๐ฉ๐ช
Vegascosmetics
2026-08-27 08:47:14
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 71>=65, Abuse 73, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2026-08-26 14:00:08
(2 days ago)
WordPress login brute-force | path: /xmlrpc.php | 2026-08-26 14:00 UTC
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-08-26 13:58:33
(2 days ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-08-25 14:48:58
(3 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
kosada.com
2026-08-25 12:46:52
(3 days ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-25 11:47:17
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 154.159.237.212 (212-237-159-154.r.airtelkenya. ...
show more
(mod_security) mod_security (id:240335) triggered by 154.159.237.212 (212-237-159-154.r.airtelkenya.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 07:47:12.937895 2026] [security2:error] [pid 1288:tid 1288] [client 154.159.237.212:32144] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.159.237.212 (+1 hits since last alert)|k2servicesinc.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "k2servicesinc.net"] [uri "/xmlrpc.php"] [unique_id "ao2AwEP5XGVe4inDMcU46gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-25 06:56:05
(3 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 05:57:14
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 154.159.237.212 (212-237-159-154.r.airtelkenya. ...
show more
(mod_security) mod_security (id:240335) triggered by 154.159.237.212 (212-237-159-154.r.airtelkenya.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 01:57:09.343751 2026] [security2:error] [pid 10701:tid 10701] [client 154.159.237.212:46479] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.159.237.212 (+1 hits since last alert)|pattenden.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pattenden.com"] [uri "/xmlrpc.php"] [unique_id "ao0utUnonvtyLNH_Qy7pqgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-08-25 04:11:38
(3 days ago)
(wordpress) Failed wordpress login from 154.159.237.212 (KE/Kenya/212-237-159-154.r.airtelkenya.com)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-24 13:20:50
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 154.159.237.212 (212-237-159-154.r.airtelkenya. ...
show more
(mod_security) mod_security (id:240335) triggered by 154.159.237.212 (212-237-159-154.r.airtelkenya.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:20:42.307869 2026] [security2:error] [pid 5035:tid 5035] [client 154.159.237.212:21501] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.159.237.212 (+1 hits since last alert)|speedysremodeling.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "speedysremodeling.com"] [uri "/xmlrpc.php"] [unique_id "aoxFKnSjRxCS1VjDwWvqEgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-08-24 12:16:13
(4 days ago)
Wordpress Vunerability attack
Web App Attack
๐ซ๐ท
masterguru
2026-08-24 09:43:19
(4 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 154.159.237.212 (KE/Kenya/212-237-159-154.r.airtelkenya.c ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 154.159.237.212 (KE/Kenya/212-237-159-154.r.airtelkenya.com): 10 in the last 3600 secs (0-201)
show less
Hacking
๐ฉ๐ช
pscriptos
2026-08-24 08:40:15
(4 days ago)
{"ClientAddr":"154.159.237.212:2029","ClientHost":"154.159.237.212","ClientPort":"2029","ClientUsern ...
show more
{"ClientAddr":"154.159.237.212:2029","ClientHost":"154.159.237.212","ClientPort":"2029","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":508412517,"OriginContentSize":418,"OriginDuration":495277908,"OriginStatus":403,"Overhead":13134609,"RequestAddr":"www.cleveradmin.de","RequestContentSize":714,"RequestCount":4798408,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-08-24T10:39:54.733203546+02:00","StartUTC":"2026-08-24T08:39:54.733203546Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-08-24T10:39:55+02:00"}
{"ClientAddr":"154.159.237.212:2029","ClientHost":"154.159.237.
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 06:28:55
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 154.159.237.212 (212-237-159-154.r.airtelkenya. ...
show more
(mod_security) mod_security (id:240335) triggered by 154.159.237.212 (212-237-159-154.r.airtelkenya.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 02:28:49.258443 2026] [security2:error] [pid 18862:tid 18862] [client 154.159.237.212:6681] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.159.237.212 (+1 hits since last alert)|michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "michelehoop.com"] [uri "/xmlrpc.php"] [unique_id "aovkobDFMYkI8vZC_eGDZQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-24 06:27:54
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack