Anonymous
2026-06-20 18:25:04
(1 day ago)
[da.kdns.gr] httpd-xmlrpc-post: sites=onar-pension.gr; logs=/var/log/httpd/domains/onar-pension.gr.l ...
show more
[da.kdns.gr] httpd-xmlrpc-post: sites=onar-pension.gr; logs=/var/log/httpd/domains/onar-pension.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 17:31:05
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 223.123.124.142 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 223.123.124.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 13:31:00.005830 2026] [security2:error] [pid 30715:tid 30715] [client 223.123.124.142:32213] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 223.123.124.142 (+1 hits since last alert)|schlegelcreative.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "schlegelcreative.com"] [uri "/xmlrpc.php"] [unique_id "ajbOVAKoHc2xa4aCzDEhqAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-20 13:28:01
(1 day ago)
[redacted] 223.123.124.142 - - [20/Jun/2026:15:27:17 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" ...
show more
[redacted] 223.123.124.142 - - [20/Jun/2026:15:27:17 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack/12.0; WordPress/6.1; http://site54521255.com"
[redacted] 223.123.124.142 - - [20/Jun/2026:15:27:28 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack/12.0; WordPress/6.2; http://site99180281.com"
[redacted] 223.123.124.142 - - [20/Jun/2026:15:27:38 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack by WordPress.com"
[redacted] 223.123.124.142 - - [20/Jun/2026:15:27:49 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.2)"
[redacted] 223.123.124.142 - - [20/Jun/2026:15:28:00 +0200] "POST /xmlrpc.php HTTP/1.1" 403 418 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.1)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 10:47:12
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 223.123.124.142 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 223.123.124.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 06:47:06.243659 2026] [security2:error] [pid 26384:tid 26384] [client 223.123.124.142:61498] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 223.123.124.142 (+1 hits since last alert)|johncyphers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "johncyphers.com"] [uri "/xmlrpc.php"] [unique_id "ajZvqjxEVvZOdfGSWAID5wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 08:15:33
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 223.123.124.142 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 223.123.124.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 04:15:25.892443 2026] [security2:error] [pid 13448:tid 13448] [client 223.123.124.142:55188] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 223.123.124.142 (+1 hits since last alert)|pixelspective.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pixelspective.com"] [uri "/xmlrpc.php"] [unique_id "ajZMHbp0yZfS__H_5aTE3wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 18:16:35
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 223.123.124.142 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 223.123.124.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 14:16:30.817707 2026] [security2:error] [pid 21417:tid 21417] [client 223.123.124.142:53387] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 223.123.124.142 (+1 hits since last alert)|luxandunion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "luxandunion.com"] [uri "/xmlrpc.php"] [unique_id "ajWHfvBpgUgfSvbyupiYCAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-19 15:18:03
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
xmission.com
2026-05-11 17:56:19
(1 month ago)
Blocked by UFW (TCP on 63269)
Source port: 44313
TTL: 43
Packet length: 60
TOS: 0x08
This report (f ...
show more
Blocked by UFW (TCP on 63269)
Source port: 44313
TTL: 43
Packet length: 60
TOS: 0x08
This report (for 223.123.124.142) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐ซ๐ท
bigorre.org
2026-04-23 10:34:51
(1 month ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-21 13:22:18
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 223.123.124.142 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 223.123.124.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 09:22:10.577480 2026] [security2:error] [pid 30416:tid 30416] [client 223.123.124.142:36932] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rustyog.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rustyog.net"] [uri "/guides/wp-json/wp/v2/users/2"] [unique_id "aed6AhPRgYd62EeFjuwK7QAAAAA"], referer: https://rustyog.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
bigorre.org
2026-04-20 11:21:46
(2 months ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
๐บ๐ธ
quilla
2026-04-03 03:20:35
(2 months ago)
Botnet infected device observed in honeypot (Vector: TCP)
DDoS Attack
๐บ๐ธ
Rip
2026-03-31 07:59:35
(2 months ago)
Automated recon attempt targeting restricted and sensitive paths.
Web App Attack