Anonymous
2026-07-29 11:57:33
(1 hour ago)
[redacted] 154.192.113.242 - - [29/Jul/2026:13:56:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" ...
show more
[redacted] 154.192.113.242 - - [29/Jul/2026:13:56:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "WordPress.com; https://wordpress.com"
[redacted] 154.192.113.242 - - [29/Jul/2026:13:56:51 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
[redacted] 154.192.113.242 - - [29/Jul/2026:13:56:57 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com"
[redacted] 154.192.113.242 - - [29/Jul/2026:13:57:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
[redacted] 154.192.113.242 - - [29/Jul/2026:13:57:07 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack by WordPress.com (Jetpack 12.5; WordPress 6.2)"
[redacted] 154.192.113.242 - - [29/Jul/2026:13:57:12 +0200] "POST /xmlrpc.php HTTP/1.1" 200 418 "-" "Jetpack/12.0; WordPress/6.1; http://site84749884.com"
[redacted] 154.192.113.242 - - [29/Jul/
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 09:06:11
(4 hours ago)
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 05:06:03.442288 2026] [security2:error] [pid 2838817:tid 2838817] [client 154.192.113.242:25237] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.192.113.242 (+1 hits since last alert)|nypatriotcards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "nypatriotcards.com"] [uri "/xmlrpc.php"] [unique_id "amnCe5-bHO_bDo1eZOjJ3gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 07:50:14
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 03:50:10.508748 2026] [security2:error] [pid 874388:tid 874388] [client 154.192.113.242:26270] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.192.113.242 (+1 hits since last alert)|dalessalesandservice.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dalessalesandservice.com"] [uri "/xmlrpc.php"] [unique_id "amhfMhdConmOXYswtnSRFwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-27 10:21:31
(2 days ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
grassau.com
2026-07-27 10:18:44
(2 days ago)
(wordpress) Failed wordpress login from 154.192.113.242 (PK/Pakistan/Khyber Pakhtunkhwa/Peshawar/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 06:20:41
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 02:20:36.456339 2026] [security2:error] [pid 3888169:tid 3888169] [client 154.192.113.242:8190] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.192.113.242 (+1 hits since last alert)|flatchestedmama.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "flatchestedmama.com"] [uri "/xmlrpc.php"] [unique_id "amb4tGudhuVDJtud-aPhNwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 05:52:22
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 01:52:13.531564 2026] [security2:error] [pid 3214760:tid 3214760] [client 154.192.113.242:7836] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.192.113.242 (+1 hits since last alert)|naturalhomebuilders.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "naturalhomebuilders.com"] [uri "/xmlrpc.php"] [unique_id "ambyDcf2lVs98ypAqxaqpQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-10 11:37:38
(2 weeks ago)
[da.kdns.gr] httpd-xmlrpc-post: sites=www.oro24.gr; logs=/var/log/httpd/domains/oro24.gr.log; sample ...
show more
[da.kdns.gr] httpd-xmlrpc-post: sites=www.oro24.gr; logs=/var/log/httpd/domains/oro24.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐ฉ๐ช
grassau.com
2026-05-21 06:20:53
(2 months ago)
(wordpress) Failed wordpress login from 154.192.113.242 (PK/Pakistan/Khyber Pakhtunkhwa/Peshawar/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-20 12:30:22
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 08:30:18.657390 2026] [security2:error] [pid 12672:tid 12672] [client 154.192.113.242:16235] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.192.113.242 (+1 hits since last alert)|gellertdealers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gellertdealers.com"] [uri "/xmlrpc.php"] [unique_id "ag2pWgMmP1fFnt2j1ZQvqwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 08:55:57
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 04:55:52.963305 2026] [security2:error] [pid 24349:tid 24349] [client 154.192.113.242:16204] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.192.113.242 (+1 hits since last alert)|toepferlab.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "toepferlab.org"] [uri "/xmlrpc.php"] [unique_id "ag13GOOn5UsiDdBNIcXttwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-05-19 15:26:47
(2 months ago)
(wordpress) Failed wordpress login from 154.192.113.242 (PK/Pakistan/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-19 14:27:00
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:240335) triggered by 154.192.113.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 10:26:53.913681 2026] [security2:error] [pid 27226:tid 27226] [client 154.192.113.242:16007] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.192.113.242 (+1 hits since last alert)|mdsshop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mdsshop.com"] [uri "/xmlrpc.php"] [unique_id "agxzLefAXEkH8ujdho5YHwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-18 15:38:22
(2 months ago)
(xmlrpc) Apache: Failed xmlrpc access from 154.192.113.242 (PK/Pakistan/-): 10 in the last 3600 secs ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 154.192.113.242 (PK/Pakistan/-): 10 in the last 3600 secs (0-201)
show less
Hacking
Anonymous
2026-05-18 13:12:55
(2 months ago)
Attac
Brute-Force