๐บ๐ธ
TPI-Abuse
2026-08-18 06:00:51
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 02:00:34.814631 2026] [security2:error] [pid 12004:tid 12004] [client 27.0.221.170:42651] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.170 (+1 hits since last alert)|margroberts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "margroberts.com"] [uri "/xmlrpc.php"] [unique_id "aoP1Aq3NTCchDha25H-zegAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-17 08:10:30
(5 days ago)
[redacted] 27.0.221.170 - - [17/Aug/2026:10:09:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Je ...
show more
[redacted] 27.0.221.170 - - [17/Aug/2026:10:09:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 27.0.221.170 - - [17/Aug/2026:10:09:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com"
[redacted] 27.0.221.170 - - [17/Aug/2026:10:10:09 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 27.0.221.170 - - [17/Aug/2026:10:10:22 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/13.0; WordPress/6.4; http://site60088787.com"
[redacted] 27.0.221.170 - - [17/Aug/2026:10:10:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 415 "-" "Jetpack/13.0; WordPress/6.1; http://site38707787.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-16 14:26:07
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 10:26:00.363014 2026] [security2:error] [pid 22743:tid 22743] [client 27.0.221.170:44736] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.170 (+1 hits since last alert)|wealthsec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wealthsec.com"] [uri "/xmlrpc.php"] [unique_id "aoHIeHuZrRCoLjS0pXWXzwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-08-14 11:23:45
(1 week ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐ฑ๐ป
garmtech.com
2026-08-14 11:18:34
(1 week ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 11:52:12
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 07:52:04.630076 2026] [security2:error] [pid 2533209:tid 2533209] [client 27.0.221.170:58379] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.170 (+1 hits since last alert)|williamfitzsimmons.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "williamfitzsimmons.com"] [uri "/xmlrpc.php"] [unique_id "an2v5D0PcntayiIz921upQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-08-13 10:21:07
(1 week ago)
(wordpress) Failed wordpress login from 27.0.221.170 (IN/India/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-10 04:13:33
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 00:13:24.026418 2026] [security2:error] [pid 6000:tid 6000] [client 27.0.221.170:62595] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.170 (+1 hits since last alert)|nidusmbt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nidusmbt.com"] [uri "/xmlrpc.php"] [unique_id "anlP5ARlb1Ur9CLJFhFigwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 11:41:50
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 07:41:44.367829 2026] [security2:error] [pid 2625039:tid 2625151] [client 27.0.221.170:46599] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.170 (+1 hits since last alert)|woofnrose.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "woofnrose.com"] [uri "/xmlrpc.php"] [unique_id "anXEeC3EWVRX_iANvQ2negAAAcA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-08-07 11:40:39
(2 weeks ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-geofence-sus.
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-07 09:23:43
(2 weeks ago)
(xmlrpc) Apache: Failed xmlrpc access from 27.0.221.170 (IN/India/-): 10 in the last 3600 secs (0-20 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 27.0.221.170 (IN/India/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-07 08:46:14
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:46:04.234115 2026] [security2:error] [pid 4110344:tid 4110344] [client 27.0.221.170:44491] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.170 (+1 hits since last alert)|mikedeutsch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mikedeutsch.com"] [uri "/xmlrpc.php"] [unique_id "anWbTHQSU-_HBNGKk6sGiwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-07-29 09:35:51
(3 weeks ago)
(xmlrpc) Failed xmlrpc access from 27.0.221.170 (IN/India/-): 5 in the last 3600 secs (0-122)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-20 10:20:45
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.170 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 06:20:37.054281 2026] [security2:error] [pid 15369:tid 15369] [client 27.0.221.170:12183] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.170 (+1 hits since last alert)|crep-psych.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "crep-psych.org"] [uri "/xmlrpc.php"] [unique_id "al32dfJyhKJ7-pGj-fOK0gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
bigwavedave
2026-07-20 10:19:50
(1 month ago)
Wordpress Attack
Web App Attack