Anonymous
2026-06-13 06:27:01
(6 hours ago)
[redacted] 109.245.34.49 - - [13/Jun/2026:08:26:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 109.245.34.49 - - [13/Jun/2026:08:26:12 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.1)"
[redacted] 109.245.34.49 - - [13/Jun/2026:08:26:24 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 109.245.34.49 - - [13/Jun/2026:08:26:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 109.245.34.49 - - [13/Jun/2026:08:26:48 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 109.245.34.49 - - [13/Jun/2026:08:27:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐ซ๐ฎ
KnightIndustries
2026-06-12 20:52:24
(15 hours ago)
2026-06-12T22:51:27.583800+02:00 milkyway wordpress(oldscarborough.com)[3526749]: XML-RPC authentica ...
show more
2026-06-12T22:51:27.583800+02:00 milkyway wordpress(oldscarborough.com)[3526749]: XML-RPC authentication failure for joshua from 109.245.34.49
2026-06-12T22:51:40.855884+02:00 milkyway wordpress(oldscarborough.com)[3491792]: XML-RPC authentication failure for joshua from 109.245.34.49
2026-06-12T22:52:23.795553+02:00 milkyway wordpress(oldscarborough.com)[3513130]: XML-RPC authentication failure for joshua from 109.245.34.49
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 16:24:45
(20 hours ago)
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): ...
show more
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 12:24:40.580061 2026] [security2:error] [pid 30228:tid 30228] [client 109.245.34.49:61342] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 109.245.34.49 (+1 hits since last alert)|frogdesignmexico.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "frogdesignmexico.com"] [uri "/xmlrpc.php"] [unique_id "aiwyyB4wPeHclvQoVvomOwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 10:21:48
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): ...
show more
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 06:21:42.026974 2026] [security2:error] [pid 17684:tid 17684] [client 109.245.34.49:63348] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 109.245.34.49 (+1 hits since last alert)|seahattravel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "seahattravel.com"] [uri "/xmlrpc.php"] [unique_id "aivdthMTHrhFZYYq_bZCVgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 08:46:29
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): ...
show more
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 04:46:22.413144 2026] [security2:error] [pid 28082:tid 28082] [client 109.245.34.49:63938] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 109.245.34.49 (+1 hits since last alert)|drwolberg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "drwolberg.com"] [uri "/xmlrpc.php"] [unique_id "aivHXmTgw5MdbyiF7Xtr6wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-12 04:41:15
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 03:27:38
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): ...
show more
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 23:27:31.111418 2026] [security2:error] [pid 18907:tid 18907] [client 109.245.34.49:57211] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 109.245.34.49 (+1 hits since last alert)|globalweb123.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "globalweb123.com"] [uri "/xmlrpc.php"] [unique_id "ait8o1VxVraCuEIIxN_-VQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-12 02:24:04
(1 day ago)
trying wp-login.php/xmlrpc.php 30 times in 1 minutes
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2026-06-11 09:38:13
(2 days ago)
109.245.34.49 - - [11/Jun/2026:11:37:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3298 "-" "Jetpack by ...
show more
109.245.34.49 - - [11/Jun/2026:11:37:32 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3298 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)" 109.245.34.49 - - [11/Jun/2026:11:37:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3299 "-" "Jetpack/13.0; WordPress/6.4; http://site52638849.com" 109.245.34.49 - - [11/Jun/2026:11:38:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3298 "-" "Jetpack/13.0; WordPress/6.2; http://site89041135.com"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 06:10:55
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): ...
show more
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 02:10:48.664370 2026] [security2:error] [pid 29141:tid 29141] [client 109.245.34.49:56870] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 109.245.34.49 (+1 hits since last alert)|versallis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "versallis.com"] [uri "/xmlrpc.php"] [unique_id "aipRaLP0xC9QGet7UThTbQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-11 03:54:16
(2 days ago)
Attac
Brute-Force
๐ซ๐ท
dynamix
2026-06-11 01:10:03
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 00:11:33
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): ...
show more
(mod_security) mod_security (id:240335) triggered by 109.245.34.49 (net49-34-245-109.mbb.yettel.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 20:11:29.258366 2026] [security2:error] [pid 6423:tid 6423] [client 109.245.34.49:59566] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 109.245.34.49 (+1 hits since last alert)|forerunnersjazz.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "forerunnersjazz.org"] [uri "/xmlrpc.php"] [unique_id "ain9Mc0nN2Bhv3YoLhg-wQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-06-10 23:16:45
(2 days ago)
(wordpress) Failed wordpress login from 109.245.34.49 (RS/Serbia/Belgrade/Belgrade/net49-34-245-109. ...
show more
(wordpress) Failed wordpress login from 109.245.34.49 (RS/Serbia/Belgrade/Belgrade/net49-34-245-109.mbb.yettel.rs)
show less
Brute-Force
Anonymous
2025-01-01 14:55:33
(1 year ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host