๐บ๐ธ
TPI-Abuse
2026-07-28 09:36:41
(1 hour ago)
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 05:36:36.980492 2026] [security2:error] [pid 293378:tid 293378] [client 46.197.12.58:37143] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.12.58 (+1 hits since last alert)|thereisaplaceonearth.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thereisaplaceonearth.com"] [uri "/xmlrpc.php"] [unique_id "amh4JIZwXAzEzWOzHeQylQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 07:13:29
(4 hours ago)
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 03:13:23.173280 2026] [security2:error] [pid 524810:tid 524810] [client 46.197.12.58:36986] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.12.58 (+1 hits since last alert)|famagustacyprus.eu|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "famagustacyprus.eu"] [uri "/xmlrpc.php"] [unique_id "amhWk7aW58PaK6yIWLvjTAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 05:02:19
(6 hours ago)
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 01:02:15.304705 2026] [security2:error] [pid 6371:tid 6437] [client 46.197.12.58:36878] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.12.58 (+1 hits since last alert)|tradersofficepark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tradersofficepark.com"] [uri "/xmlrpc.php"] [unique_id "amg31xmkuXA3IwkHfuaZTAAAAgg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 02:43:10
(8 hours ago)
(wordpress) Failed wordpress login from 46.197.12.58 (TR/Tรผrkiye/Antalya/Yukarฤฑkaraman/-/[redacted])
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 18:57:12
(16 hours ago)
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:57:08.475186 2026] [security2:error] [pid 3992477:tid 3992477] [client 46.197.12.58:34410] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.12.58 (+1 hits since last alert)|naturalhomebuilders.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "naturalhomebuilders.com"] [uri "/xmlrpc.php"] [unique_id "ameqBB9dGDxhWlzeBtvAAwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-27 14:39:36
(20 hours ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
Anonymous
2026-07-27 14:38:24
(20 hours ago)
[ns31.kdns.gr] httpd-xmlrpc-post: sites=www.savouras.gr; logs=/var/log/httpd/domains/savouras.gr.log ...
show more
[ns31.kdns.gr] httpd-xmlrpc-post: sites=www.savouras.gr; logs=/var/log/httpd/domains/savouras.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 08:33:21
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 04:33:13.352556 2026] [security2:error] [pid 26121:tid 26121] [client 46.197.12.58:33828] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.12.58 (+1 hits since last alert)|wpcoc.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wpcoc.org"] [uri "/xmlrpc.php"] [unique_id "amcXyYK_tl508pL3ukmzKwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-26 16:04:52
(1 day ago)
(wordpress) Failed wordpress login from 46.197.12.58 (TR/Tรผrkiye/Istanbul/Istanbul/-/[redacted])
Brute-Force
๐ฆ๐บ
screwlooseit.com.au
2026-07-26 13:50:13
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
TR/Turkey/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 12:19:30
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 08:19:24.143624 2026] [security2:error] [pid 3626240:tid 3626240] [client 46.197.12.58:35057] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.12.58 (+1 hits since last alert)|eileensharaga.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "eileensharaga.com"] [uri "/xmlrpc.php"] [unique_id "amX7TNqooilwEwetmcIEaQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 11:18:17
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 07:18:11.901616 2026] [security2:error] [pid 2564203:tid 2564203] [client 46.197.12.58:36952] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.12.58 (+1 hits since last alert)|starcrestsales.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "starcrestsales.com"] [uri "/xmlrpc.php"] [unique_id "amXs80Y-3D6M4MMxVjkZFQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-26 08:23:23
(2 days ago)
(wordpress) Failed wordpress login from 46.197.12.58 (TR/Tรผrkiye/-)
Brute-Force
๐ซ๐ท
dynamix
2026-07-26 08:23:10
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 07:24:02
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.12.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 03:23:54.942415 2026] [security2:error] [pid 3248279:tid 3248279] [client 46.197.12.58:36917] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.12.58 (+1 hits since last alert)|matt-bechtel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "matt-bechtel.com"] [uri "/xmlrpc.php"] [unique_id "amW2CmyPM653NP3yibuEOQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack