Anonymous
2026-06-05 03:14:16
(1 day ago)
Attac
Brute-Force
๐ซ๐ท
applemooz
2026-06-04 12:57:08
(2 days ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-04 12:26:49
(2 days ago)
(wordpress) Failed wordpress login from 112.134.183.28 (LK/Sri Lanka/v4.dns.slt.lk)
Brute-Force
Anonymous
2026-06-04 09:15:04
(2 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ช๐ธ
elcruzado.es
2026-06-04 09:08:49
(2 days ago)
(wordpress) Failed wordpress login from 112.134.183.28 (LK/Sri Lanka/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-04 07:18:06
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 112.134.183.28 (v4.dns.slt.lk): 1 in the last 3 ...
show more
(mod_security) mod_security (id:240335) triggered by 112.134.183.28 (v4.dns.slt.lk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 03:18:01.579537 2026] [security2:error] [pid 23621:tid 23621] [client 112.134.183.28:22267] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.134.183.28 (+1 hits since last alert)|tenmenband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tenmenband.com"] [uri "/xmlrpc.php"] [unique_id "aiEmqToQphedeRldu1PbzgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-06-04 07:03:21
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-06-04 05:49:24
(2 days ago)
[redacted] 112.134.183.28 - - [04/Jun/2026:07:48:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" " ...
show more
[redacted] 112.134.183.28 - - [04/Jun/2026:07:48:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 112.134.183.28 - - [04/Jun/2026:07:48:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 112.134.183.28 - - [04/Jun/2026:07:49:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.1; http://site61061378.com"
[redacted] 112.134.183.28 - - [04/Jun/2026:07:49:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 112.134.183.28 - - [04/Jun/2026:07:49:22 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 04:32:56
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 112.134.183.28 (v4.dns.slt.lk): 1 in the last 3 ...
show more
(mod_security) mod_security (id:240335) triggered by 112.134.183.28 (v4.dns.slt.lk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 00:32:49.766401 2026] [security2:error] [pid 8253:tid 8253] [client 112.134.183.28:22721] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.134.183.28 (+1 hits since last alert)|fatcaverecords.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fatcaverecords.com"] [uri "/xmlrpc.php"] [unique_id "aiD_8ZGW3tBtg8G6fL3lKgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 02:49:13
(2 days ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-04 02:48:26
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 112.134.183.28 (v4.dns.slt.lk): 1 in the last 3 ...
show more
(mod_security) mod_security (id:240335) triggered by 112.134.183.28 (v4.dns.slt.lk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 22:48:23.396246 2026] [security2:error] [pid 10283:tid 10283] [client 112.134.183.28:22348] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.134.183.28 (+1 hits since last alert)|medusakenya.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "medusakenya.com"] [uri "/xmlrpc.php"] [unique_id "aiDnd6yHBcokKdxi_i0sRwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-06-04 02:47:53
(2 days ago)
112.134.183.28 - - [04/Jun/2026:
...
Brute-Force
Anonymous
2026-06-04 01:50:03
(2 days ago)
Web App Attack, Hacking
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 01:49:17
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 112.134.183.28 (v4.dns.slt.lk): 1 in the last 3 ...
show more
(mod_security) mod_security (id:240335) triggered by 112.134.183.28 (v4.dns.slt.lk): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 21:49:09.316269 2026] [security2:error] [pid 4310:tid 4310] [client 112.134.183.28:22461] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 112.134.183.28 (+1 hits since last alert)|indiahouseportland.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "indiahouseportland.com"] [uri "/xmlrpc.php"] [unique_id "aiDZledpTNM5i2lSuIxdYAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 10:55:40
(3 days ago)
[redacted] 112.134.183.28 - - [03/Jun/2026:12:54:59 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" " ...
show more
[redacted] 112.134.183.28 - - [03/Jun/2026:12:54:59 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com"
[redacted] 112.134.183.28 - - [03/Jun/2026:12:55:09 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "WordPress.com; https://wordpress.com"
[redacted] 112.134.183.28 - - [03/Jun/2026:12:55:19 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com"
[redacted] 112.134.183.28 - - [03/Jun/2026:12:55:30 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com"
[redacted] 112.134.183.28 - - [03/Jun/2026:12:55:40 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
...
show less
Hacking
Web App Attack