π«π·
dynamix
2026-08-24 21:04:02
(4 minutes ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
IndigoRidge
2026-08-24 20:23:09
(45 minutes ago)
46.197.13.47 - - [24/Aug/2026:16:22:04 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5530 "-" "WordPress.co ...
show more
46.197.13.47 - - [24/Aug/2026:16:22:04 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5530 "-" "WordPress.com; https://wordpress.com"
46.197.13.47 - - [24/Aug/2026:16:22:25 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5514 "-" "WordPress.com; https://wordpress.com"
46.197.13.47 - - [24/Aug/2026:16:22:36 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5498 "-" "WordPress.com; https://wordpress.com"
46.197.13.47 - - [24/Aug/2026:16:22:57 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5514 "-" "WordPress.com; https://wordpress.com"
46.197.13.47 - - [24/Aug/2026:16:23:08 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5514 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
Anonymous
2026-08-24 18:46:02
(2 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-08-24 16:50:16
(4 hours ago)
(wordpress) Failed wordpress login from 46.197.13.47 (TR/TΓΌrkiye/-)
Brute-Force
π©πͺ
konseptit
2026-08-24 16:50:00
(4 hours ago)
(wordpress) Failed wordpress login from 46.197.13.47 (TR/TΓΌrkiye/-)
Brute-Force
πΊπΈ
TPI-Abuse
2026-08-23 14:53:38
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:53:32.879696 2026] [security2:error] [pid 17948:tid 17948] [client 46.197.13.47:28430] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.13.47 (+1 hits since last alert)|lspfest.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lspfest.com"] [uri "/xmlrpc.php"] [unique_id "aosJbK4En_JlgWoadbeGUQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π²πΎ
Rizzy
2026-08-23 14:22:41
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 11:30:20
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:30:12.912257 2026] [security2:error] [pid 10854:tid 10854] [client 46.197.13.47:29126] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.13.47 (+1 hits since last alert)|pathpa.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pathpa.org"] [uri "/xmlrpc.php"] [unique_id "aorZxOQsKOvKTvAbewOh9wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
debestelapp
2026-08-23 10:20:07
(1 day ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-23 08:04:22
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 04:04:18.049477 2026] [security2:error] [pid 19629:tid 19629] [client 46.197.13.47:25708] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.13.47 (+1 hits since last alert)|abeltours.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "abeltours.com"] [uri "/xmlrpc.php"] [unique_id "aoqpgoCSpT5dhLRfNSOjrAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 19:56:37
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 15:56:33.719441 2026] [security2:error] [pid 27279:tid 27279] [client 46.197.13.47:28510] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.13.47 (+1 hits since last alert)|zabyte.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "zabyte.net"] [uri "/xmlrpc.php"] [unique_id "aon-8TPcKDf4suoY1wlCRAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-22 19:26:23
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 15:26:17.143300 2026] [security2:error] [pid 27922:tid 27922] [client 46.197.13.47:28447] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.13.47 (+1 hits since last alert)|thepinman.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thepinman.org"] [uri "/xmlrpc.php"] [unique_id "aon32VPas1d8yA-KxvmaGgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-19 10:55:49
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 46.197.13.47 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 06:55:45.256183 2026] [security2:error] [pid 26027:tid 26027] [client 46.197.13.47:11898] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 46.197.13.47 (+1 hits since last alert)|georgegourmet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "georgegourmet.com"] [uri "/xmlrpc.php"] [unique_id "aoWLsdgLBk4vCIjAVrWFsQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
exxos
2025-09-29 23:08:03
(10 months ago)
Attacks with Bad user agents
Hacking