🇩🇪
dbmwebdesign
2026-08-29 04:00:12
(1 week ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
🇨🇦
Dunham Support
2026-08-29 02:58:19
(1 week ago)
(wordpress) Failed wordpress login from 124.158.42.213 (PH/Philippines/-)
Brute-Force
🇩🇪
abdubhai
2026-08-29 01:55:01
(1 week ago)
124.158.42.213 - - [29/Aug/2026:
...
Brute-Force
🇫🇷
dynamix
2026-08-29 01:25:25
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-08-28 01:59:29
(1 week ago)
(xmlrpc) Apache: Failed xmlrpc access from 124.158.42.213 (PH/Philippines/-): 10 in the last 3600 se ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 124.158.42.213 (PH/Philippines/-): 10 in the last 3600 secs (0-201)
show less
Hacking
🇺🇸
nationaleventpros.com
2026-08-28 00:11:11
(1 week ago)
WordPress login attempt
Brute-Force
🇺🇸
kosada.com
2026-08-27 05:12:02
(1 week ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-25 14:24:22
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 10:24:11.155730 2026] [security2:error] [pid 4453:tid 4453] [client 124.158.42.213:40503] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.213 (+1 hits since last alert)|btccasting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "btccasting.com"] [uri "/xmlrpc.php"] [unique_id "ao2liwC0pAvIc6_BYhETAgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 13:21:48
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 09:21:34.568199 2026] [security2:error] [pid 32090:tid 32090] [client 124.158.42.213:34751] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.213 (+1 hits since last alert)|j3pr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "j3pr.com"] [uri "/xmlrpc.php"] [unique_id "ao2W3iyjmw9Iiv1X7qqcOAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 11:22:53
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 07:22:41.599559 2026] [security2:error] [pid 16838:tid 16838] [client 124.158.42.213:23896] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.213 (+1 hits since last alert)|badgerkelley.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "badgerkelley.com"] [uri "/xmlrpc.php"] [unique_id "ao17AWNv1HjRuP9my5v6mgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-25 09:50:43
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 124.158.42.213 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 124.158.42.213 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 05:50:31.648859 2026] [security2:error] [pid 777:tid 777] [client 124.158.42.213:46780] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 124.158.42.213 (+1 hits since last alert)|realclean.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "realclean.net"] [uri "/xmlrpc.php"] [unique_id "ao1lZzphETjisuWelykrAAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-07-31 04:17:25
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot