π³π±
Site.eu
2026-08-19 05:51:22
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-08-18 12:55:50
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np ...
show more
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 08:55:44.830436 2026] [security2:error] [pid 8347:tid 8347] [client 27.34.65.159:49551] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.34.65.159 (+1 hits since last alert)|cbrtome.cl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cbrtome.cl"] [uri "/xmlrpc.php"] [unique_id "aoRWUK9YfaQkOLIfyUxhmAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 10:17:43
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np ...
show more
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 06:17:36.571857 2026] [security2:error] [pid 25122:tid 25122] [client 27.34.65.159:33509] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.34.65.159 (+1 hits since last alert)|mundanestudies.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mundanestudies.org"] [uri "/xmlrpc.php"] [unique_id "aoQxQFm-ITwcZbUHWX8A3gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-18 09:13:49
(3 days ago)
(wordpress) Failed wordpress login from 27.34.65.159 (NP/Nepal/159.65.34.27.dynamic.wlink.com.np)
Brute-Force
π©πͺ
YF
2026-08-17 12:00:15
(4 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-17 11:19:56
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np ...
show more
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 07:19:51.801113 2026] [security2:error] [pid 13688:tid 13688] [client 27.34.65.159:27476] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.34.65.159 (+1 hits since last alert)|gisur.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gisur.com"] [uri "/xmlrpc.php"] [unique_id "aoLuV0Azb7pV6PPt-AB-dwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-08-17 09:10:46
(4 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
π©πͺ
pscriptos
2026-08-17 06:21:30
(4 days ago)
{"ClientAddr":"27.34.65.159:45092","ClientHost":"27.34.65.159","ClientPort":"45092","ClientUsername" ...
show more
{"ClientAddr":"27.34.65.159:45092","ClientHost":"27.34.65.159","ClientPort":"45092","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":156686104,"OriginContentSize":418,"OriginDuration":153675094,"OriginStatus":403,"Overhead":3011010,"RequestAddr":"www.cleveradmin.de","RequestContentSize":709,"RequestCount":4075299,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-08-17T08:21:07.992425418+02:00","StartUTC":"2026-08-17T06:21:07.992425418Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-08-17T08:21:08+02:00"}
{"ClientAddr":"27.34.65.159:45092","ClientHost":"27.34.65.159","Clie
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-17 05:57:31
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np ...
show more
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 01:57:24.580762 2026] [security2:error] [pid 4810:tid 4810] [client 27.34.65.159:9181] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.34.65.159 (+1 hits since last alert)|tcomputerguy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tcomputerguy.com"] [uri "/xmlrpc.php"] [unique_id "aoKixIrN2uC5in5t52AT1wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 08:16:50
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np ...
show more
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:16:44.071185 2026] [security2:error] [pid 14649:tid 14649] [client 27.34.65.159:38046] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.34.65.159 (+1 hits since last alert)|boraimpact.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "boraimpact.com"] [uri "/xmlrpc.php"] [unique_id "aoFx7B8YSelWSmKwIRYjugAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 07:44:52
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np ...
show more
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:44:46.300144 2026] [security2:error] [pid 24144:tid 24167] [client 27.34.65.159:2504] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.34.65.159 (+1 hits since last alert)|coasterdvdsonline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "coasterdvdsonline.com"] [uri "/xmlrpc.php"] [unique_id "aoFqbm9WWiAOTA26f2V_NQAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
rh24
2026-08-16 06:39:35
(5 days ago)
(xmlrpc_405) XMLRPC-Bot 405 27.34.65.159 (NP/Nepal/159.65.34.27.dynamic.wlink.com.np)
Hacking
π³π±
debestelapp
2026-08-16 05:55:07
(5 days ago)
Web App Attack
π©πͺ
Vegascosmetics
2026-08-16 03:43:10
(5 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nest ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nesting / CPU-drain risk). Evidence: DEEP ATTACK: Recursive currentUrl nesting detected
show less
Hacking
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-15 12:27:58
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np ...
show more
(mod_security) mod_security (id:240335) triggered by 27.34.65.159 (159.65.34.27.dynamic.wlink.com.np): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 08:27:50.938630 2026] [security2:error] [pid 1858:tid 1858] [client 27.34.65.159:27598] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.34.65.159 (+1 hits since last alert)|fadcometal.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fadcometal.com"] [uri "/xmlrpc.php"] [unique_id "aoBbRllZQy4PxtqvxVwu3AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack