Anonymous
2026-06-14 17:13:38
(1 day ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=kostaspriftis.gr; logs=/var/log/httpd/domains/kostaspriftis. ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=kostaspriftis.gr; logs=/var/log/httpd/domains/kostaspriftis.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-06-14 10:59:18
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 17:11:08
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 13:11:00.731470 2026] [security2:error] [pid 1406:tid 1406] [client 202.47.53.217:19299] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.47.53.217 (+1 hits since last alert)|forefrontmusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "forefrontmusic.com"] [uri "/xmlrpc.php"] [unique_id "airsJE2IOaEtmwBG9MknogAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-10 22:15:37
(5 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฌ๐ง
NotCool
2026-06-10 17:17:35
(5 days ago)
(XMLRPC) WP XMLPRC Attack 202.47.53.217 (PK/Pakistan/-): 50 in the last 3600 secs
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 11:56:30
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 07:56:21.213448 2026] [security2:error] [pid 1960:tid 1960] [client 202.47.53.217:18628] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.47.53.217 (+1 hits since last alert)|lemoulinavent.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lemoulinavent.org"] [uri "/xmlrpc.php"] [unique_id "ailQ5SkNrh1dFQkyRXyQiQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-10 02:16:35
(6 days ago)
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=tentes-margaritis.gr; logs=/var/log/httpd/domains/tentes-mar ...
show more
[ssd5.kdns.gr] httpd-xmlrpc-post: sites=tentes-margaritis.gr; logs=/var/log/httpd/domains/tentes-margaritis.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 02:14:09
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 22:14:03.027779 2026] [security2:error] [pid 1921:tid 1945] [client 202.47.53.217:19694] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.47.53.217 (+1 hits since last alert)|tsengkwongchi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tsengkwongchi.com"] [uri "/xmlrpc.php"] [unique_id "aijIa3GSYt8R7ebPv3WPFwAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 15:14:19
(1 week ago)
(wordpress) Failed wordpress login from 202.47.53.217 (PK/Pakistan/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 23:53:53
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 19:53:46.635854 2026] [security2:error] [pid 3500:tid 3500] [client 202.47.53.217:19666] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.47.53.217 (+1 hits since last alert)|coolcustomweddingproducts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "coolcustomweddingproducts.com"] [uri "/xmlrpc.php"] [unique_id "aidWCn7ytcaQZQvQXUlyUgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 20:20:36
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 16:20:29.186662 2026] [security2:error] [pid 29672:tid 29672] [client 202.47.53.217:18278] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.47.53.217 (+1 hits since last alert)|casaluzislamujeres.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "casaluzislamujeres.com"] [uri "/xmlrpc.php"] [unique_id "aickDRMZBGNKedRRxZpKWgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 07:58:25
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 03:58:19.053698 2026] [security2:error] [pid 7656:tid 7656] [client 202.47.53.217:19253] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.47.53.217 (+1 hits since last alert)|sliconswamp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sliconswamp.com"] [uri "/xmlrpc.php"] [unique_id "aiZ2GxSlceCwDKL49n-FoAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 06:56:36
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 02:56:33.187883 2026] [security2:error] [pid 27162:tid 27162] [client 202.47.53.217:18316] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.47.53.217 (+1 hits since last alert)|loneoakhoney.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "loneoakhoney.com"] [uri "/xmlrpc.php"] [unique_id "aiZnoeygFW4HWlRSqreQnQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 06:13:25
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 02:13:19.912480 2026] [security2:error] [pid 4269:tid 4269] [client 202.47.53.217:18942] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.47.53.217 (+1 hits since last alert)|nextstepplus.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nextstepplus.net"] [uri "/xmlrpc.php"] [unique_id "aiZdf_KT48F5MMtBrRZpdwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 21:02:22
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 202.47.53.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 17:02:17.324130 2026] [security2:error] [pid 14030:tid 14030] [client 202.47.53.217:18832] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brushmileage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brushmileage.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aiXcWYjlO0X1vLzH_M_8owAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack