๐ฉ๐ช
pscriptos
2026-08-25 12:41:54
(3 days ago)
{"ClientAddr":"223.181.52.2:15969","ClientHost":"223.181.52.2","ClientPort":"15969","ClientUsername" ...
show more
{"ClientAddr":"223.181.52.2:15969","ClientHost":"223.181.52.2","ClientPort":"15969","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":136168915,"OriginContentSize":418,"OriginDuration":131114257,"OriginStatus":403,"Overhead":5054658,"RequestAddr":"www.cleveradmin.de","RequestContentSize":707,"RequestCount":4918762,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-08-25T14:41:34.919006518+02:00","StartUTC":"2026-08-25T12:41:34.919006518Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-08-25T14:41:35+02:00"}
{"ClientAddr":"223.181.52.2:15969","ClientHost":"223.181.52.2","Clie
...
show less
Brute-Force
Web App Attack
Anonymous
2026-08-25 12:27:46
(3 days ago)
[redacted] 223.181.52.2 - - [25/Aug/2026:14:27:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Wo ...
show more
[redacted] 223.181.52.2 - - [25/Aug/2026:14:27:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 223.181.52.2 - - [25/Aug/2026:14:27:19 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
[redacted] 223.181.52.2 - - [25/Aug/2026:14:27:25 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.4)"
[redacted] 223.181.52.2 - - [25/Aug/2026:14:27:34 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 223.181.52.2 - - [25/Aug/2026:14:27:45 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.4; http://site90237251.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-08-25 12:10:31
(3 days ago)
[redacted] 223.181.52.2 - - [25/Aug/2026:14:09:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 223.181.52.2 - - [25/Aug/2026:14:09:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
[redacted] 223.181.52.2 - - [25/Aug/2026:14:09:59 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 223.181.52.2 - - [25/Aug/2026:14:10:09 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
[redacted] 223.181.52.2 - - [25/Aug/2026:14:10:20 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 223.181.52.2 - - [25/Aug/2026:14:10:31 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-25 11:50:43
(3 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
NotCool
2026-08-25 11:24:39
(3 days ago)
(XMLRPC) WP XMLPRC Attack 223.181.52.2 (IN/India/-): 50 in the last 3600 secs
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 11:22:48
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 223.181.52.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 223.181.52.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 07:22:44.189268 2026] [security2:error] [pid 3516:tid 3516] [client 223.181.52.2:15050] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 223.181.52.2 (+1 hits since last alert)|cosplayculture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cosplayculture.com"] [uri "/xmlrpc.php"] [unique_id "ao17BDLLLghnZ957yV_JfwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 11:06:57
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 223.181.52.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 223.181.52.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 07:06:51.202060 2026] [security2:error] [pid 23547:tid 23547] [client 223.181.52.2:10480] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 223.181.52.2 (+1 hits since last alert)|honigcpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "honigcpa.com"] [uri "/xmlrpc.php"] [unique_id "ao13SxZU3KP1jBIsef_S0gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-25 10:54:58
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 08:27:43
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 223.181.52.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 223.181.52.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 04:27:35.735700 2026] [security2:error] [pid 31420:tid 31491] [client 223.181.52.2:28400] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 223.181.52.2 (+1 hits since last alert)|strengthsmatter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "strengthsmatter.com"] [uri "/xmlrpc.php"] [unique_id "ao1R9xL4B9ub1aJK4W6v5wAAAcU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-25 08:09:48
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-08-25 07:34:36
(4 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 223.181.52.2 (IN/India/-): 10 in the last 3600 secs (0-20 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 223.181.52.2 (IN/India/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐จ๐ฆ
Anytech
2026-08-25 07:08:25
(4 days ago)
Blocked by ConnMonitor
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 06:15:32
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 223.181.52.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 223.181.52.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 02:15:26.231208 2026] [security2:error] [pid 3182:tid 3182] [client 223.181.52.2:6189] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 223.181.52.2 (+1 hits since last alert)|wwtransform.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wwtransform.org"] [uri "/xmlrpc.php"] [unique_id "ao0y_gLCTs5h5kSh9FNklQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 05:38:16
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 223.181.52.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 223.181.52.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 01:38:12.078510 2026] [security2:error] [pid 24797:tid 24797] [client 223.181.52.2:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 223.181.52.2 (+1 hits since last alert)|pixacast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pixacast.com"] [uri "/xmlrpc.php"] [unique_id "ao0qRHmMIVAMa_kn0io32QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-08-25 04:38:13
(4 days ago)
Wordpress Vunerability attack
Web App Attack