid 26174:tid 26174] [client 24.73.125.82:57034] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 24.73.125.82 (+1 hits since last alert)|roguetechscene.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "roguetechscene.com"] [uri "/xmlrpc.php"] [unique_id "aj0z6phudFQ1XmVJaX7DQQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-25 13:25:13
(1 day ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-24 17:23:51
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum. ...
show more
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 13:23:44.658582 2026] [security2:error] [pid 27058:tid 27071] [client 24.73.125.82:56633] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 24.73.125.82 (+1 hits since last alert)|artmarialeon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "artmarialeon.com"] [uri "/xmlrpc.php"] [unique_id "ajwSoHjh1LNx9NZ3g3IX4QAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 12:07:31
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum. ...
show more
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 08:07:27.184239 2026] [security2:error] [pid 24053:tid 24053] [client 24.73.125.82:58906] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 24.73.125.82 (+1 hits since last alert)|papapizza.pizza|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "papapizza.pizza"] [uri "/xmlrpc.php"] [unique_id "ajvIf8uc3gZilxYA1Mrq_AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 17:09:55
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum. ...
show more
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 13:09:50.440965 2026] [security2:error] [pid 8411:tid 8411] [client 24.73.125.82:50259] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 24.73.125.82 (+1 hits since last alert)|towlesilvapsychotherapy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "towlesilvapsychotherapy.com"] [uri "/xmlrpc.php"] [unique_id "ajq93j2FTnOQgiYrkme4AwAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-23 13:33:40
(3 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ซ๐ท
dynamix
2026-06-16 18:04:48
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ช๐ธ
GranTech
2026-06-16 15:22:39
(1 week ago)
Brute-force login attack detected on https://grantech.es. 5 failed login attempts for username "admi ...
show more
Brute-force login attack detected on https://grantech.es. 5 failed login attempts for username "admin" within the configured time window.
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-16 14:26:19
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum. ...
show more
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 10:26:16.035705 2026] [security2:error] [pid 21617:tid 21617] [client 24.73.125.82:60692] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 24.73.125.82 (+1 hits since last alert)|birdlovesfish.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "birdlovesfish.com"] [uri "/xmlrpc.php"] [unique_id "ajFdCGQ5HXHNBINgrJYKlgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-06-11 19:00:50
(2 weeks ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-10 17:12:35
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum. ...
show more
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 13:12:31.421813 2026] [security2:error] [pid 8202:tid 8202] [client 24.73.125.82:56585] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 24.73.125.82 (+1 hits since last alert)|konahawaiirealty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "konahawaiirealty.com"] [uri "/xmlrpc.php"] [unique_id "aima_4ET_7fRtrjPOLyg3gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 16:11:37
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum. ...
show more
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 12:11:30.699800 2026] [security2:error] [pid 10838:tid 10945] [client 24.73.125.82:63493] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 24.73.125.82 (+1 hits since last alert)|tradersofficepark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tradersofficepark.com"] [uri "/xmlrpc.php"] [unique_id "aibpsoEIzUo_sHBIfuSK9wAAAdc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 18:14:15
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum. ...
show more
(mod_security) mod_security (id:240335) triggered by 24.73.125.82 (syn-024-073-125-082.biz.spectrum.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 14:14:12.365452 2026] [security2:error] [pid 27433:tid 27433] [client 24.73.125.82:54496] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 24.73.125.82 (+1 hits since last alert)|pharmaceuticalsalescertifications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pharmaceuticalsalescertifications.com"] [uri "/xmlrpc.php"] [unique_id "ah8ddEXqAunQbfA5pRXmtgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack