๐บ๐ธ
TPI-Abuse
2026-06-23 05:06:17
(58 minutes ago)
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 01:06:06.245719 2026] [security2:error] [pid 8664:tid 8664] [client 49.47.152.166:58753] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.47.152.166 (+1 hits since last alert)|blacksheepoffroad.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "blacksheepoffroad.com"] [uri "/xmlrpc.php"] [unique_id "ajoUPj48-PZmMlHZNmaoHwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 03:19:23
(2 hours ago)
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 23:19:13.943865 2026] [security2:error] [pid 15650:tid 15650] [client 49.47.152.166:63164] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.47.152.166 (+1 hits since last alert)|saynotoofland.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "saynotoofland.org"] [uri "/xmlrpc.php"] [unique_id "ajn7MeMeNMEKVbp99R5hfQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-06-22 10:40:50
(19 hours ago)
{"ClientAddr":"49.47.152.166:60025","ClientHost":"49.47.152.166","ClientPort":"60025","ClientUsernam ...
show more
{"ClientAddr":"49.47.152.166:60025","ClientHost":"49.47.152.166","ClientPort":"60025","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":127441609,"OriginContentSize":418,"OriginDuration":124781680,"OriginStatus":403,"Overhead":2659929,"RequestAddr":"www.cleveradmin.de","RequestContentSize":715,"RequestCount":1138651,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-06-22T12:40:29.4296537+02:00","StartUTC":"2026-06-22T10:40:29.4296537Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-06-22T12:40:29+02:00"}
{"ClientAddr":"49.47.152.166:60025","ClientHost":"49.47.152.166","Clie
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 04:57:10
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 00:57:01.041610 2026] [security2:error] [pid 8174:tid 8174] [client 49.47.152.166:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.47.152.166 (+1 hits since last alert)|upskirtcrazy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "upskirtcrazy.com"] [uri "/xmlrpc.php"] [unique_id "ajjAnUdq2LWHQ-evgo3WoQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-22 04:24:22
(1 day ago)
(xmlrpc) Apache: Failed xmlrpc access from 49.47.152.166 (IN/India/-): 10 in the last 3600 secs (0-2 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 49.47.152.166 (IN/India/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-21 13:47:03
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 09:46:51.800328 2026] [security2:error] [pid 30348:tid 30348] [client 49.47.152.166:57582] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.47.152.166 (+1 hits since last alert)|stacyfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "stacyfarm.com"] [uri "/xmlrpc.php"] [unique_id "ajfrS2_5NorDUse6s2L_xAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-21 04:22:34
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-20 10:27:58
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 06:27:48.662503 2026] [security2:error] [pid 6032:tid 6032] [client 49.47.152.166:60111] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.47.152.166 (+1 hits since last alert)|luxandunion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "luxandunion.com"] [uri "/xmlrpc.php"] [unique_id "ajZrJDaeyZT4OgPaLfsjPwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 11:35:23
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 07:35:13.249141 2026] [security2:error] [pid 8986:tid 8986] [client 49.47.152.166:60851] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.47.152.166 (+1 hits since last alert)|salernospizza.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "salernospizza.com"] [uri "/xmlrpc.php"] [unique_id "ajUpcYvFXKAdp8Y-S-moVgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-19 05:20:49
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 49.47.152.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 01:20:37.170548 2026] [security2:error] [pid 3918:tid 3918] [client 49.47.152.166:58884] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 49.47.152.166 (+1 hits since last alert)|garanta.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "garanta.co"] [uri "/xmlrpc.php"] [unique_id "ajTRpZlxc80q_XFgrF7SLAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-19 04:42:28
(4 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
Anonymous
2026-06-19 03:26:03
(4 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-18 22:36:30
(4 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฒ๐พ
Rizzy
2026-06-18 06:06:43
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-06-18 05:08:46
(5 days ago)
[server.tmg.gr] httpd-xmlrpc-post: sites=tmg.gr; logs=/var/log/httpd/domains/tmg.gr.log; samples=/xm ...
show more
[server.tmg.gr] httpd-xmlrpc-post: sites=tmg.gr; logs=/var/log/httpd/domains/tmg.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack