Anonymous
2026-07-21 14:02:08
(11 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 11:50:07
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.213.81.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.213.81.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:50:00.646157 2026] [security2:error] [pid 21344:tid 21344] [client 106.213.81.221:29933] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.213.81.221 (+1 hits since last alert)|rohanbyles.com.au|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rohanbyles.com.au"] [uri "/xmlrpc.php"] [unique_id "al9c6NXQrBIMR2scQFMBaQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 11:18:30
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.213.81.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.213.81.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:18:26.925272 2026] [security2:error] [pid 22150:tid 22150] [client 106.213.81.221:15188] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.213.81.221 (+1 hits since last alert)|gemco-mfg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gemco-mfg.com"] [uri "/xmlrpc.php"] [unique_id "al9Vgk_4ldgjZl8LBfIGNAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-21 09:46:26
(15 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 08:09:47
(17 hours ago)
(mod_security) mod_security (id:240335) triggered by 106.213.81.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 106.213.81.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 04:09:40.728217 2026] [security2:error] [pid 3438769:tid 3438776] [client 106.213.81.221:9041] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 106.213.81.221 (+1 hits since last alert)|supercyprus.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "supercyprus.com"] [uri "/xmlrpc.php"] [unique_id "al8pRE7sj6mtF_W_GLclSwAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-07-21 08:08:09
(17 hours ago)
(wordpress) Failed wordpress login from 106.213.81.221 (IN/India/-)
Brute-Force
Anonymous
2026-05-01 07:45:55
(2 months ago)
Unauthorized connection attempt on Port 23
Port Scan
Hacking
Exploited Host
Anonymous
2026-04-17 03:43:06
(3 months ago)
Automated bot traffic โ residential proxy, fake browser fingerprint. UA="Mozilla/5.0 (Windows NT 10. ...
show more
Automated bot traffic โ residential proxy, fake browser fingerprint. UA="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/109.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Packets-Decreaser.NET
2024-09-27 08:17:54
(1 year ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐บ๐ธ
hostseries
2024-08-05 09:47:35
(1 year ago)
Trigger: LF_DISTATTACK
Brute-Force
Anonymous
2024-08-05 09:39:23
(1 year ago)
Ports: 25,465,587; Direction: 0; Trigger: LF_DISTATTACK
Brute-Force
SSH
๐จ๐ฟ
unhfree.net
2024-08-05 09:37:24
(1 year ago)
Aug 5 11:24:58 canopus postfix/smtpd[2812808]: NOQUEUE: reject: RCPT from unknown[106.213.81.221]: ...
show more
Aug 5 11:24:58 canopus postfix/smtpd[2812808]: NOQUEUE: reject: RCPT from unknown[106.213.81.221]: 554 5.7.1 <[email protected] >: Recipient address rejected: Maximum 20 messages per 60 minutes limit reached; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<unhfree.net>
Aug 5 11:26:22 canopus postfix/smtpd[2815429]: NOQUEUE: reject: RCPT from unknown[106.213.81.221]: 554 5.7.1 <[email protected] >: Recipient address rejected: Maximum 20 messages per 60 minutes limit reached; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<178-132-2-10.hosted-by-worldstream.net.>
Aug 5 11:28:43 canopus postfix/smtpd[2802762]: NOQUEUE: reject: RCPT from unknown[106.213.81.221]: 554 5.7.1 <[email protected] >: Recipient address rejected: Maximum 20 messages per 60 minutes limit reached; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<unhfree.net>
Aug 5 11:29:54 canopus postfix/smtpd[2812816]: NOQUEUE: reject: RCPT from unknown[106
...
show less
Brute-Force
Exploited Host