๐ฉ๐ช
DocNetzwerk
2026-06-05 12:50:44
(3 months ago)
(wordpress) Failed wordpress login from 27.6.40.140 (IN/India/40.6.27.140.hathway.com)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-05 12:23:39
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 08:23:34.369091 2026] [security2:error] [pid 32711:tid 32711] [client 27.6.40.140:56602] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.6.40.140 (+1 hits since last alert)|pathpa.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pathpa.org"] [uri "/xmlrpc.php"] [unique_id "aiK_xjOo6qGTPRnqfTTWUAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 11:42:07
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 07:41:58.803760 2026] [security2:error] [pid 28138:tid 28138] [client 27.6.40.140:64327] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.6.40.140 (+1 hits since last alert)|premierveterinarysurgery.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "premierveterinarysurgery.com"] [uri "/xmlrpc.php"] [unique_id "aiK2BsTfXWnPrdnLKy155AAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-06-05 08:15:49
(3 months ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 15:22:27
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 11:22:20.259157 2026] [security2:error] [pid 727:tid 727] [client 27.6.40.140:63758] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.6.40.140 (+1 hits since last alert)|asociacioncopan.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "asociacioncopan.org"] [uri "/xmlrpc.php"] [unique_id "aiGYLMoGRMdpE1EFogA7WwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 14:49:29
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 10:49:23.399311 2026] [security2:error] [pid 28292:tid 28292] [client 27.6.40.140:53816] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.6.40.140 (+1 hits since last alert)|hertzan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hertzan.com"] [uri "/xmlrpc.php"] [unique_id "aiGQcx1ZSSeSe8wfO1lveAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 10:01:34
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 06:01:26.919078 2026] [security2:error] [pid 1833:tid 1833] [client 27.6.40.140:53574] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.6.40.140 (+1 hits since last alert)|richmondrents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "richmondrents.com"] [uri "/xmlrpc.php"] [unique_id "ah_7duIRXCrsRCvzrzTDeAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 08:58:13
(3 months ago)
Attac
Brute-Force
๐ซ๐ฎ
YF
2026-05-29 12:06:17
(3 months ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
Anonymous
2026-05-29 10:38:04
(3 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-05-29 09:05:27
(3 months ago)
[ns19.kdns.gr] httpd-xmlrpc-post: sites=microtech.com.cy; logs=/var/log/httpd/domains/microtech.com. ...
show more
[ns19.kdns.gr] httpd-xmlrpc-post: sites=microtech.com.cy; logs=/var/log/httpd/domains/microtech.com.cy.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 14:11:36
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the ...
show more
(mod_security) mod_security (id:240335) triggered by 27.6.40.140 (40.6.27.140.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 10:11:30.492826 2026] [security2:error] [pid 6576:tid 6576] [client 27.6.40.140:49255] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.6.40.140 (+1 hits since last alert)|tcit.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tcit.org"] [uri "/xmlrpc.php"] [unique_id "ahhNEgSEWsrZE4ID2LSNvwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
applemooz
2026-05-28 10:45:40
(3 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
Anonymous
2026-05-28 08:25:13
(3 months ago)
Attac
Brute-Force
Anonymous
2026-05-28 08:08:41
(3 months ago)
[redacted] 27.6.40.140 - - [28/May/2026:10:07:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jet ...
show more
[redacted] 27.6.40.140 - - [28/May/2026:10:07:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 27.6.40.140 - - [28/May/2026:10:08:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.1; http://site79011409.com"
[redacted] 27.6.40.140 - - [28/May/2026:10:08:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 27.6.40.140 - - [28/May/2026:10:08:27 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 27.6.40.140 - - [28/May/2026:10:08:38 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack