๐ฎ๐น
CoreTech srl
2026-08-08 15:28:56
(2 weeks ago)
cloudlinux2 fail2ban: 2026-08-08 17:23:54,419 fail2ban.actions [1467]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-08 17:23:54,419 fail2ban.actions [1467]: NOTICE [plesk-modsecurity] Unban 106.222.205.96cloudlinux2 fail2ban: 2026-08-08 17:23:55,213 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 103.161.55.78 - 2026-08-08 17:23:55cloudlinux2 fail2ban: 2026-08-08 17:24:10,785 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 34.138.40.57 - 2026-08-08 17:24:10cloudlinux2 fail2ban: 2026-08-08 17:24:11,005 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 34.138.40.57 - 2026-08-08 17:24:11cloudlinux2 fail2ban: 2026-08-08 17:24:10,777 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 34.138.40.57 - 2026-08-08 17:24:10cloudlinux2 fail2ban: 2026-08-08 17:24:10,751 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 34.138.40.57 - 2026-08-08 17:24:10cloudlinux2 fail2ban: 2026-08-08 17:24:10,805 fail2ban.filter [1467]: INFO [plesk-modsecurity] Found 34.138.40.57 - 2026-08-08 17:24:10cloudlinux2 fail2ban:
show less
Brute-Force
๐ง๐ช
cmbplf
2026-08-08 10:05:45
(2 weeks ago)
2.753 requests from abuseipdb.com blacklisted IP (7mos1w3d)
Brute-Force
Bad Web Bot
๐บ๐ธ
WeekendWeb
2026-08-08 10:01:55
(2 weeks ago)
Wordpress Vunerability attack
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-07 16:15:22
(2 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nest ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nesting / CPU-drain risk). Evidence: DEEP ATTACK: Recursive currentUrl nesting detected
show less
Hacking
Exploited Host
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-07 15:30:55
(2 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
Marc
2026-08-07 11:29:54
(2 weeks ago)
103.161.55.78 - - [07/Aug/2026:13:29:31 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4833 "-" "WordPress.c ...
show more
103.161.55.78 - - [07/Aug/2026:13:29:31 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4833 "-" "WordPress.com; https://wordpress.com" 103.161.55.78 - - [07/Aug/2026:13:29:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4831 "-" "WordPress.com; https://wordpress.com" 103.161.55.78 - - [07/Aug/2026:13:29:52 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4831 "-" "Jetpack by WordPress.com"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-07 09:20:58
(2 weeks ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-07 09:14:29
(2 weeks ago)
ModSecurity rejected a query
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 06:29:08
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.161.55.78 (keralavisionisp-dynamic-78.55.16 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.161.55.78 (keralavisionisp-dynamic-78.55.161.103.keralavisionisp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 02:29:03.376399 2026] [security2:error] [pid 32096:tid 32096] [client 103.161.55.78:12343] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.161.55.78 (+1 hits since last alert)|pleaseaddbacon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pleaseaddbacon.com"] [uri "/xmlrpc.php"] [unique_id "anV7LxN9bi2TPMAzsirCDgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-08-06 11:45:00
(2 weeks ago)
103.161.55.78 - - [06/Aug/2026:13:44:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6358 "-" "Jetpack by ...
show more
103.161.55.78 - - [06/Aug/2026:13:44:40 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6358 "-" "Jetpack by WordPress.com"
103.161.55.78 - - [06/Aug/2026:13:44:49 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6358 "-" "WordPress.com; https://wordpress.com"
103.161.55.78 - - [06/Aug/2026:13:45:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6358 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
show less
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-08-06 11:34:01
(2 weeks ago)
(xmlrpc) Failed xmlrpc access from 103.161.55.78 (IN/India/keralavisionisp-dynamic-78.55.161.103.ker ...
show more
(xmlrpc) Failed xmlrpc access from 103.161.55.78 (IN/India/keralavisionisp-dynamic-78.55.161.103.keralavisionisp.com): 5 in the last 3600 secs (0-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-06 11:33:18
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.161.55.78 (keralavisionisp-dynamic-78.55.16 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.161.55.78 (keralavisionisp-dynamic-78.55.161.103.keralavisionisp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 07:33:10.100070 2026] [security2:error] [pid 313293:tid 313293] [client 103.161.55.78:10208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.161.55.78 (+1 hits since last alert)|axiomemail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "axiomemail.net"] [uri "/xmlrpc.php"] [unique_id "anRw9o0G97dl1ztd2iuN7QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-08-06 11:29:37
(2 weeks ago)
103.161.55.78 - - [06/Aug/2026:13:29:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6358 "-" "Jetpack/12. ...
show more
103.161.55.78 - - [06/Aug/2026:13:29:16 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6358 "-" "Jetpack/12.5; WordPress/6.2; http://site65642541.com"
103.161.55.78 - - [06/Aug/2026:13:29:25 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6358 "-" "WordPress.com; https://wordpress.com"
103.161.55.78 - - [06/Aug/2026:13:29:36 +0200] "POST /xmlrpc.php HTTP/1.1" 200 6358 "-" "Jetpack/12.0; WordPress/6.3; http://site37558189.com"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 08:59:07
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.161.55.78 (keralavisionisp-dynamic-78.55.16 ...
show more
(mod_security) mod_security (id:225170) triggered by 103.161.55.78 (keralavisionisp-dynamic-78.55.161.103.keralavisionisp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 04:59:00.844058 2026] [security2:error] [pid 2329604:tid 2329604] [client 103.161.55.78:18367] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||crcponcha.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "crcponcha.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anRM1E2e1JY0lYcZMy4eaAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 07:13:31
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 103.161.55.78 (keralavisionisp-dynamic-78.55.16 ...
show more
(mod_security) mod_security (id:240335) triggered by 103.161.55.78 (keralavisionisp-dynamic-78.55.161.103.keralavisionisp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 03:13:24.968420 2026] [security2:error] [pid 70747:tid 70747] [client 103.161.55.78:5133] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 103.161.55.78 (+1 hits since last alert)|fishleadership.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fishleadership.org"] [uri "/xmlrpc.php"] [unique_id "anQ0FL7pM34NH3qzG5bFIwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack