๐ช๐ธ
Gem
2026-06-26 22:14:47
(1 day ago)
Unauthorized web scan.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 13:17:18
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 27.7.55.55 (55.7.27.55.hathway.com): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 27.7.55.55 (55.7.27.55.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 09:17:11.656568 2026] [security2:error] [pid 10564:tid 10564] [client 27.7.55.55:64813] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.7.55.55 (+1 hits since last alert)|tedharris.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tedharris.com"] [uri "/xmlrpc.php"] [unique_id "aj0qV9D1nT72jMrLqou5UAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 12:46:41
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 27.7.55.55 (55.7.27.55.hathway.com): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 27.7.55.55 (55.7.27.55.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 08:46:36.364797 2026] [security2:error] [pid 28968:tid 28972] [client 27.7.55.55:53448] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.7.55.55 (+1 hits since last alert)|artmarialeon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "artmarialeon.com"] [uri "/xmlrpc.php"] [unique_id "aj0jLLe86Q_NROHOy3QLdwAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-25 12:19:05
(3 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-06-25 11:58:52
(3 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-06-25 10:52:17
(3 days ago)
(wordpress) Failed wordpress login from 27.7.55.55 (IN/India/Telangana/Hyderabad/55.7.27.55.hathway. ...
show more
(wordpress) Failed wordpress login from 27.7.55.55 (IN/India/Telangana/Hyderabad/55.7.27.55.hathway.com/[redacted])
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-25 10:44:17
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 27.7.55.55 (55.7.27.55.hathway.com): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 27.7.55.55 (55.7.27.55.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 06:44:11.188770 2026] [security2:error] [pid 1063:tid 1063] [client 27.7.55.55:62426] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.7.55.55 (+1 hits since last alert)|d-sinema.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "d-sinema.com"] [uri "/xmlrpc.php"] [unique_id "aj0Ge7w1pDb1Z8OqvTRDmAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lunix
2026-06-25 08:36:37
(3 days ago)
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-06-25 06:35:39
(3 days ago)
4.663 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-25 06:02:11
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 27.7.55.55 (55.7.27.55.hathway.com): 1 in the l ...
show more
(mod_security) mod_security (id:240335) triggered by 27.7.55.55 (55.7.27.55.hathway.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 02:02:06.064772 2026] [security2:error] [pid 23202:tid 23202] [client 27.7.55.55:60215] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.7.55.55 (+1 hits since last alert)|gasoilliquidsdaily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gasoilliquidsdaily.com"] [uri "/xmlrpc.php"] [unique_id "ajzEXkR3mrQpYl0WAm1l6gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
applemooz
2026-06-25 04:40:25
(3 days ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack