๐ฉ๐ช
pltcldvlpr
2026-06-19 12:09:55
(2 days ago)
CMS/framework probe: 201.159.84.252 - - [19/Jun/2026:14:09:55 +0200] "POST /xmlrpc.php HTTP/1.1" 444 ...
show more
CMS/framework probe: 201.159.84.252 - - [19/Jun/2026:14:09:55 +0200] "POST /xmlrpc.php HTTP/1.1" 444 0 "-" "Jetpack by WordPress.com" asn=61764 org="Rio Grande Tecnologia e Comunic Multimidia Ltda" country=BR
...
show less
Web App Attack
Anonymous
2026-06-17 16:40:13
(4 days ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-15 11:44:13
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 07:44:05.811848 2026] [security2:error] [pid 31289:tid 31289] [client 201.159.84.252:8132] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 201.159.84.252 (+1 hits since last alert)|tourissue.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tourissue.com"] [uri "/xmlrpc.php"] [unique_id "ai_lhVRJ8peeGdy5fZm_KwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-06-09 14:00:40
(1 week ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-09 12:54:43
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:54:35.813736 2026] [security2:error] [pid 27724:tid 27724] [client 201.159.84.252:8369] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 201.159.84.252 (+1 hits since last alert)|rocksolidhomebuilders.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rocksolidhomebuilders.com"] [uri "/xmlrpc.php"] [unique_id "aigNC_VjCVKVYj8M7VW3jwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-09 12:52:54
(1 week ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
BR/Brazil/201.159.84.252.rgol.com.br
Web App Attack
Anonymous
2026-06-03 19:35:11
(2 weeks ago)
Attac
Brute-Force
๐ฆ๐บ
screwlooseit.com.au
2026-06-03 17:00:53
(2 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
BR/Brazil/201.159.84.252.rgol.com.br
Web App Attack
๐บ๐ธ
etu brutus
2026-06-03 12:15:58
(2 weeks ago)
201.159.84.252 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 11:15:33
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 07:15:29.057697 2026] [security2:error] [pid 18825:tid 18825] [client 201.159.84.252:8522] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 201.159.84.252 (+1 hits since last alert)|jonasrimkunas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jonasrimkunas.com"] [uri "/xmlrpc.php"] [unique_id "aiAM0djNyPJAmreaM9ptIgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Martin Lundstrom
2026-06-02 18:43:10
(2 weeks ago)
https://www.eagleeye-intelligence.com โ WordPress attack. Automatically detected and blocked.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 15:32:15
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 11:32:10.565488 2026] [security2:error] [pid 3275:tid 3275] [client 201.159.84.252:8333] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 201.159.84.252 (+1 hits since last alert)|t9teamsportinggoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "t9teamsportinggoods.com"] [uri "/xmlrpc.php"] [unique_id "ah73encQ5TjzJg0zS6R79AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 13:31:24
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 09:31:20.597508 2026] [security2:error] [pid 20295:tid 20295] [client 201.159.84.252:8726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 201.159.84.252 (+1 hits since last alert)|pakistanvision.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pakistanvision.com"] [uri "/xmlrpc.php"] [unique_id "ah7bKGix0uRfI_u5Uan0OgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 12:34:42
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 ...
show more
(mod_security) mod_security (id:240335) triggered by 201.159.84.252 (201.159.84.252.rgol.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 08:34:36.121126 2026] [security2:error] [pid 1114:tid 1114] [client 201.159.84.252:8478] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 201.159.84.252 (+1 hits since last alert)|intothebigempty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "intothebigempty.com"] [uri "/xmlrpc.php"] [unique_id "ah7N3M38xwE6uGShwoF2vAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-01 13:47:34
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack