Anonymous
2026-06-04 18:47:34
(8 hours ago)
27.124.64.29 - - [04/Jun/2026:20:47:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by Wo ...
show more
27.124.64.29 - - [04/Jun/2026:20:47:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
27.124.64.29 - - [04/Jun/2026:20:47:13 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
27.124.64.29 - - [04/Jun/2026:20:47:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
27.124.64.29 - - [04/Jun/2026:20:47:23 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
27.124.64.29 - - [04/Jun/2026:20:47:33 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack/12.0; WordPress/6.4; http://site45465818.com"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-04 18:43:56
(8 hours ago)
(wordpress) Failed wordpress login from 27.124.64.29 (IN/India/27.124.64.29.mta1.ethen.in)
Brute-Force
Anonymous
2026-06-04 18:22:40
(8 hours ago)
Attac
Brute-Force
๐ซ๐ท
Lunix
2026-06-04 16:55:05
(10 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 16:29:46
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 27.124.64.29 (27.124.64.29.mta1.ethen.in): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 27.124.64.29 (27.124.64.29.mta1.ethen.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 12:29:41.333749 2026] [security2:error] [pid 22829:tid 22829] [client 27.124.64.29:61389] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.124.64.29 (+1 hits since last alert)|haverhillhouse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "haverhillhouse.com"] [uri "/xmlrpc.php"] [unique_id "aiGn9X--bqXqrgbjHYeWvAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-04 15:02:11
(11 hours ago)
(wordpress) Failed wordpress login from 27.124.64.29 (IN/India/27.124.64.29.mta1.ethen.in)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-04 14:06:56
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 27.124.64.29 (27.124.64.29.mta1.ethen.in): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 27.124.64.29 (27.124.64.29.mta1.ethen.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 10:06:52.293512 2026] [security2:error] [pid 3957:tid 3957] [client 27.124.64.29:52396] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.124.64.29 (+1 hits since last alert)|glassclublake.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "glassclublake.com"] [uri "/xmlrpc.php"] [unique_id "aiGGfJJzuTMtMP_J2IB3VwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-04 12:30:43
(14 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
reznekcs
2026-06-04 12:28:33
(14 hours ago)
F2B wordpress ban. Logs: 27.124.64.29 - - [04/Jun/2026:14:28:21 +0200] "POST /xmlrpc.php HTTP/1.1" 2 ...
show more
F2B wordpress ban. Logs: 27.124.64.29 - - [04/Jun/2026:14:28:21 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4308 "-" "Jetpack/13.0; WordPress/6.2; http://site57655006.com"
27.124.64.29 - - [04/Jun/2026:14:28:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4308 "-" "Jetpack/12.1; WordPress/6.3; http://site30523207.com"
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-03 17:11:14
(1 day ago)
(xmlrpc) Apache: Failed xmlrpc access from 27.124.64.29 (IN/India/27.124.64.29.mta1.ethen.in): 10 in ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 27.124.64.29 (IN/India/27.124.64.29.mta1.ethen.in): 10 in the last 3600 secs (0-201)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-02 21:31:27
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 27.124.64.29 (27.124.64.29.mta1.ethen.in): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 27.124.64.29 (27.124.64.29.mta1.ethen.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 17:31:20.588226 2026] [security2:error] [pid 14454:tid 14454] [client 27.124.64.29:58316] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.124.64.29 (+1 hits since last alert)|xcarsubscription.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "xcarsubscription.com"] [uri "/xmlrpc.php"] [unique_id "ah9LqMrFyMbHLvhMYXKFuAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-02 21:26:25
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-02 17:38:54
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 27.124.64.29 (27.124.64.29.mta1.ethen.in): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 27.124.64.29 (27.124.64.29.mta1.ethen.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:38:49.650740 2026] [security2:error] [pid 14191:tid 14191] [client 27.124.64.29:52438] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.124.64.29 (+1 hits since last alert)|globaldentalservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "globaldentalservices.com"] [uri "/xmlrpc.php"] [unique_id "ah8VKet7QbsUQeIHTViz0QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 14:24:29
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 27.124.64.29 (27.124.64.29.mta1.ethen.in): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 27.124.64.29 (27.124.64.29.mta1.ethen.in): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 10:24:22.933555 2026] [security2:error] [pid 1908:tid 1908] [client 27.124.64.29:58979] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.124.64.29 (+1 hits since last alert)|uphillfarmvt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "uphillfarmvt.com"] [uri "/xmlrpc.php"] [unique_id "ah7nlkxBEQzln_qgyS2cLAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 13:38:41
(2 days ago)
Attac
Brute-Force