๐ซ๐ท
masterguru
2026-06-09 16:19:45
(2 weeks ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐ฉ๐ช
konseptit
2026-06-09 10:42:37
(2 weeks ago)
(wordpress) Failed wordpress login from 27.60.20.198 (IN/India/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-09 00:37:52
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 20:37:48.933507 2026] [security2:error] [pid 9821:tid 9821] [client 27.60.20.198:1289] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.60.20.198 (+1 hits since last alert)|jessicalevant.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jessicalevant.com"] [uri "/xmlrpc.php"] [unique_id "aidgXNmtwp0vSc7qgHb7mgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 00:05:58
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 20:05:52.529307 2026] [security2:error] [pid 5554:tid 5554] [client 27.60.20.198:12415] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.60.20.198 (+1 hits since last alert)|cassialifesci.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cassialifesci.com"] [uri "/xmlrpc.php"] [unique_id "aidY4Hs3KacP_rok6ophvwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 22:59:35
(2 weeks ago)
WordPress Brute Force
Brute-Force
๐ท๐ด
iulianh
2026-06-08 20:06:49
(2 weeks ago)
80,443
Brute-Force
SSH
Anonymous
2026-06-08 18:53:07
(2 weeks ago)
(wordpress) Failed wordpress login from 27.60.20.198 (IN/India/-)
Brute-Force
Anonymous
2026-06-08 16:38:10
(2 weeks ago)
Attac
Brute-Force
Anonymous
2026-06-05 23:26:11
(2 weeks ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-05 22:45:25
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 18:45:19.003901 2026] [security2:error] [pid 15629:tid 15629] [client 27.60.20.198:37918] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.60.20.198 (+1 hits since last alert)|havilahmalone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "havilahmalone.com"] [uri "/xmlrpc.php"] [unique_id "aiNRf_Vt8QwAdPcZhYDmjwAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 22:15:17
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 18:15:10.204488 2026] [security2:error] [pid 4347:tid 4347] [client 27.60.20.198:28310] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.60.20.198 (+1 hits since last alert)|kentsavagelaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kentsavagelaw.com"] [uri "/xmlrpc.php"] [unique_id "aiNKbigY0GHxROyfsWfulQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 21:12:05
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 17:11:57.796071 2026] [security2:error] [pid 10418:tid 10444] [client 27.60.20.198:33985] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.60.20.198 (+1 hits since last alert)|fastesttrademark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fastesttrademark.com"] [uri "/xmlrpc.php"] [unique_id "aiM7naTrgfFjCqlCUEqVSwAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-05 16:04:41
(2 weeks ago)
[ns31.kdns.gr] httpd-xmlrpc-post: sites=teory.gr; logs=/var/log/httpd/domains/teory.gr.log; samples= ...
show more
[ns31.kdns.gr] httpd-xmlrpc-post: sites=teory.gr; logs=/var/log/httpd/domains/teory.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 14:32:40
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 27.60.20.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 10:32:35.823395 2026] [security2:error] [pid 22078:tid 22078] [client 27.60.20.198:17483] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.60.20.198 (+1 hits since last alert)|hayrun.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hayrun.com"] [uri "/xmlrpc.php"] [unique_id "aiLeA7HtZoY9XUAKN4ke2AAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-06-04 21:15:30
(2 weeks ago)
(wordpress) Failed wordpress login from 27.60.20.198 (IN/India/-): (CF_ENABLE)
Brute-Force