๐ซ๐ท
Sysadmin Peter
2026-02-18 10:27:43
(4 months ago)
Feb 18 11:27:43 mail postfix/smtpd[2884633]: warning: unknown[151.241.122.79]: SASL CRAM-MD5 authent ...
show more
Feb 18 11:27:43 mail postfix/smtpd[2884633]: warning: unknown[151.241.122.79]: SASL CRAM-MD5 authentication failed: authentication failure
Feb 18 11:27:43 mail postfix/smtpd[2884633]: warning: unknown[151.241.122.79]: SASL PLAIN authentication failed: authentication failure
...
show less
Email Spam
๐ซ๐ท
UM3
2026-02-18 09:26:20
(4 months ago)
Exim Auth Failed
Brute-Force
๐ฌ๐ง
consul.to
2026-02-07 02:07:15
(4 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
โจ
2026-02-03 02:50:11
(4 months ago)
Rule : SMTP
02/03/26 03:48:56 2684 151.241.122.79 220 mail.equateur.ch 22 0
02/03/26 03:48:56 2 ...
show more
Rule : SMTP
02/03/26 03:48:56 2684 151.241.122.79 220 mail.equateur.ch 22 0
02/03/26 03:48:56 2684 151.241.122.79 EHLO ehlo [10.10.18.245] ***hidden-privacy*** [151.241.122.79], this server offers 7 extensions 214 21
02/03/26 03:48:56 2684 151.241.122.79 AUTH {blank} 334 PDE4NzcyLjEyMzg3NzIxNDBAbnMzMjQxMDE3Pg== 46 15
02/03/26 03:48:57 2684 151.241.122.79 AUTH aWtAZGtsaWsuY2ggMTU2MjAwNTc1YjQyMzA4NDU5NWI0YTViZTQxMGE3Njg= 535 Invalid username or password CRAM-MD5 43 62
02/03/26 03:48:57 2684 151.241.122.79 AUTH {blank} 334 UGFzc3dvcmQ6 18 29 [email protected]
02/03/26 03:48:57 2684 151.241.122.79 AUTH {blank} 535 Invalid Username or Password 34 18 [email protected]
show less
Email Spam
Port Scan
Spoofing
๐จ๐ฟ
lp
2026-01-30 12:07:32
(4 months ago)
Email account brute force: 2 attempts were recorded from 151.241.122.79
2026-01-30T11:51:17+01:00 wa ...
show more
Email account brute force: 2 attempts were recorded from 151.241.122.79
2026-01-30T11:51:17+01:00 warning: unknown[151.241.122.79]: SASL PLAIN authentication failed: authentication failure, [email protected]
2026-01-30T11:51:17+01:00 warning: unknown[151.241.122.79]: SASL LOGIN authentication failed: authentication failure, [email protected]
show less
Brute-Force
๐บ๐ธ
bigscoots.com
2026-01-24 23:28:04
(4 months ago)
(smtpauth) Failed SMTP AUTH login from 151.241.122.79 (US/United States/-): 5 in the last 3600 secs; ...
show more
(smtpauth) Failed SMTP AUTH login from 151.241.122.79 (US/United States/-): 5 in the last 3600 secs; Ports: 25,465,587; Direction: 0; Trigger: LF_SMTPAUTH; Logs: 2026-01-24 18:27:35 dovecot_plain authenticator failed for H=([10.10.18.245]) [151.241.122.79]:28457: 535 Incorrect authentication data ([email protected] )
2026-01-24 18:27:41 dovecot_login authenticator failed for H=([10.10.18.245]) [151.241.122.79]:28457: 535 Incorrect authentication data ([email protected] )
2026-01-24 18:27:47 dovecot_plain authenticator failed for H=([10.10.18.245]) [151.241.122.79]:28423: 535 Incorrect authentication data ([email protected] )
2026-01-24 18:27:53 dovecot_login authenticator failed for H=([10.10.18.245]) [151.241.122.79]:28423: 535 Incorrect authentication data ([email protected] )
2026-01-24 18:28:01 dovecot_plain authenticator failed for H=([10.10.18.245]) [151.241.122.79]:1588: 535 Incorrect authentication data ([email protected] )
show less
Brute-Force
SSH
Anonymous
2025-10-30 18:02:19
(7 months ago)
Attempted brute force login to web vpn 13 time(s); last attempt for 2025.10.30 is noted in report ti ...
show more
Attempted brute force login to web vpn 13 time(s); last attempt for 2025.10.30 is noted in report timestamp
show less
Hacking
Brute-Force
๐ฉ๐ช
grassau.com
2025-08-18 16:26:56
(10 months ago)
(wordpress) Failed wordpress login from 151.241.122.79 (US/United States/-)
Brute-Force
Anonymous
2025-08-18 16:08:21
(10 months ago)
151.241.122.79 - - [18/Aug/2025:16:08:20 +0000] "POST /xmlrpc.php HTTP/1.1" 404 17315 "-" "Mozilla/5 ...
show more
151.241.122.79 - - [18/Aug/2025:16:08:20 +0000] "POST /xmlrpc.php HTTP/1.1" 404 17315 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; x86) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-08-18 02:21:29
(10 months ago)
1.629 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-08-17 08:23:33
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 151.241.122.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 151.241.122.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 17 04:23:28.649435 2025] [security2:error] [pid 3011:tid 3011] [client 151.241.122.79:8234] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||limadeltadx.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "limadeltadx.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aKGRgI5yUuChUlaacUI72gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-16 02:32:25
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 151.241.122.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 151.241.122.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 15 22:32:21.247100 2025] [security2:error] [pid 21062:tid 21062] [client 151.241.122.79:61981] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tenmenband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tenmenband.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aJ_ttQp-C_vopA4TTWFozAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-15 02:54:26
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 151.241.122.79 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 151.241.122.79 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 14 22:54:20.690626 2025] [security2:error] [pid 32537:tid 32537] [client 151.241.122.79:12396] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||themadwriter.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "themadwriter.us"] [uri "/wp-json/wp/v2/users"] [unique_id "aJ6hXKuUt8N-nOoXQ6_piwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2025-08-13 02:18:05
(10 months ago)
151.241.122.79 - - [12/Aug/2025:21:12:02 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2972 "-" "Mozilla/5. ...
show more
151.241.122.79 - - [12/Aug/2025:21:12:02 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2972 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/94.0.0.0 Safari/537.36"
151.241.122.79 - - [12/Aug/2025:21:13:26 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2972 "-" "Mozilla/5.0 (Linux; Android 10; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/83.0.0.0 Safari/537.36"
151.241.122.79 - - [12/Aug/2025:21:14:46 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2971 "-" "Mozilla/5.0 (Windows NT 10.0; x86) AppleWebKit/537.36 (KHTML, like Gecko) Safari/14.0.0.0 Safari/537.36"
151.241.122.79 - - [12/Aug/2025:21:16:12 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2971 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; x86) AppleWebKit/537.36 (KHTML, like Gecko) Firefox/80.0.0.0 Safari/537.36"
151.241.122.79 - - [12/Aug/2025:21:18:03 -0500] "POST /xmlrpc.php HTTP/1.1" 200 2972 "-" "Mozilla/5.0 (Windows NT 6.3; x64) AppleWebKit/537.36 (KHTML, like Gecko) Opera/71.0.0.0 S
...
show less
Web App Attack
๐ฆ๐บ
weblite
2025-08-12 21:05:22
(10 months ago)
WP_XMLRPC_ABUSE
Brute-Force
Web App Attack