Anonymous
2026-07-20 10:20:00
(2 days ago)
[ns65.kdns.gr] httpd-xmlrpc-post: sites=www.villafleria.gr; logs=/var/log/httpd/domains/villafleria. ...
show more
[ns65.kdns.gr] httpd-xmlrpc-post: sites=www.villafleria.gr; logs=/var/log/httpd/domains/villafleria.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
πΊπΈ
n2nguyenn2nguyen
2026-07-20 10:01:38
(2 days ago)
Blocked by YFC Security on https://brixzly.com β type: xmlrpc_attempts
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 09:32:36
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 05:32:30.642186 2026] [security2:error] [pid 636175:tid 636175] [client 111.92.145.54:47379] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.145.54 (+1 hits since last alert)|jerielster.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jerielster.com"] [uri "/xmlrpc.php"] [unique_id "al3rLrVeENwWnvMQnunhgQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-20 09:02:03
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 05:01:53.888108 2026] [security2:error] [pid 9599:tid 9680] [client 111.92.145.54:47208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.145.54 (+1 hits since last alert)|koalacogs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "koalacogs.com"] [uri "/xmlrpc.php"] [unique_id "al3kAV9pCgxli8Rn0xxccgAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
abdubhai
2026-07-20 09:00:28
(2 days ago)
111.92.145.54 - - [20/Jul/2026:1
...
Brute-Force
πΊπΈ
TPI-Abuse
2026-07-20 07:19:06
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 03:18:59.393369 2026] [security2:error] [pid 2655704:tid 2655704] [client 111.92.145.54:47469] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.145.54 (+1 hits since last alert)|bigheartskitchen.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bigheartskitchen.net"] [uri "/xmlrpc.php"] [unique_id "al3L4ySp_NIZI-PfOeJR0QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
ipoac.nl
2026-07-20 06:40:46
(2 days ago)
2026-07-20T08:40:45.679448+02:00 ipoac.nl wordpress(-)-: XML-RPC authentication failure for-from 111 ...
show more
2026-07-20T08:40:45.679448+02:00 ipoac.nl wordpress(-)-: XML-RPC authentication failure for-from 111.92.145.54
show less
Web App Attack
πΊπΈ
LSPCCU
2026-07-02 06:51:24
(2 weeks ago)
TSEC Honeypot Network report. Threat score: 71/100. Categories: DDoS Attack, Port Scan, Hacking, Bru ...
show more
TSEC Honeypot Network report. Threat score: 71/100. Categories: DDoS Attack, Port Scan, Hacking, Brute-Force, Web App Attack, SSH. Honeypot: ssh-telnet, cowrie. Context: 111.
show less
DDoS Attack
Port Scan
Hacking
Brute-Force
Web App Attack
SSH
Anonymous
2026-06-30 10:36:05
(3 weeks ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
πΊπΈ
kosada.com
2026-06-29 08:16:40
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
π©πͺ
SMARTNET
2026-05-27 06:03:53
(1 month ago)
Aisuru(Mirai variant) DDoS | Incident ID: 1175168a-7e6d-467e-bb9a-dd1cdfa3fb9e
DDoS Attack
π§πͺ
cmbplf
2026-05-07 13:47:28
(2 months ago)
5.708 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-05-07 12:48:50
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 08:48:45.231364 2026] [security2:error] [pid 29582:tid 29582] [client 111.92.145.54:52653] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.145.54 (+1 hits since last alert)|cypro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cypro.com"] [uri "/xmlrpc.php"] [unique_id "afyKLczyJPyKdCYVArvmAAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-07 12:13:14
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 08:13:09.004973 2026] [security2:error] [pid 24211:tid 24211] [client 111.92.145.54:52242] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.145.54 (+1 hits since last alert)|marshdcs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "marshdcs.com"] [uri "/xmlrpc.php"] [unique_id "afyB1ZvzDslUT3A4hnuViwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-07 11:47:30
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 111.92.145.54 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 07 07:47:22.789982 2026] [security2:error] [pid 11180:tid 11208] [client 111.92.145.54:52782] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 111.92.145.54 (+1 hits since last alert)|worldecom.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "worldecom.org"] [uri "/xmlrpc.php"] [unique_id "afx7ypcZxwj4Ru4uK15idgAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack