Anonymous
2026-06-27 10:08:05
(21 hours ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-26 14:38:43
(1 day ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐ฉ๐ช
grassau.com
2026-06-26 14:22:35
(1 day ago)
(wordpress) Failed wordpress login from 92.246.207.130 (RU/Russia/-/-/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-24 21:38:23
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 17:38:17.392465 2026] [security2:error] [pid 27504:tid 27504] [client 92.246.207.130:50855] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 92.246.207.130 (+1 hits since last alert)|telecompros.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "telecompros.net"] [uri "/xmlrpc.php"] [unique_id "ajxOSY9qNUTJdMurt9xs_wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-06-24 21:06:26
(3 days ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 20:37:33
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 16:37:28.527192 2026] [security2:error] [pid 30152:tid 30152] [client 92.246.207.130:57319] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 92.246.207.130 (+1 hits since last alert)|portlunchgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "portlunchgroup.com"] [uri "/xmlrpc.php"] [unique_id "ajxACGQYxPfT_0s1OVgifAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-24 20:04:07
(3 days ago)
92.246.207.130 - - [24/Jun/2026:22:03:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.c ...
show more
92.246.207.130 - - [24/Jun/2026:22:03:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.com; https://wordpress.com"
92.246.207.130 - - [24/Jun/2026:22:03:46 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "WordPress.com; https://wordpress.com"
92.246.207.130 - - [24/Jun/2026:22:03:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "Jetpack by WordPress.com"
92.246.207.130 - - [24/Jun/2026:22:03:56 +0200] "POST /xmlrpc.php HTTP/1.1" 200 403 "-" "Jetpack by WordPress.com"
92.246.207.130 - - [24/Jun/2026:22:04:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 593 "-" "WordPress.com; https://wordpress.com"
...
show less
Brute-Force
Web App Attack
๐ฒ๐น
Malta
2026-06-23 23:04:33
(4 days ago)
92.246.207.130 - - [24/Jun/2026:01:04:33 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack by WordPress.co ...
show more
92.246.207.130 - - [24/Jun/2026:01:04:33 +0200] "POST /xmlrpc.php HTTP/1.1" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.3)"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 21:34:54
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 17:34:48.930570 2026] [security2:error] [pid 31992:tid 31992] [client 92.246.207.130:53799] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 92.246.207.130 (+1 hits since last alert)|pakistanvision.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pakistanvision.com"] [uri "/xmlrpc.php"] [unique_id "ajr7-FFRBf1UTVp5i9j9JAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 21:04:23
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 17:04:15.019668 2026] [security2:error] [pid 20524:tid 20524] [client 92.246.207.130:53389] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 92.246.207.130 (+1 hits since last alert)|marcosbarraza.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "marcosbarraza.net"] [uri "/xmlrpc.php"] [unique_id "ajr0z-OvB7bENoQC6io_ZgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-23 20:04:00
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 16:03:54.030362 2026] [security2:error] [pid 26077:tid 26077] [client 92.246.207.130:53530] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 92.246.207.130 (+1 hits since last alert)|kidswow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kidswow.com"] [uri "/xmlrpc.php"] [unique_id "ajrmqh9B45vOtFqtm1UihQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
konseptit
2026-06-23 20:02:08
(4 days ago)
(wordpress) Failed wordpress login from 92.246.207.130 (RU/Russia/-)
Brute-Force
Anonymous
2026-06-22 21:34:04
(5 days ago)
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-22 20:43:55
(5 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 21:17:49
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 92.246.207.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 17:17:42.180496 2026] [security2:error] [pid 18494:tid 18494] [client 92.246.207.130:65426] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 92.246.207.130 (+1 hits since last alert)|graciousholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "graciousholding.com"] [uri "/xmlrpc.php"] [unique_id "ajcDdueUVuMYWeYcTMs-9QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack