Anonymous
2026-06-25 12:58:40
(8 hours ago)
[osotir.org] httpd-xmlrpc-post: sites=agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.log; sa ...
show more
[osotir.org] httpd-xmlrpc-post: sites=agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
π«π·
dynamix
2026-06-25 12:19:12
(8 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-06-25 11:39:10
(9 hours ago)
Attac
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-25 11:27:30
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 07:27:25.626380 2026] [security2:error] [pid 9583:tid 9583] [client 112.208.180.61:36379] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.208.180.61 (+1 hits since last alert)|pondplain.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pondplain.org"] [uri "/xmlrpc.php"] [unique_id "aj0QnUezh06XumznUBGEEgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
konseptit
2026-06-25 11:27:01
(9 hours ago)
(wordpress) Failed wordpress login from 112.208.180.61 (PH/Philippines/112.208.180.61.pldt.net)
Brute-Force
π©πͺ
rh24
2026-06-25 10:55:23
(10 hours ago)
(xmlrpc_405) XMLRPC-Bot 405 112.208.180.61 (PH/Philippines/112.208.180.61.pldt.net)
Hacking
πΊπΈ
TPI-Abuse
2026-06-25 09:22:59
(11 hours ago)
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 05:22:51.315195 2026] [security2:error] [pid 7167:tid 7167] [client 112.208.180.61:34244] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.208.180.61 (+1 hits since last alert)|soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "soundtrax.net"] [uri "/xmlrpc.php"] [unique_id "ajzza2JA1OOBiXu9NCxUMAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-25 08:12:55
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 04:12:51.687116 2026] [security2:error] [pid 12111:tid 12124] [client 112.208.180.61:34073] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.208.180.61 (+1 hits since last alert)|leaderoftheopposition.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "leaderoftheopposition.com"] [uri "/xmlrpc.php"] [unique_id "ajzjA6LkWvYhEqaY1UfDyQAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-25 07:06:32
(14 hours ago)
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 03:06:27.085573 2026] [security2:error] [pid 22822:tid 22822] [client 112.208.180.61:36652] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.208.180.61 (+1 hits since last alert)|rochesterhistorical.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rochesterhistorical.org"] [uri "/xmlrpc.php"] [unique_id "ajzTc-a6GJ0YbQSPfSPAHwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-25 05:39:36
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 01:39:33.187536 2026] [security2:error] [pid 4087:tid 4087] [client 112.208.180.61:35352] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.208.180.61 (+1 hits since last alert)|ohiohca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ohiohca.com"] [uri "/xmlrpc.php"] [unique_id "ajy_Fes97ePCgLLiIj7cVgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-25 02:22:48
(18 hours ago)
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 22:22:45.178320 2026] [security2:error] [pid 9372:tid 9372] [client 112.208.180.61:34341] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.208.180.61 (+1 hits since last alert)|pixelspective.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pixelspective.com"] [uri "/xmlrpc.php"] [unique_id "ajyQ9RiJRHeGVw1KQnSRewAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-06-25 01:50:53
(19 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
PH/Philippines/112.208.180.61.pldt.net
Web App Attack
πͺπΈ
masterguru
2026-06-25 01:22:49
(19 hours ago)
(xmlrpc) Failed xmlrpc access from 112.208.180.61 (PH/Philippines/112.208.180.61.pldt.net): 5 in the ...
show more
(xmlrpc) Failed xmlrpc access from 112.208.180.61 (PH/Philippines/112.208.180.61.pldt.net): 5 in the last 3600 secs (0-122)
show less
Hacking
Anonymous
2026-06-24 12:06:32
(1 day ago)
Trying to access config files
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-24 11:49:52
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in ...
show more
(mod_security) mod_security (id:240335) triggered by 112.208.180.61 (112.208.180.61.pldt.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 07:49:46.153776 2026] [security2:error] [pid 11371:tid 11371] [client 112.208.180.61:36497] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.208.180.61 (+1 hits since last alert)|laecovillage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "laecovillage.org"] [uri "/xmlrpc.php"] [unique_id "ajvEWv5uXD5OYpA4GTgJwAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack