Anonymous
2026-07-30 09:21:10
(54 minutes ago)
Automated Apache credential probe in 15m: hits=28; url=/xmlrpc.php; category=web-app-attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 07:15:47
(2 hours ago)
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 03:15:39.914477 2026] [security2:error] [pid 3160300:tid 3160300] [client 185.92.138.3:19798] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.92.138.3 (+1 hits since last alert)|denkyusalesca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "denkyusalesca.com"] [uri "/xmlrpc.php"] [unique_id "amr6G6w6RO-RRM-gYduSowAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 19:27:39
(14 hours ago)
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 15:27:32.214831 2026] [security2:error] [pid 156888:tid 156888] [client 185.92.138.3:21052] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.92.138.3 (+1 hits since last alert)|t9teamsportinggoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "t9teamsportinggoods.com"] [uri "/xmlrpc.php"] [unique_id "ampUJKELHsZODJw8sYAxPwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-29 11:56:16
(22 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-07-29 07:00:00
(1 day ago)
Automated Apache web application probing in selected 24h window; attempts=26, unique_paths=1, error_ ...
show more
Automated Apache web application probing in selected 24h window; attempts=26, unique_paths=1, error_responses=20; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(1 day ago)
Apache probe; attempts=26; exact paths: /xmlrpc.php
Web App Attack
๐ช๐ธ
alferez
2026-07-29 05:13:27
(1 day ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 02:41:24
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 22:41:18.157631 2026] [security2:error] [pid 3273414:tid 3273414] [client 185.92.138.3:6097] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.92.138.3 (+1 hits since last alert)|prcomputersolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "prcomputersolutions.com"] [uri "/xmlrpc.php"] [unique_id "amloTj8JqaU_JSDvW1HzOgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 02:11:35
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 22:11:31.013373 2026] [security2:error] [pid 1998926:tid 1998926] [client 185.92.138.3:3478] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.92.138.3 (+1 hits since last alert)|rentkase.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rentkase.com"] [uri "/xmlrpc.php"] [unique_id "amlhU5cuUO0oa5pj6IwGigAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 22:56:11
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 18:56:05.996494 2026] [security2:error] [pid 686258:tid 686309] [client 185.92.138.3:2249] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.92.138.3 (+1 hits since last alert)|kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kettlehill.com"] [uri "/xmlrpc.php"] [unique_id "amkzhQgh-7JgdneMjl82YwAAAZY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 18:10:05
(1 day ago)
IP banned by Fail2Ban in jail wordpress
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
bigwavedave
2026-07-28 18:09:20
(1 day ago)
Wordpress Attack
Web App Attack
Anonymous
2026-07-28 18:08:03
(1 day ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 16:28:32
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 185.92.138.3 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 12:28:25.414310 2026] [security2:error] [pid 1183056:tid 1183056] [client 185.92.138.3:3467] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 185.92.138.3 (+1 hits since last alert)|ucommsi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ucommsi.com"] [uri "/xmlrpc.php"] [unique_id "amjYqV8lHCBorqok6qGVtQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-07-28 16:00:52
(1 day ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force