Anonymous
2026-05-13 10:29:04
(3 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
kjaerulff
2026-05-12 12:26:39
(4 months ago)
Failed Wordpress login using xmlrpc.php
Web App Attack
๐ฒ๐พ
Rizzy
2026-05-11 15:22:38
(4 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2026-05-10 13:03:42
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (EG/Egypt/-): 5 in the last 300 se ...
show more
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (EG/Egypt/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 12:00:07
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 08:00:00.469128 2026] [security2:error] [pid 10890:tid 10890] [client 45.247.15.27:59088] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.247.15.27 (+1 hits since last alert)|americanexportimport.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "americanexportimport.com"] [uri "/xmlrpc.php"] [unique_id "agBzQPh1kr0W0vjDEzH7pQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-09 17:53:33
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 13:53:26.299584 2026] [security2:error] [pid 5287:tid 5290] [client 45.247.15.27:28099] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.247.15.27 (+1 hits since last alert)|cynosureinternetservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cynosureinternetservices.com"] [uri "/xmlrpc.php"] [unique_id "af90lhkw-XByICbhGhd1kAAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-05-07 14:38:14
(4 months ago)
(wordpress) Failed wordpress login from 45.247.15.27 (EG/Egypt/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-06 16:55:51
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 12:55:43.588146 2026] [security2:error] [pid 22836:tid 22836] [client 45.247.15.27:53499] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.247.15.27 (+1 hits since last alert)|susanoneill.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "susanoneill.us"] [uri "/xmlrpc.php"] [unique_id "aftyj8k-9v7cQD-n1OmUsgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-05-06 12:00:14
(4 months ago)
[WedMay0614:00:08.4331772026][security2:error][pid3517660:tid3519423][client45.247.15.27:0]ModSecuri ...
show more
[WedMay0614:00:08.4331772026][security2:error][pid3517660:tid3519423][client45.247.15.27:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"367\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"flyingberber.com\"][uri\"/xmlrpc.php\"][unique_id\"afstSIeUJGacgICqj3nO8AAAAEA\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-06 09:34:19
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 06 05:34:12.939219 2026] [security2:error] [pid 15579:tid 15579] [client 45.247.15.27:9567] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.247.15.27 (+1 hits since last alert)|grabagame.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "grabagame.com"] [uri "/xmlrpc.php"] [unique_id "afsLFDytzX2GR81ioKfxPgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-05 11:08:58
(4 months ago)
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.247.15.27 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 05 07:08:53.939170 2026] [security2:error] [pid 26717:tid 26717] [client 45.247.15.27:65344] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.247.15.27 (+1 hits since last alert)|desertmiragetowing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "desertmiragetowing.com"] [uri "/xmlrpc.php"] [unique_id "afnPxUJINTNy1IwghsGdqwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-04 13:17:49
(4 months ago)
Blocked by ModSec and CSF
Port Scan