Anonymous
2024-01-11 12:21:09
(2 years ago)
apache vulnerability scan
Web App Attack
Anonymous
2023-12-14 10:32:00
(2 years ago)
"Illegal file type"
Brute-Force
๐บ๐ธ
TPI-Abuse
2023-12-12 02:33:51
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.212.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.212.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 11 21:33:44.026423 2023] [security2:error] [pid 26567] [client 43.138.212.72:52098] [client 43.138.212.72] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.212.72 (+1 hits since last alert)|lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lysedzija.com"] [uri "/xmlrpc.php"] [unique_id "ZXfGiFWIfb_7xLvQI4u6pgAAAAs"], referer: https://lysedzija.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฑ
Dolphi
2023-12-12 01:40:03
(2 years ago)
Excessive POST /xmlrpc.php requests
Brute-Force
Web App Attack
๐ณ๐ฑ
vestibtech
2023-12-11 23:32:04
(2 years ago)
43.138.212.72 - - [11/Dec/2023:16:32:03 -0700] "GET /xmlrpc.php HTTP/1.1" 404 10176 "-" "Mozilla/5.0 ...
show more
43.138.212.72 - - [11/Dec/2023:16:32:03 -0700] "GET /xmlrpc.php HTTP/1.1" 404 10176 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0"
...
show less
Web App Attack
๐ฑ๐น
NotACaptcha
2023-12-11 13:34:59
(2 years ago)
webserver:80 [11/Dec/2023] "GET /xmlrpc.php HTTP/1.1" 302 471 "-" "Mozilla/5.0 (Windows NT 6.1; WOW ...
show more
webserver:80 [11/Dec/2023] "GET /xmlrpc.php HTTP/1.1" 302 471 "-" "Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-10 07:31:56
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.212.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.212.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 10 02:31:48.669827 2023] [security2:error] [pid 1271955] [client 43.138.212.72:58870] [client 43.138.212.72] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.212.72 (+1 hits since last alert)|salernospizza.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "salernospizza.com"] [uri "/xmlrpc.php"] [unique_id "ZXVpZFkA2APcl4I_XMYWYwAAAAY"], referer: http://salernospizza.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
findlab
2023-12-09 21:20:02
(2 years ago)
Backdrop CMS module - scanning for vulnerable files
Bad Web Bot
Web App Attack
Anonymous
2023-12-07 06:34:56
(2 years ago)
[06:34:55] 11: Scanning for Exploits - /xmlrpc.php (Repeat abuser, 13 other attacks previously recor ...
show more
[06:34:55] 11: Scanning for Exploits - /xmlrpc.php (Repeat abuser, 13 other attacks previously recorded.)
show less
Hacking
Web App Attack
๐ฌ๐ง
CrystalMaker
2023-12-06 23:31:24
(2 years ago)
Wordpress attack - GET /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-04 19:32:32
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.212.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.212.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 04 14:32:26.336624 2023] [security2:error] [pid 11769] [client 43.138.212.72:51708] [client 43.138.212.72] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.212.72 (+1 hits since last alert)|www.realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.realclean.net"] [uri "/xmlrpc.php"] [unique_id "ZW4pSuQ34SQO6qz9FLVIbgAAAAc"], referer: http://www.realclean.net/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-12-02 23:33:47
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.212.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.212.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 02 18:33:40.954111 2023] [security2:error] [pid 20855] [client 43.138.212.72:36638] [client 43.138.212.72] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.212.72 (+1 hits since last alert)|www.batesstrategygroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.batesstrategygroup.com"] [uri "/xmlrpc.php"] [unique_id "ZWu-1K5MI6dl5J1wZJjavAAAAAM"], referer: http://www.batesstrategygroup.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kommunos
2023-12-02 20:31:04
(2 years ago)
/xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2023-11-30 01:33:24
(2 years ago)
(mod_security) mod_security (id:240335) triggered by 43.138.212.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.138.212.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 29 20:33:19.338104 2023] [security2:error] [pid 8591] [client 43.138.212.72:35078] [client 43.138.212.72] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.138.212.72 (+1 hits since last alert)|braintechsoftwaresolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "braintechsoftwaresolutions.com"] [uri "/xmlrpc.php"] [unique_id "ZWfmX-XC_EIwrFFv4L0YdgAAAAY"], referer: https://braintechsoftwaresolutions.com/xmlrpc.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2023-11-30 00:31:42
(2 years ago)
Bad Web Bot
Web App Attack