Anonymous
2026-06-05 14:07:48
(6 days ago)
Trying to access config files
Web App Attack
Anonymous
2026-06-05 00:37:51
(1 week ago)
(wordpress) Failed wordpress login from 74.244.129.127 (ZM/Zambia/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-05 00:07:27
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 20:07:22.099057 2026] [security2:error] [pid 8600:tid 8600] [client 74.244.129.127:13244] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 74.244.129.127 (+1 hits since last alert)|the-it-man.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "the-it-man.com"] [uri "/xmlrpc.php"] [unique_id "aiITOjFHWnm_GPhkoL5GXAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 23:36:40
(1 week ago)
Attac
Brute-Force
Anonymous
2026-06-04 23:03:49
(1 week ago)
74.244.129.127 - - [05/Jun/2026:07:03:48 +0800] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12. ...
show more
74.244.129.127 - - [05/Jun/2026:07:03:48 +0800] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack/12.0; WordPress/6.3; http://site59896325.com"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 14:32:25
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 10:32:19.501797 2026] [security2:error] [pid 28680:tid 28680] [client 74.244.129.127:18623] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 74.244.129.127 (+1 hits since last alert)|weddingmusicguitar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "weddingmusicguitar.com"] [uri "/xmlrpc.php"] [unique_id "aiGMc7iSWGJNoZq1LGc_egAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 13:58:50
(1 week ago)
[redacted] 74.244.129.127 - - [04/Jun/2026:15:58:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 74.244.129.127 - - [04/Jun/2026:15:58:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 74.244.129.127 - - [04/Jun/2026:15:58:16 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 74.244.129.127 - - [04/Jun/2026:15:58:27 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 74.244.129.127 - - [04/Jun/2026:15:58:38 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
[redacted] 74.244.129.127 - - [04/Jun/2026:15:58:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-04 10:06:04
(1 week ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 09:25:51
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 05:25:45.042119 2026] [security2:error] [pid 23942:tid 23953] [client 74.244.129.127:44690] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 74.244.129.127 (+1 hits since last alert)|reghay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "reghay.com"] [uri "/xmlrpc.php"] [unique_id "aiFEmaxZFvrQdIR1ZQ24JgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
INTEQ
2026-06-04 08:51:22
(1 week ago)
Web attack from 74.244.129.127
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 07:53:30
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 03:53:26.435442 2026] [security2:error] [pid 27341:tid 27341] [client 74.244.129.127:30804] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 74.244.129.127 (+1 hits since last alert)|thehealthyplaceclayton.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thehealthyplaceclayton.com"] [uri "/xmlrpc.php"] [unique_id "aiEu9tUQLgLjseZ_FL4kGQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-04 04:44:53
(1 week ago)
(wordpress) Failed wordpress login from 74.244.129.127 (ZM/Zambia/-)
Brute-Force
Anonymous
2026-06-03 23:17:04
(1 week ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=eumedline.com; logs=/var/log/httpd/domains/eumedline.com.lo ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=eumedline.com; logs=/var/log/httpd/domains/eumedline.com.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 21:13:18
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 17:13:12.277247 2026] [security2:error] [pid 28486:tid 28486] [client 74.244.129.127:18997] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 74.244.129.127 (+1 hits since last alert)|metcomarine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "metcomarine.com"] [uri "/xmlrpc.php"] [unique_id "aiCY6MLekseSHjhyZYk8NwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 18:40:26
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 74.244.129.127 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 14:40:21.378977 2026] [security2:error] [pid 16429:tid 16429] [client 74.244.129.127:51277] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 74.244.129.127 (+1 hits since last alert)|warpedweed.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "warpedweed.com"] [uri "/xmlrpc.php"] [unique_id "aiB1Fby0IfeY3wlTkDmZXAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack