๐ซ๐ฎ
YF
2026-04-22 08:00:22
(4 months ago)
xmlrpc.php (Potential DDoS or brute force)
Brute-Force
Web App Attack
๐บ๐ธ
WellSpring
2026-04-22 00:11:38
(4 months ago)
xmlrpc exploit on comrepute.org/xmlrpc.php โ WellSpr.ing/NetSentinel civic-AI security layer
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-21 22:49:30
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 18:49:21.489199 2026] [security2:error] [pid 1238839:tid 1238839] [client 41.111.242.66:16630] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.111.242.66 (+1 hits since last alert)|digi-estudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "digi-estudio.com"] [uri "/xmlrpc.php"] [unique_id "aef-8WpMJ1PRjKGCuInbQwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-21 16:33:42
(4 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฆ๐บ
screwlooseit.com.au
2026-04-21 12:57:56
(4 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
DZ/Algeria/-
Web App Attack
๐ซ๐ท
dynamix
2026-04-21 11:35:17
(4 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-21 08:56:05
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 04:55:59.606643 2026] [security2:error] [pid 3991858:tid 3991858] [client 41.111.242.66:55767] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.111.242.66 (+1 hits since last alert)|abeltours.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abeltours.com"] [uri "/xmlrpc.php"] [unique_id "aec7n06O5hi7yqBSxNwcAwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-04-21 03:40:44
(4 months ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-20 19:26:36
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 15:26:28.220232 2026] [security2:error] [pid 1364951:tid 1364967] [client 41.111.242.66:29968] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.111.242.66 (+1 hits since last alert)|northtexaslive.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "northtexaslive.com"] [uri "/xmlrpc.php"] [unique_id "aeZ95IcPUp5vloyAXRHcCAAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-20 17:21:39
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 13:21:30.670456 2026] [security2:error] [pid 4100960:tid 4100960] [client 41.111.242.66:4843] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.111.242.66 (+1 hits since last alert)|newcitypark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "newcitypark.com"] [uri "/xmlrpc.php"] [unique_id "aeZgmt-J09owX32AvaeoQgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dwmp
2026-04-20 16:35:08
(4 months ago)
WordPress login Brute-Force
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-20 14:57:17
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 10:57:11.918680 2026] [security2:error] [pid 364827:tid 364827] [client 41.111.242.66:7049] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.111.242.66 (+1 hits since last alert)|crittergetterpestcontrol.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "crittergetterpestcontrol.com"] [uri "/xmlrpc.php"] [unique_id "aeY-xy_qBFfPE3sH4HAL_gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-20 13:56:40
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 09:56:33.413985 2026] [security2:error] [pid 2094462:tid 2094462] [client 41.111.242.66:42934] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.111.242.66 (+1 hits since last alert)|comunicacion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "comunicacion.com"] [uri "/xmlrpc.php"] [unique_id "aeYwkdriJR0cQzukXgYAcgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-20 09:30:51
(4 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-04-20 00:24:54
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.111.242.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 20:24:48.399764 2026] [security2:error] [pid 840229:tid 840229] [client 41.111.242.66:16712] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.111.242.66 (+1 hits since last alert)|brianwhitty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "brianwhitty.com"] [uri "/xmlrpc.php"] [unique_id "aeVyUDC0TfCTWszI2jq5nQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack