Anonymous
2026-06-26 12:56:55
(13 hours ago)
[osotir.org] httpd-xmlrpc-post: sites=drasimas.gr; logs=/var/log/httpd/domains/drasimas.gr.log; samp ...
show more
[osotir.org] httpd-xmlrpc-post: sites=drasimas.gr; logs=/var/log/httpd/domains/drasimas.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ฉ๐ช
rh24
2026-06-26 12:55:56
(13 hours ago)
(xmlrpc_405) XMLRPC-Bot 405 202.152.156.233 (ID/Indonesia/202-152-156-233.pwkt.citra.net.id)
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-26 11:06:50
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net ...
show more
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 07:06:45.963835 2026] [security2:error] [pid 18608:tid 18608] [client 202.152.156.233:64436] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.152.156.233 (+1 hits since last alert)|majesticsolutions.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "majesticsolutions.co"] [uri "/xmlrpc.php"] [unique_id "aj5dRS5gji6nqroOaKP9LwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-26 10:55:04
(15 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 08:53:12
(17 hours ago)
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net ...
show more
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 04:53:07.964072 2026] [security2:error] [pid 17582:tid 17582] [client 202.152.156.233:57762] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.152.156.233 (+1 hits since last alert)|j3pr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "j3pr.com"] [uri "/xmlrpc.php"] [unique_id "aj498yvfMmbd7sCtJTRiBgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-26 08:50:25
(17 hours ago)
[redacted] 202.152.156.233 - - [26/Jun/2026:10:49:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 202.152.156.233 - - [26/Jun/2026:10:49:39 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
[redacted] 202.152.156.233 - - [26/Jun/2026:10:49:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 202.152.156.233 - - [26/Jun/2026:10:50:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 202.152.156.233 - - [26/Jun/2026:10:50:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 202.152.156.233 - - [26/Jun/2026:10:50:22 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-26 06:02:53
(20 hours ago)
[redacted] 202.152.156.233 - - [26/Jun/2026:08:02:09 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 202.152.156.233 - - [26/Jun/2026:08:02:09 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.2; http://site31858151.com"
[redacted] 202.152.156.233 - - [26/Jun/2026:08:02:20 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 202.152.156.233 - - [26/Jun/2026:08:02:31 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 202.152.156.233 - - [26/Jun/2026:08:02:41 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 202.152.156.233 - - [26/Jun/2026:08:02:52 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐ซ๐ท
tecnicorioja
2026-06-23 22:00:15
(3 days ago)
POST /xmlrpc.php [23/Jun/2026:12:47:05
Brute-Force
Web App Attack
๐ฉ๐ช
rh24
2026-06-23 01:21:24
(4 days ago)
(xmlrpc_405) XMLRPC-Bot 405 202.152.156.233 (ID/Indonesia/202-152-156-233.pwkt.citra.net.id)
Hacking
๐ซ๐ฎ
YF
2026-06-22 12:00:32
(4 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-22 09:32:47
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net ...
show more
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 05:32:40.992610 2026] [security2:error] [pid 9750:tid 9750] [client 202.152.156.233:62541] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.152.156.233 (+1 hits since last alert)|nearfieldchrist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nearfieldchrist.com"] [uri "/xmlrpc.php"] [unique_id "ajkBOBzOMgqs7u7BHJKp-wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 03:46:56
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net ...
show more
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 23:46:49.068063 2026] [security2:error] [pid 21756:tid 21756] [client 202.152.156.233:51034] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.152.156.233 (+1 hits since last alert)|atidysort.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "atidysort.com"] [uri "/xmlrpc.php"] [unique_id "ajiwKasrrvvsUWO3JuDqNgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 10:52:26
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net ...
show more
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 06:52:19.729959 2026] [security2:error] [pid 9246:tid 9246] [client 202.152.156.233:58034] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.152.156.233 (+1 hits since last alert)|fltsiminc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fltsiminc.com"] [uri "/xmlrpc.php"] [unique_id "ajUfYwZA8uC00oXvPcm7EgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 05:40:25
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net ...
show more
(mod_security) mod_security (id:240335) triggered by 202.152.156.233 (202-152-156-233.pwkt.citra.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 01:40:17.061884 2026] [security2:error] [pid 14928:tid 14954] [client 202.152.156.233:63484] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.152.156.233 (+1 hits since last alert)|nabsci.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nabsci.com"] [uri "/xmlrpc.php"] [unique_id "ajTWQbJThKRUhJx7iae9lAAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
bittiguru.fi
2026-06-19 03:11:51
(1 week ago)
202.152.156.233 - [19/Jun/2026:06:11:42 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18963 "-" "Jetpack by ...
show more
202.152.156.233 - [19/Jun/2026:06:11:42 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18963 "-" "Jetpack by WordPress.com" "-"
202.152.156.233 - [19/Jun/2026:06:11:50 +0300] "POST /xmlrpc.php HTTP/1.1" 503 18050 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)" "-"
...
show less
Hacking
Brute-Force
Web App Attack