🇺🇸
TPI-Abuse
2026-08-25 06:11:31
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 02:11:22.418197 2026] [security2:error] [pid 14608:tid 14608] [client 27.0.221.173:30459] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.173 (+1 hits since last alert)|btccasting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "btccasting.com"] [uri "/xmlrpc.php"] [unique_id "ao0yCk_L0dUflExwWFwXDQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 07:52:23
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 03:52:16.028667 2026] [security2:error] [pid 14110:tid 14110] [client 27.0.221.173:47988] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.173 (+1 hits since last alert)|tcomputerguy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tcomputerguy.com"] [uri "/xmlrpc.php"] [unique_id "aolVML30FocByEZqNQTVywAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 07:18:38
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 03:18:31.003362 2026] [security2:error] [pid 15843:tid 15843] [client 27.0.221.173:17163] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.173 (+1 hits since last alert)|levijoneslegal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "levijoneslegal.com"] [uri "/xmlrpc.php"] [unique_id "aolNRvVYMwUaLmEL5e2KuwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 05:15:19
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 01:15:08.135180 2026] [security2:error] [pid 1377:tid 1377] [client 27.0.221.173:2683] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.173 (+1 hits since last alert)|tcit.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tcit.org"] [uri "/xmlrpc.php"] [unique_id "aokwXE0rKBdGNYU2MiTnOQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 07:51:33
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 03:51:24.756987 2026] [security2:error] [pid 1429332:tid 1429332] [client 27.0.221.173:41111] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.173 (+1 hits since last alert)|assembliesofgodinsamoa.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "assembliesofgodinsamoa.org"] [uri "/xmlrpc.php"] [unique_id "anrUfMEsSt7nQVdgs7d1swAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 06:28:04
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 02:27:54.098828 2026] [security2:error] [pid 3985:tid 4036] [client 27.0.221.173:44585] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.173 (+1 hits since last alert)|asetiadi.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "asetiadi.net"] [uri "/xmlrpc.php"] [unique_id "anrA6kB6Fmc424lPbGbhoQAAAZY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-06 07:54:13
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 03:54:08.293087 2026] [security2:error] [pid 15106:tid 15106] [client 27.0.221.173:39111] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.173 (+1 hits since last alert)|roguetechink.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "roguetechink.com"] [uri "/xmlrpc.php"] [unique_id "aiPSIJZQpf4u1kR2KkdhHAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-06 05:39:05
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 01:38:58.613971 2026] [security2:error] [pid 4916:tid 4916] [client 27.0.221.173:38635] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||richmondrents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "richmondrents.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiOyclr1V6Qli30_9nU-9QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-06 04:58:03
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 00:57:55.533918 2026] [security2:error] [pid 14832:tid 14832] [client 27.0.221.173:25956] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.173 (+1 hits since last alert)|jazziiafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jazziiafoundation.org"] [uri "/xmlrpc.php"] [unique_id "aiOo07UWBHz2hj1cIf2PnAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WellSpring
2026-06-06 04:16:21
(2 months ago)
xmlrpc exploit on 262.today/xmlrpc.php — WellSpr.ing/NetSentinel civic-AI security layer
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-06-03 05:58:14
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 01:58:09.211616 2026] [security2:error] [pid 16527:tid 16527] [client 27.0.221.173:11686] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.173 (+1 hits since last alert)|anchor07.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "anchor07.com"] [uri "/xmlrpc.php"] [unique_id "ah_CcXMwQk-KZk3Tfmos1AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-03 04:24:57
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 00:24:54.008335 2026] [security2:error] [pid 13656:tid 13656] [client 27.0.221.173:52300] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.173 (+1 hits since last alert)|tenmenband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tenmenband.com"] [uri "/xmlrpc.php"] [unique_id "ah-slppHnUBlsPu_5Z61XwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-02 06:08:17
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.0.221.173 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 02:08:10.689463 2026] [security2:error] [pid 27600:tid 27600] [client 27.0.221.173:20010] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.0.221.173 (+1 hits since last alert)|lawrencehale.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lawrencehale.com"] [uri "/xmlrpc.php"] [unique_id "ah5zShnYqW1UultNGVqwjwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-05-29 05:31:22
(3 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-05-29 04:54:48
(3 months ago)
Attac
Brute-Force