๐ฉ๐ช
v1nc
2026-10-03 11:08:38
(3 hours ago)
52.141.59.245 - - [03/Oct/2026:11:08:37 +0000] "GET / HTTP/1.1" 200 432 "https://heinen.wedding/xmlr ...
show more
52.141.59.245 - - [03/Oct/2026:11:08:37 +0000] "GET / HTTP/1.1" 200 432 "https://heinen.wedding/xmlrpc.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.130 Safari/537.36"
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-03 10:33:55
(3 hours ago)
(mod_security) mod_security (id:210350) triggered by 52.141.59.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 52.141.59.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 06:33:52.185928 2026] [security2:error] [pid 28478:tid 28478] [client 52.141.59.245:3980] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||thorndikestudio.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "thorndikestudio.com"] [uri "/"] [unique_id "asDaEOWFnJkQeXcrIQUvGwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-10-03 09:35:00
(4 hours ago)
IPBlock protected site ID [3390-wh].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-10-03 09:15:05
(5 hours ago)
Domain : gestioncgt.es
Rule : xmlrpc
2026-10-03 09:13:35 ***hidden-privacy*** GET /xmlrpc.php - 443 ...
show more
Domain : gestioncgt.es
Rule : xmlrpc
2026-10-03 09:13:35 ***hidden-privacy*** GET /xmlrpc.php - 443 - 52.141.59.245 HTTP/1.1 Mozilla/5.0 (X11; Linux x86_64) Gecko/20100101 Firefox/121.0 https://gestioncgt.es/xmlrpc.php www.gestioncgt.es 404 0 0 750 555 261 - -
show less
Web App Attack
๐ซ๐ท
spot
2026-10-03 09:06:18
(5 hours ago)
52.141.59.245 - - [03/Oct/2026:10:06:17 +0100] "GET /xmlrpc.php HTTP/1.1" 404 12437 "https://duckduc ...
show more
52.141.59.245 - - [03/Oct/2026:10:06:17 +0100] "GET /xmlrpc.php HTTP/1.1" 404 12437 "https://duckduckgo.com/" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.6167.85 Safari/537.36"
...
show less
Web App Attack
Hacking
๐ฏ๐ต
ki3
2026-10-03 07:50:42
(6 hours ago)
Fail2Ban: Web App Attacks and Forum Spam 52.141.59.245 1791013841.0(JST)
Web Spam
Bad Web Bot
Web App Attack
๐ธ๐ช
1337v411
2026-10-03 06:35:00
(7 hours ago)
[2026-10-03T06:34:59+00:00] uri="/xmlrpc.php" ua="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 ...
show more
[2026-10-03T06:34:59+00:00] uri="/xmlrpc.php" ua="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.6099.130 Safari/537.36"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 06:26:15
(7 hours ago)
Scanner hitting /xmlrpc.php on ara-oman.com (MSFT) โ aaguard
Brute-Force
Port Scan
๐ณ๐ฟ
Tripwire
2026-10-03 05:47:33
(8 hours ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-10-03 05:31:15
(8 hours ago)
Repeated 403 Forbidden responses
Web App Attack
๐บ๐ธ
Penny Packer
2026-10-03 04:17:02
(10 hours ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 04:06:24
(10 hours ago)
(mod_security) mod_security (id:210350) triggered by 52.141.59.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 52.141.59.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 00:06:16.846525 2026] [security2:error] [pid 26007:tid 26007] [client 52.141.59.245:2118] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||jalenbattle.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jalenbattle.com"] [uri "/"] [unique_id "asB_ODsCPcB_Sri9BubNDAAAAAE"], referer: https://twitter.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 03:58:02
(10 hours ago)
Bot / scanning and/or hacking attempts: GET /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 03:21:15
(11 hours ago)
(mod_security) mod_security (id:210350) triggered by 52.141.59.245 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 52.141.59.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:21:08.318739 2026] [security2:error] [pid 1693:tid 1693] [client 52.141.59.245:3146] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||cedricwillems.be|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cedricwillems.be"] [uri "/"] [unique_id "asB0pIxtiG9ssMsp4HvSPQAAABo"], referer: https://twitter.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-10-03 02:34:56
(11 hours ago)
Accessed trap at '/xmlrpc.php'
Web App Attack