๐ฉ๐ช
FeG Deutschland
2026-07-17 09:23:33
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 28
Exploited Host
Web App Attack
๐ซ๐ท
dynamix
2026-07-12 06:00:05
(2 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-07-12 05:30:04
(2 months ago)
[redacted] 111.92.135.90 - - [12/Jul/2026:07:29:21 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "J ...
show more
[redacted] 111.92.135.90 - - [12/Jul/2026:07:29:21 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.2)"
[redacted] 111.92.135.90 - - [12/Jul/2026:07:29:31 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)"
[redacted] 111.92.135.90 - - [12/Jul/2026:07:29:42 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 111.92.135.90 - - [12/Jul/2026:07:29:53 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 111.92.135.90 - - [12/Jul/2026:07:30:03 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.3)"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-12 05:01:56
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135. ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135.92.111.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 01:01:50.592303 2026] [security2:error] [pid 1000:tid 1000] [client 111.92.135.90:53826] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.135.90 (+1 hits since last alert)|bonesband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bonesband.com"] [uri "/xmlrpc.php"] [unique_id "alMfvtzUcdIFY1EndakbEgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
bigwavedave
2026-07-11 16:45:22
(2 months ago)
Wordpress Attack
Web App Attack
Anonymous
2026-07-11 16:44:07
(2 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 16:16:00
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135. ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135.92.111.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 12:15:52.158076 2026] [security2:error] [pid 25527:tid 25527] [client 111.92.135.90:53714] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.135.90 (+1 hits since last alert)|lightbender.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lightbender.net"] [uri "/xmlrpc.php"] [unique_id "alJsOI_OE_jKX-LTbUv8AQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 05:37:39
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135. ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135.92.111.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 01:37:33.801648 2026] [security2:error] [pid 30498:tid 30498] [client 111.92.135.90:53100] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.135.90 (+1 hits since last alert)|studioyau.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "studioyau.com"] [uri "/xmlrpc.php"] [unique_id "alHWnTnrdGR6Y7-WI__HIAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 05:08:09
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135. ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135.92.111.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 01:08:05.833059 2026] [security2:error] [pid 19532:tid 19532] [client 111.92.135.90:53978] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.135.90 (+1 hits since last alert)|yerevanpress.am|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "yerevanpress.am"] [uri "/xmlrpc.php"] [unique_id "alHPtc32x9ryHkqQyUnAEQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 17:19:57
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135. ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135.92.111.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 13:19:50.719143 2026] [security2:error] [pid 7260:tid 7260] [client 111.92.135.90:53512] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.135.90 (+1 hits since last alert)|desertautoworks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "desertautoworks.com"] [uri "/xmlrpc.php"] [unique_id "alEptiKpvFmVp40c2pHBqAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-07-10 15:49:25
(2 months ago)
111.92.135.90 - - [10/Jul/2026:11:48:29 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.c ...
show more
111.92.135.90 - - [10/Jul/2026:11:48:29 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.com; https://wordpress.com"
111.92.135.90 - - [10/Jul/2026:11:48:40 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.com; https://wordpress.com"
111.92.135.90 - - [10/Jul/2026:11:49:03 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.com; https://wordpress.com"
111.92.135.90 - - [10/Jul/2026:11:49:13 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.com; https://wordpress.com"
111.92.135.90 - - [10/Jul/2026:11:49:24 -0400] "POST /xmlrpc.php HTTP/1.0" 200 5266 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 15:20:05
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135. ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135.92.111.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 11:19:56.920504 2026] [security2:error] [pid 633:tid 633] [client 111.92.135.90:53355] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.135.90 (+1 hits since last alert)|fusteriafontane.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fusteriafontane.com"] [uri "/xmlrpc.php"] [unique_id "alENnHitO_YebNRPbIeNUgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 07:00:32
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135. ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.135.90 (fn135-dynamic90.snms.net.pk.135.92.111.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 03:00:26.899340 2026] [security2:error] [pid 11859:tid 11859] [client 111.92.135.90:53425] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.135.90 (+1 hits since last alert)|portlunchgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "portlunchgroup.com"] [uri "/xmlrpc.php"] [unique_id "alCYikodVEf0OWQhD69djQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-07-10 03:23:22
(2 months ago)
(xmlrpc_405) XMLRPC-Bot 405 111.92.135.90 (PK/Pakistan/fn135-dynamic90.snms.net.pk.135.92.111.in-add ...
show more
(xmlrpc_405) XMLRPC-Bot 405 111.92.135.90 (PK/Pakistan/fn135-dynamic90.snms.net.pk.135.92.111.in-addr.arpa)
show less
Hacking
Anonymous
2026-07-09 10:06:40
(2 months ago)
Fail2Ban - Wordpress brute-force
...
Brute-Force
Web App Attack