Anonymous
2026-06-18 09:04:36
(18 hours ago)
[redacted] 43.241.66.27 - - [18/Jun/2026:11:03:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 43.241.66.27 - - [18/Jun/2026:11:03:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 43.241.66.27 - - [18/Jun/2026:11:04:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 43.241.66.27 - - [18/Jun/2026:11:04:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
[redacted] 43.241.66.27 - - [18/Jun/2026:11:04:22 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 43.241.66.27 - - [18/Jun/2026:11:04:32 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-18 08:39:13
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 43.241.66.27 (27.66.241.43-in-addr.arpa-mithril ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.66.27 (27.66.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 04:39:08.051353 2026] [security2:error] [pid 26411:tid 26411] [client 43.241.66.27:17899] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.66.27 (+1 hits since last alert)|avantgarde-hk.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "avantgarde-hk.org"] [uri "/xmlrpc.php"] [unique_id "ajOurMk8zXDn0vgGVvtfnAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 12:10:49
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 43.241.66.27 (27.66.241.43-in-addr.arpa-mithril ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.66.27 (27.66.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 08:10:42.547385 2026] [security2:error] [pid 2150:tid 2150] [client 43.241.66.27:10956] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.66.27 (+1 hits since last alert)|ideaofauniversity.website|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ideaofauniversity.website"] [uri "/xmlrpc.php"] [unique_id "ahbfQtcnED6saP7WN6Fz6QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-27 12:08:46
(3 weeks ago)
Attac
Brute-Force
Anonymous
2026-05-27 06:04:30
(3 weeks ago)
(wordpress) Failed wordpress login from 43.241.66.27 (IN/India/Telangana/Hyderabad/27.66.241.43-in-a ...
show more
(wordpress) Failed wordpress login from 43.241.66.27 (IN/India/Telangana/Hyderabad/27.66.241.43-in-addr.arpa-mithriltele.net/[redacted])
show less
Brute-Force
Anonymous
2026-05-26 11:49:10
(3 weeks ago)
Attac
Brute-Force
Anonymous
2026-05-25 13:06:02
(3 weeks ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-05-25 06:31:19
(3 weeks ago)
Attac
Brute-Force
๐บ๐ธ
Dolphi
2026-05-25 05:40:08
(3 weeks ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack
Anonymous
2026-05-23 12:37:37
(3 weeks ago)
[redacted] 43.241.66.27 - - [23/May/2026:14:36:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 43.241.66.27 - - [23/May/2026:14:36:57 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
[redacted] 43.241.66.27 - - [23/May/2026:14:37:04 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.4; http://site15587247.com"
[redacted] 43.241.66.27 - - [23/May/2026:14:37:15 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.1; http://site46617582.com"
[redacted] 43.241.66.27 - - [23/May/2026:14:37:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 43.241.66.27 - - [23/May/2026:14:37:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-05-23 07:23:28
(3 weeks ago)
[redacted] 43.241.66.27 - - [23/May/2026:09:22:48 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 43.241.66.27 - - [23/May/2026:09:22:48 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
[redacted] 43.241.66.27 - - [23/May/2026:09:22:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 43.241.66.27 - - [23/May/2026:09:23:05 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 43.241.66.27 - - [23/May/2026:09:23:17 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.3)"
[redacted] 43.241.66.27 - - [23/May/2026:09:23:26 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-23 04:15:51
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 43.241.66.27 (27.66.241.43-in-addr.arpa-mithril ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.66.27 (27.66.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 23 00:15:44.255507 2026] [security2:error] [pid 29035:tid 29035] [client 43.241.66.27:10263] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.66.27 (+1 hits since last alert)|ssion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ssion.com"] [uri "/xmlrpc.php"] [unique_id "ahEp8IGNnz856MroWf-RNwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 10:32:32
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 43.241.66.27 (27.66.241.43-in-addr.arpa-mithril ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.66.27 (27.66.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 06:32:26.015299 2026] [security2:error] [pid 30731:tid 30731] [client 43.241.66.27:10260] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.66.27 (+1 hits since last alert)|kdgsf.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kdgsf.xyz"] [uri "/xmlrpc.php"] [unique_id "ahAwuqxkYlKbiPQ_YGTXqgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-22 07:07:14
(3 weeks ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-22 05:06:15
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 43.241.66.27 (27.66.241.43-in-addr.arpa-mithril ...
show more
(mod_security) mod_security (id:240335) triggered by 43.241.66.27 (27.66.241.43-in-addr.arpa-mithriltele.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 01:06:09.278651 2026] [security2:error] [pid 18704:tid 18704] [client 43.241.66.27:10868] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.241.66.27 (+1 hits since last alert)|abundancecompany.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abundancecompany.com"] [uri "/xmlrpc.php"] [unique_id "ag_kQbfGWTtpeoazmqX0kgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack