๐บ๐ธ
TPI-Abuse
2026-06-27 22:07:43
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasi ...
show more
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasil.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 18:07:39.515760 2026] [security2:error] [pid 2483:tid 2483] [client 45.236.51.181:45470] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.236.51.181 (+1 hits since last alert)|mundanestudies.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mundanestudies.org"] [uri "/xmlrpc.php"] [unique_id "akBJqzWuu3lVWBbCs7dEoAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-06-27 22:06:13
(1 hour ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 21:36:42
(2 hours ago)
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasi ...
show more
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasil.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 17:36:36.549574 2026] [security2:error] [pid 3316:tid 3316] [client 45.236.51.181:52829] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.236.51.181 (+1 hits since last alert)|coolcustomproducts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "coolcustomproducts.com"] [uri "/xmlrpc.php"] [unique_id "akBCZMzCeur8U10_NPujiAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-27 10:22:47
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasi ...
show more
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasil.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 06:22:43.081333 2026] [security2:error] [pid 9042:tid 9042] [client 45.236.51.181:39861] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.236.51.181 (+1 hits since last alert)|grasslakepizzatime.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "grasslakepizzatime.com"] [uri "/xmlrpc.php"] [unique_id "aj-kcz09d5k2NKx1LRtotQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-27 10:21:14
(13 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 22:01:32
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasi ...
show more
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasil.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 18:01:25.664840 2026] [security2:error] [pid 17027:tid 17027] [client 45.236.51.181:35529] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.236.51.181 (+1 hits since last alert)|usaangelinvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "usaangelinvestors.com"] [uri "/xmlrpc.php"] [unique_id "aj72tRhsFm0rKG4-IPQYPQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 21:34:58
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasi ...
show more
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasil.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 17:34:51.506812 2026] [security2:error] [pid 30079:tid 30079] [client 45.236.51.181:35179] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.236.51.181 (+1 hits since last alert)|blacksheepoffroad.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "blacksheepoffroad.com"] [uri "/xmlrpc.php"] [unique_id "aj7wewYo_-rZ4_KhNbbhSAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
clapper
2026-06-26 20:30:09
(1 day ago)
(mod_security) mod_security (id:350202) triggered by 45.236.51.181 (BR/Brazil/45-236-51-181.dinamico ...
show more
(mod_security) mod_security (id:350202) triggered by 45.236.51.181 (BR/Brazil/45-236-51-181.dinamico.redebrasil.net.br): 5 in the last 600 secs; ID: rub
show less
Brute-Force
Bad Web Bot
Anonymous
2026-06-26 16:57:27
(1 day ago)
45.236.51.181 - - [26/Jun/2026:18:56:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 750 "-" "Mozilla/5.0 ...
show more
45.236.51.181 - - [26/Jun/2026:18:56:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 750 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Opera/74.0.0.0 Safari/537.36"
45.236.51.181 - - [26/Jun/2026:18:56:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Opera/74.0.0.0 Safari/537.36"
45.236.51.181 - - [26/Jun/2026:18:56:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 750 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/98.0.0.0 Safari/537.36"
45.236.51.181 - - [26/Jun/2026:18:56:53 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Edge/98.0.0.0 Safari/537.36"
45.236.51.181 - - [26/Jun/2026:18:57:26 +0200] "POST /xmlrpc.php HTTP/1.1" 200 750 "-" "Mozilla/5.0 (Windows NT 10.0; arm64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-26 11:47:43
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-26 10:18:12
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasi ...
show more
(mod_security) mod_security (id:240335) triggered by 45.236.51.181 (45-236-51-181.dinamico.redebrasil.net.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 06:18:04.922019 2026] [security2:error] [pid 420:tid 420] [client 45.236.51.181:50240] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.236.51.181 (+1 hits since last alert)|clayrivers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "clayrivers.com"] [uri "/xmlrpc.php"] [unique_id "aj5R3L6m1k6P0z7XAN9IoQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-06-26 02:36:57
(1 day ago)
(wordpress) Failed wordpress login from 45.236.51.181 (BR/Brazil/45-236-51-181.dinamico.redebrasil.n ...
show more
(wordpress) Failed wordpress login from 45.236.51.181 (BR/Brazil/45-236-51-181.dinamico.redebrasil.net.br)
show less
Brute-Force
๐ง๐ช
cmbplf
2026-06-25 23:39:18
(2 days ago)
2.537 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐ณ๐ฑ
wlt-blocker
2026-06-25 21:15:16
(2 days ago)
Unauthorized access to webpage admin
Web App Attack
Anonymous
2026-06-25 18:30:05
(2 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack