Anonymous
2026-06-07 15:44:16
(14 hours ago)
Attac
Brute-Force
๐ฉ๐ช
pscriptos
2026-06-06 22:21:54
(1 day ago)
{"ClientAddr":"92.241.37.50:56436","ClientHost":"92.241.37.50","ClientPort":"56436","ClientUsername" ...
show more
{"ClientAddr":"92.241.37.50:56436","ClientHost":"92.241.37.50","ClientPort":"56436","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":143570552,"OriginContentSize":418,"OriginDuration":139611576,"OriginStatus":403,"Overhead":3958976,"RequestAddr":"www.cleveradmin.de","RequestContentSize":703,"RequestCount":1442849,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-06-07T00:21:29.555334904+02:00","StartUTC":"2026-06-06T22:21:29.555334904Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-06-07T00:21:29+02:00"}
{"ClientAddr":"92.241.37.50:56436","ClientHost":"92.241.37.50","Clie
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2026-06-06 20:10:07
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (JO/Jordan/-): 5 in the last 300 s ...
show more
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (JO/Jordan/-): 5 in the last 300 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 18:40:34
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 14:40:26.665595 2026] [security2:error] [pid 23529:tid 23529] [client 92.241.37.50:58070] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 92.241.37.50 (+1 hits since last alert)|exhaustthelimits.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "exhaustthelimits.org"] [uri "/xmlrpc.php"] [unique_id "aiRpml3oZDGpKY_hpnTBkQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-06 14:51:50
(1 day ago)
[redacted] 92.241.37.50 - - [06/Jun/2026:16:51:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Wo ...
show more
[redacted] 92.241.37.50 - - [06/Jun/2026:16:51:06 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 92.241.37.50 - - [06/Jun/2026:16:51:15 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 92.241.37.50 - - [06/Jun/2026:16:51:27 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 92.241.37.50 - - [06/Jun/2026:16:51:38 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
[redacted] 92.241.37.50 - - [06/Jun/2026:16:51:49 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
...
show less
Hacking
Web App Attack
Anonymous
2026-06-06 13:11:14
(1 day ago)
[ns41.kdns.gr] httpd-xmlrpc-post: sites=kkourelis.gr; logs=/var/log/httpd/domains/kkourelis.gr.log; ...
show more
[ns41.kdns.gr] httpd-xmlrpc-post: sites=kkourelis.gr; logs=/var/log/httpd/domains/kkourelis.gr.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 22:10:34
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 18:10:29.959347 2026] [security2:error] [pid 20840:tid 20866] [client 92.241.37.50:55720] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 92.241.37.50 (+1 hits since last alert)|whatismetamodern.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "whatismetamodern.com"] [uri "/xmlrpc.php"] [unique_id "aiNJVX36TmDAVo85cDduzQAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-05 16:10:54
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ณ๐ฑ
Site.eu
2026-06-03 14:17:34
(4 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-06-03 00:00:37
(5 days ago)
[redacted] 92.241.37.50 - - [03/Jun/2026:01:59:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Wo ...
show more
[redacted] 92.241.37.50 - - [03/Jun/2026:01:59:46 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 92.241.37.50 - - [03/Jun/2026:01:59:58 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 92.241.37.50 - - [03/Jun/2026:02:00:10 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.1; http://site77660151.com"
[redacted] 92.241.37.50 - - [03/Jun/2026:02:00:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.2; http://site92677941.com"
[redacted] 92.241.37.50 - - [03/Jun/2026:02:00:36 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 23:03:03
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 19:02:58.697618 2026] [security2:error] [pid 9084:tid 9084] [client 92.241.37.50:54374] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 92.241.37.50 (+1 hits since last alert)|indoorsfinishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "indoorsfinishing.com"] [uri "/xmlrpc.php"] [unique_id "ah9hIiJHVO20NwXk5cPAygAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-02 16:35:50
(5 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
JO/Hashemite Kingdom of Jordan/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 00:15:12
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 20:15:09.083856 2026] [security2:error] [pid 22096:tid 22096] [client 92.241.37.50:57794] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 92.241.37.50 (+1 hits since last alert)|pinetreedistrict.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pinetreedistrict.org"] [uri "/xmlrpc.php"] [unique_id "ah4gjTBVZDIHiIlico8fgQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-01 23:42:15
(6 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-06-01 14:28:15
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 92.241.37.50 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 10:28:09.151577 2026] [security2:error] [pid 32730:tid 32730] [client 92.241.37.50:52708] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 92.241.37.50 (+1 hits since last alert)|metcomarine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "metcomarine.com"] [uri "/xmlrpc.php"] [unique_id "ah2W-eBkGDmwEm36B9JtUgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack