Anonymous
2026-06-25 12:23:04
(9 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-06-25 11:58:21
(9 hours ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-25 10:13:27
(11 hours ago)
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 06:13:22.618282 2026] [security2:error] [pid 17445:tid 17463] [client 27.5.124.235:53783] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.5.124.235 (+1 hits since last alert)|jpdesign.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jpdesign.us"] [uri "/xmlrpc.php"] [unique_id "ajz_QguRZW9nGBExEwAfagAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-06-25 08:44:33
(12 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ท
dynamix
2026-06-24 10:45:46
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 09:15:50
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 05:15:43.466925 2026] [security2:error] [pid 21542:tid 21542] [client 27.5.124.235:61551] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.5.124.235 (+1 hits since last alert)|joevallone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "joevallone.com"] [uri "/xmlrpc.php"] [unique_id "ajugP9G9-OVTIjHTesknSQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 07:43:27
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 03:43:21.915182 2026] [security2:error] [pid 15452:tid 15452] [client 27.5.124.235:61109] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.5.124.235 (+1 hits since last alert)|soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "soundtrax.net"] [uri "/xmlrpc.php"] [unique_id "ajuKmXK1aYxejNvyZK02YwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 04:45:48
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 00:45:42.209438 2026] [security2:error] [pid 7143:tid 7143] [client 27.5.124.235:53197] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.5.124.235 (+1 hits since last alert)|tedharris.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tedharris.com"] [uri "/xmlrpc.php"] [unique_id "ajtg9nkO2aAySi9H_Ug0lwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 12:21:38
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 08:21:31.404040 2026] [security2:error] [pid 25188:tid 25188] [client 27.5.124.235:55337] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.5.124.235 (+1 hits since last alert)|cnphilos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cnphilos.com"] [uri "/xmlrpc.php"] [unique_id "ajp6S9bYdY5aJOfaiCuJaQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 11:46:23
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 07:46:18.390911 2026] [security2:error] [pid 14510:tid 14510] [client 27.5.124.235:50861] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.5.124.235 (+1 hits since last alert)|jennyfiore.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jennyfiore.com"] [uri "/xmlrpc.php"] [unique_id "ajpyCmacIQXbwHsdekZdHwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 09:43:58
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 05:43:52.011904 2026] [security2:error] [pid 28575:tid 28575] [client 27.5.124.235:60859] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.5.124.235 (+1 hits since last alert)|microbooty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "microbooty.com"] [uri "/xmlrpc.php"] [unique_id "ajpVWOzgQZ-kBdpB_ShZCwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 09:15:35
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in t ...
show more
(mod_security) mod_security (id:240335) triggered by 27.5.124.235 (124.5.27.235.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 05:15:30.844159 2026] [security2:error] [pid 31710:tid 31710] [client 27.5.124.235:53146] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.5.124.235 (+1 hits since last alert)|nypatriotcards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nypatriotcards.com"] [uri "/xmlrpc.php"] [unique_id "ajpOsvR2oXbm-zPPutVDMgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-23 08:28:03
(2 days ago)
5.915 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ซ๐ท
masterguru
2026-06-23 07:30:49
(2 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ฒ๐พ
Rizzy
2026-06-23 07:14:00
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack