Anonymous
2026-06-18 04:52:57
(9 minutes ago)
[redacted] 45.127.121.242 - - [18/Jun/2026:06:52:14 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 45.127.121.242 - - [18/Jun/2026:06:52:14 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 45.127.121.242 - - [18/Jun/2026:06:52:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.4; http://site83929898.com"
[redacted] 45.127.121.242 - - [18/Jun/2026:06:52:34 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.2; http://site75119680.com"
[redacted] 45.127.121.242 - - [18/Jun/2026:06:52:45 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.4; http://site72154873.com"
[redacted] 45.127.121.242 - - [18/Jun/2026:06:52:55 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 10:52:41
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 06:52:28.914578 2026] [security2:error] [pid 28314:tid 28314] [client 45.127.121.242:60326] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.127.121.242 (+1 hits since last alert)|blindshine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "blindshine.com"] [uri "/xmlrpc.php"] [unique_id "ajJ8bF1WWhU6vAdjkxQhhgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-17 04:54:48
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 10:56:05
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 06:55:54.989227 2026] [security2:error] [pid 18167:tid 18178] [client 45.127.121.242:54337] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.127.121.242 (+1 hits since last alert)|nabsci.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nabsci.com"] [uri "/xmlrpc.php"] [unique_id "ajErulfksQPKMvwKO0moKwAAAYM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-15 05:56:45
(2 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-12 09:58:28
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 05:58:19.751496 2026] [security2:error] [pid 11588:tid 11588] [client 45.127.121.242:54537] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.127.121.242 (+1 hits since last alert)|faithlines.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "faithlines.com"] [uri "/xmlrpc.php"] [unique_id "aivYO4-aTkZvvpjqdblKgQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 05:47:37
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 01:47:25.468148 2026] [security2:error] [pid 15283:tid 15283] [client 45.127.121.242:61657] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.127.121.242 (+1 hits since last alert)|hawarcenter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hawarcenter.com"] [uri "/xmlrpc.php"] [unique_id "aiudbTFITBgfBPxD1HphXwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 05:54:19
(1 week ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-09 05:24:07
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:23:55.483342 2026] [security2:error] [pid 10112:tid 10122] [client 45.127.121.242:61548] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.127.121.242 (+1 hits since last alert)|whatismetamodern.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whatismetamodern.com"] [uri "/xmlrpc.php"] [unique_id "aieja5QXdYlI3rBDGe1HrQAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 09:47:20
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 05:47:07.809954 2026] [security2:error] [pid 4671:tid 4671] [client 45.127.121.242:53132] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.127.121.242 (+1 hits since last alert)|sizefinder.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sizefinder.com"] [uri "/xmlrpc.php"] [unique_id "aiaPmysZiy9bCbT97TWEAgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 05:40:45
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 01:40:33.314297 2026] [security2:error] [pid 17824:tid 17824] [client 45.127.121.242:55596] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.127.121.242 (+1 hits since last alert)|soonerstone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "soonerstone.com"] [uri "/xmlrpc.php"] [unique_id "aiZV0TmzILAJpOzgX7u7CAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-08 03:49:57
(1 week ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-08 03:48:43
(1 week ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐บ๐ธ
TAY
2026-06-06 07:03:06
(1 week ago)
45.127.121.242 - - [06/Jun/2026:15:02:41 +0800] "POST /xmlrpc.php HTTP/1.1" 200 3833 "-" "Jetpack by ...
show more
45.127.121.242 - - [06/Jun/2026:15:02:41 +0800] "POST /xmlrpc.php HTTP/1.1" 200 3833 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
45.127.121.242 - - [06/Jun/2026:15:02:31 +0800] "POST /xmlrpc.php HTTP/1.1" 200 3833 "-" "Jetpack by WordPress.com"
45.127.121.242 - - [06/Jun/2026:15:02:51 +0800] "POST /xmlrpc.php HTTP/1.1" 200 3833 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-06 06:49:40
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 45.127.121.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 02:49:31.569479 2026] [security2:error] [pid 16817:tid 16817] [client 45.127.121.242:64321] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.127.121.242 (+1 hits since last alert)|kaylamaclaincounseling.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kaylamaclaincounseling.com"] [uri "/xmlrpc.php"] [unique_id "aiPC-24pkoaIi8KJ0DUXHgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack