Anonymous
2026-08-11 11:48:48
(1 week ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=www.crisis-management2017.eu; logs=/var/log/httpd/domains/c ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=www.crisis-management2017.eu; logs=/var/log/httpd/domains/crisis-management2017.eu.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 08:25:56
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.166 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 04:25:48.459096 2026] [security2:error] [pid 3767666:tid 3767666] [client 27.0.221.166:39910] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.166 (+1 hits since last alert)|xhumanlikerobots.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "xhumanlikerobots.com"] [uri "/xmlrpc.php"] [unique_id "anrcjAuVhSE7LbLdqf4AWgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-03 07:55:06
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.166 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 03 03:54:57.981912 2026] [security2:error] [pid 3282152:tid 3282152] [client 27.0.221.166:48956] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.166 (+1 hits since last alert)|mahjongcouture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mahjongcouture.com"] [uri "/xmlrpc.php"] [unique_id "anBJUVwGELBBNOD2eSA78gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-03 07:20:43
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-03 07:19:29
(2 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-07-16 12:37:37
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ซ๐ฎ
KnightIndustries
2026-06-19 05:15:06
(2 months ago)
2026-06-19T07:14:46.283798+02:00 milkyway wordpress(oldscarborough.com)[145962]: XML-RPC authenticat ...
show more
2026-06-19T07:14:46.283798+02:00 milkyway wordpress(oldscarborough.com)[145962]: XML-RPC authentication failure for joshua from 27.0.221.166
2026-06-19T07:14:55.683537+02:00 milkyway wordpress(oldscarborough.com)[145970]: XML-RPC authentication failure for joshua from 27.0.221.166
2026-06-19T07:15:06.272338+02:00 milkyway wordpress(oldscarborough.com)[141982]: XML-RPC authentication failure for joshua from 27.0.221.166
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-16 07:49:01
(2 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 11:44:14
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.166 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 07:44:08.971911 2026] [security2:error] [pid 22083:tid 22083] [client 27.0.221.166:8670] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.166 (+1 hits since last alert)|carolinafootprints.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "carolinafootprints.com"] [uri "/xmlrpc.php"] [unique_id "ai_liE35T9xbCppsRBl-PgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-12 04:33:46
(2 months ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ฆ๐บ
QT
2026-06-12 03:32:47
(2 months ago)
Unauthorised WordPress admin login attempted at 2026-06-12 13:32:46 +1000
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 09:23:44
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.166 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 05:23:36.430851 2026] [security2:error] [pid 22546:tid 22546] [client 27.0.221.166:57832] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.166 (+1 hits since last alert)|kildarafarms.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kildarafarms.com"] [uri "/xmlrpc.php"] [unique_id "ah_ymGLSALRzfCWNAUCKRAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 10:06:40
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.166 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 06:06:36.293016 2026] [security2:error] [pid 13760:tid 13772] [client 27.0.221.166:60838] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.166 (+1 hits since last alert)|willmanlawfirm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "willmanlawfirm.com"] [uri "/xmlrpc.php"] [unique_id "ah1ZrEILotV6aUeDML8kZQAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-01 08:30:07
(2 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
Marc
2026-06-01 06:58:18
(2 months ago)
27.0.221.166 - - [01/Jun/2026:08:57:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3209 "-" "Jetpack by W ...
show more
27.0.221.166 - - [01/Jun/2026:08:57:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3209 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)" 27.0.221.166 - - [01/Jun/2026:08:58:05 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3209 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)" 27.0.221.166 - - [01/Jun/2026:08:58:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3209 "-" "WordPress.com; https://wordpress.com"
show less
Brute-Force
Web App Attack