Anonymous
2026-05-16 18:46:40
(3 months ago)
Attac
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-16 01:28:44
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 93.86.49.213 (93-86-49-213.static.isp.telekom.r ...
show more
(mod_security) mod_security (id:240335) triggered by 93.86.49.213 (93-86-49-213.static.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 21:28:35.937479 2026] [security2:error] [pid 32042:tid 32042] [client 93.86.49.213:61928] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 93.86.49.213 (+1 hits since last alert)|ssion.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ssion.com"] [uri "/xmlrpc.php"] [unique_id "agfIQ2RTgBCxy4LslD9HdwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 01:37:04
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 93.86.49.213 (93-86-49-213.static.isp.telekom.r ...
show more
(mod_security) mod_security (id:240335) triggered by 93.86.49.213 (93-86-49-213.static.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 21:36:57.260865 2026] [security2:error] [pid 21252:tid 21252] [client 93.86.49.213:22533] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 93.86.49.213 (+1 hits since last alert)|darrenj.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "darrenj.com"] [uri "/xmlrpc.php"] [unique_id "agZ4uQbJtjbeoDx7sodFSAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-14 23:38:40
(3 months ago)
Attac
Brute-Force
Anonymous
2026-05-14 19:32:03
(3 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
WellSpring
2026-05-13 00:56:35
(3 months ago)
xmlrpc exploit on 860.today/xmlrpc.php โ WellSpr.ing/NetSentinel civic-AI security layer
Brute-Force
Web App Attack
๐จ๐ฆ
Paulo Henrique dos Santos Nichio
2026-05-12 20:19:59
(3 months ago)
(ls_brute) LiteSpeed Brute Force Attack 93.86.49.213 (RS/Serbia/93-86-49-213.static.isp.telekom.rs): ...
show more
(ls_brute) LiteSpeed Brute Force Attack 93.86.49.213 (RS/Serbia/93-86-49-213.static.isp.telekom.rs): 3 in the last 600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026-05-12 17:19:01.702967 [WARN] [2134872] [T0] [93.86.49.213:5495#APVH_www.hslperfuratrizes.com.br:443] Brute force detected for IP [93.86.49.213], throttle.
2026-05-12 17:19:11.963577 [WARN] [2134872] [T0] [93.86.49.213:5495-1#APVH_www.hslperfuratrizes.com.br:443] Brute force detected for IP [93.86.49.213], throttle.
2026-05-12 17:19:57.928979 [WARN] [2134872] [T0] [93.86.49.213:45292-2#APVH_www.hslperfuratrizes.com.br:443] Brute force detected for IP [93.86.49.213], throttle.
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-12 19:10:13
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 93.86.49.213 (93-86-49-213.static.isp.telekom.r ...
show more
(mod_security) mod_security (id:240335) triggered by 93.86.49.213 (93-86-49-213.static.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 15:10:09.425207 2026] [security2:error] [pid 993:tid 993] [client 93.86.49.213:16023] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 93.86.49.213 (+1 hits since last alert)|cloudex.link|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cloudex.link"] [uri "/xmlrpc.php"] [unique_id "agN7ESrxV-Yh4YgLoJSRYwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-11 22:09:53
(3 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
grassau.com
2026-05-11 03:44:03
(3 months ago)
(wordpress) Failed wordpress login from 93.86.49.213 (RS/Serbia/Belgrade/Obrenovac/93-86-49-213.stat ...
show more
(wordpress) Failed wordpress login from 93.86.49.213 (RS/Serbia/Belgrade/Obrenovac/93-86-49-213.static.isp.telekom.rs)
show less
Brute-Force
๐ซ๐ท
dynamix
2026-05-10 23:25:45
(3 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-05-10 21:06:07
(3 months ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-10 04:52:59
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 93.86.49.213 (93-86-49-213.static.isp.telekom.r ...
show more
(mod_security) mod_security (id:240335) triggered by 93.86.49.213 (93-86-49-213.static.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 10 00:52:51.624819 2026] [security2:error] [pid 31514:tid 31514] [client 93.86.49.213:17192] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 93.86.49.213 (+1 hits since last alert)|bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bamedica.com"] [uri "/xmlrpc.php"] [unique_id "agAPI3zUZWTP5srOymcxGQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-05-10 02:33:56
(3 months ago)
1.975 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-10 01:49:58
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 93.86.49.213 (93-86-49-213.static.isp.telekom.r ...
show more
(mod_security) mod_security (id:240335) triggered by 93.86.49.213 (93-86-49-213.static.isp.telekom.rs): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 09 21:49:50.390629 2026] [security2:error] [pid 16580:tid 16580] [client 93.86.49.213:65144] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 93.86.49.213 (+1 hits since last alert)|srosa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "srosa.com"] [uri "/xmlrpc.php"] [unique_id "af_kPnkNgJ2gRDXEvRvfpQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack