๐ณ๐ฑ
Site.eu
2026-07-25 21:23:29
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
konseptit
2026-07-24 10:50:01
(2 days ago)
(wordpress) Failed wordpress login from 197.45.252.33 (EG/Egypt/-)
Brute-Force
๐ณ๐ฑ
Site.eu
2026-07-24 08:47:05
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ช๐ธ
alferez
2026-07-24 04:09:22
(3 days ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
pscriptos
2026-07-24 00:33:55
(3 days ago)
{"ClientAddr":"197.45.252.33:51322","ClientHost":"197.45.252.33","ClientPort":"51322","ClientUsernam ...
show more
{"ClientAddr":"197.45.252.33:51322","ClientHost":"197.45.252.33","ClientPort":"51322","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":163149402,"OriginContentSize":418,"OriginDuration":158977624,"OriginStatus":403,"Overhead":4171778,"RequestAddr":"www.cleveradmin.de","RequestContentSize":717,"RequestCount":1860283,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-07-24T02:33:33.89841991+02:00","StartUTC":"2026-07-24T00:33:33.89841991Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-07-24T02:33:34+02:00"}
{"ClientAddr":"197.45.252.33:51322","ClientHost":"197.45.252.33","Cl
...
show less
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-23 14:22:27
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-07-23 13:23:30
(3 days ago)
(xmlrpc) Failed xmlrpc access from 197.45.252.33 (EG/Egypt/-): 5 in the last 3600 secs (0-122)
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-23 11:20:08
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 197.45.252.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 197.45.252.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 07:20:01.796371 2026] [security2:error] [pid 19655:tid 19655] [client 197.45.252.33:52546] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.45.252.33 (+1 hits since last alert)|abilityimprinting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abilityimprinting.com"] [uri "/xmlrpc.php"] [unique_id "amH44e0oBKqMz1HkZSKR0QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 21:42:17
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 197.45.252.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 197.45.252.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 17:42:09.809497 2026] [security2:error] [pid 2700234:tid 2700234] [client 197.45.252.33:63067] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.45.252.33 (+1 hits since last alert)|virtualmediamasters.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "virtualmediamasters.net"] [uri "/xmlrpc.php"] [unique_id "amE5MekoKfWEEudKonUA1wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-22 21:38:20
(4 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 20:09:40
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 197.45.252.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 197.45.252.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 16:09:32.482563 2026] [security2:error] [pid 1276103:tid 1276103] [client 197.45.252.33:60957] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.45.252.33 (+1 hits since last alert)|pharmaceuticalsalescertifications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pharmaceuticalsalescertifications.com"] [uri "/xmlrpc.php"] [unique_id "amEjfDI5TUo1dcKboe7O2AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-22 19:35:39
(4 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-07-22 19:05:52
(4 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-22 03:12:15
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 197.45.252.33 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 197.45.252.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 23:12:08.424462 2026] [security2:error] [pid 3790163:tid 3790163] [client 197.45.252.33:60990] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.45.252.33 (+1 hits since last alert)|madisonjazzorchestra.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "madisonjazzorchestra.com"] [uri "/xmlrpc.php"] [unique_id "amA1CHzhx2gdJ1wxNyknhQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-07-21 22:23:48
(5 days ago)
(wordpress) Failed wordpress login from 197.45.252.33 (EG/Egypt/-): (CF_ENABLE)
Brute-Force