๐บ๐ธ
TPI-Abuse
2026-06-19 06:26:28
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 02:26:23.773307 2026] [security2:error] [pid 899:tid 899] [client 27.0.221.167:50092] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.167 (+1 hits since last alert)|hawarcenter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hawarcenter.com"] [uri "/xmlrpc.php"] [unique_id "ajThD5qafsNhbZ3oHVwgUwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-19 06:12:17
(2 hours ago)
27.0.221.167 - - [19/Jun/2026:08:11:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by Wo ...
show more
27.0.221.167 - - [19/Jun/2026:08:11:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
27.0.221.167 - - [19/Jun/2026:08:11:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
27.0.221.167 - - [19/Jun/2026:08:12:05 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
27.0.221.167 - - [19/Jun/2026:08:12:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
27.0.221.167 - - [19/Jun/2026:08:12:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-19 05:11:24
(3 hours ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-19 04:12:16
(4 hours ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 00:12:11.710390 2026] [security2:error] [pid 9647:tid 9647] [client 27.0.221.167:32008] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.167 (+1 hits since last alert)|midwayisland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "midwayisland.com"] [uri "/xmlrpc.php"] [unique_id "ajTBmxoze0wTe_rrbkFq4gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 05:27:10
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 01:27:02.082001 2026] [security2:error] [pid 26222:tid 26235] [client 27.0.221.167:64856] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.167 (+1 hits since last alert)|leaderoftheopposition.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "leaderoftheopposition.com"] [uri "/xmlrpc.php"] [unique_id "ajOBpluyT_6TVVTeRUaFVgAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-06-18 04:25:02
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-18 04:24:26
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 10:31:05
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 06:30:59.027328 2026] [security2:error] [pid 18448:tid 18448] [client 27.0.221.167:21320] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.167 (+1 hits since last alert)|margroberts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "margroberts.com"] [uri "/xmlrpc.php"] [unique_id "ajJ3Y71q10AZOTyaIWcicgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 07:54:23
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 03:54:15.986633 2026] [security2:error] [pid 18192:tid 18192] [client 27.0.221.167:15605] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.167 (+1 hits since last alert)|indoorsfinishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "indoorsfinishing.com"] [uri "/xmlrpc.php"] [unique_id "ajEBJ_LCN1c4FZqAb8hNjgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-16 04:58:38
(3 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐ฉ๐ช
yvoictra
2026-06-16 04:38:02
(3 days ago)
27.0.221.167 - - [16/Jun/2026:06:37:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack by Wo ...
show more
27.0.221.167 - - [16/Jun/2026:06:37:09 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack by WordPress.com"
27.0.221.167 - - [16/Jun/2026:06:37:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack by WordPress.com"
27.0.221.167 - - [16/Jun/2026:06:37:29 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack by WordPress.com"
27.0.221.167 - - [16/Jun/2026:06:37:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack by WordPress.com"
27.0.221.167 - - [16/Jun/2026:06:37:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack/12.5; WordPress/6.1; http://site23042369.com"
27.0.221.167 - - [16/Jun/2026:06:38:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-11 07:17:10
(1 week ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=goingkoi.com.cy; logs=/var/log/httpd/domains/goingkoi.com.cy ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=goingkoi.com.cy; logs=/var/log/httpd/domains/goingkoi.com.cy.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
Anonymous
2026-06-02 06:52:46
(2 weeks ago)
Attac
Brute-Force
Anonymous
2026-05-27 11:31:39
(3 weeks ago)
27.0.221.167 - - [27/May/2026:13:31:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by Wo ...
show more
27.0.221.167 - - [27/May/2026:13:31:18 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
27.0.221.167 - - [27/May/2026:13:31:20 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
27.0.221.167 - - [27/May/2026:13:31:27 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
27.0.221.167 - - [27/May/2026:13:31:28 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
27.0.221.167 - - [27/May/2026:13:31:37 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 11:08:41
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.167 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 07:08:37.609773 2026] [security2:error] [pid 18527:tid 18527] [client 27.0.221.167:65287] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.167 (+1 hits since last alert)|sizefinder.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sizefinder.com"] [uri "/xmlrpc.php"] [unique_id "ahbQtZxz_clr1pKcsi0WLAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack