๐ฉ๐ช
dbmwebdesign
2026-08-24 16:10:17
(6 hours ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-08-24 16:08:41
(6 hours ago)
(xmlrpc) Apache: Failed xmlrpc access from 154.74.158.12 (TZ/Tanzania/-): 10 in the last 3600 secs ( ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 154.74.158.12 (TZ/Tanzania/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-24 13:55:44
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 154.74.158.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.74.158.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:55:36.607717 2026] [security2:error] [pid 9542:tid 9542] [client 154.74.158.12:27619] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.74.158.12 (+1 hits since last alert)|dvdmasters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dvdmasters.com"] [uri "/xmlrpc.php"] [unique_id "aoxNWA1p--spygOhhTg37QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 13:25:17
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 154.74.158.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.74.158.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 09:25:12.732108 2026] [security2:error] [pid 6262:tid 6262] [client 154.74.158.12:47483] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.74.158.12 (+1 hits since last alert)|writebetweenthelines.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "writebetweenthelines.com"] [uri "/xmlrpc.php"] [unique_id "aoxGOImBTZ8vbXvAeHdjGwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-08-22 17:32:29
(2 days ago)
(wordpress) Failed wordpress login from 154.74.158.12 (TZ/Tanzania/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
cwytech
2026-08-22 17:25:43
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-07 09:51:18
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-07 08:59:32
(2 weeks ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.co ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf_xmlrpc | req: /xmlrpc.php | UA: Jetpack by WordPress.com
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 06:31:17
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 154.74.158.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.74.158.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 02:31:08.587528 2026] [security2:error] [pid 2060755:tid 2060764] [client 154.74.158.12:35323] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.74.158.12 (+1 hits since last alert)|vancekelly.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vancekelly.com"] [uri "/xmlrpc.php"] [unique_id "anV7rOWYuPKMkBMbscp-_gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
powerhostingdk
2026-08-06 09:10:09
(2 weeks ago)
[mailserver] CrowdSec detected crowdsecurity/postscreen-rbl (1 events). Automated abuse report.
Email Spam
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-26 13:50:29
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 154.74.158.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 154.74.158.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 09:50:22.651640 2026] [security2:error] [pid 597941:tid 597999] [client 154.74.158.12:8521] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 154.74.158.12 (+1 hits since last alert)|woofnrose.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "woofnrose.com"] [uri "/xmlrpc.php"] [unique_id "amYQnqAmunlBEaAXzp7j2QAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-07-26 05:38:27
(4 weeks ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS (fault code)
Web App Attack
๐ซ๐ท
matthieul.dev
2026-07-19 21:50:17
(1 month ago)
Blocked by os-abuseipdb; 9 hits, proto=tcp,udp, ports=50009
Port Scan
Brute-Force
๐ฉ๐ช
kreativstrecke
2026-05-11 21:06:08
(3 months ago)
2026-05-11T23:06:01.368543+02:00 srv02 postfix/smtps/smtpd[2563596]: warning: unknown[154.74.158.12] ...
show more
2026-05-11T23:06:01.368543+02:00 srv02 postfix/smtps/smtpd[2563596]: warning: unknown[154.74.158.12]: SASL PLAIN authentication failed: (reason unavailable), [email protected]
2026-05-11T23:06:07.407358+02:00 srv02 postfix/smtps/smtpd[2563596]: warning: unknown[154.74.158.12]: SASL LOGIN authentication failed: (reason unavailable), [email protected]
2026-05-11T23:06:07.575048+02:00 srv02 postfix/smtps/smtpd[2563596]: lost connection after AUTH from unknown[154.74.158.12]
...
show less
Brute-Force
๐บ๐ธ
bigscoots.com
2026-05-11 18:59:49
(3 months ago)
(smtpauth) Failed SMTP AUTH login from 154.74.158.12 (TZ/Tanzania/-): 5 in the last 3600 secs; Ports ...
show more
(smtpauth) Failed SMTP AUTH login from 154.74.158.12 (TZ/Tanzania/-): 5 in the last 3600 secs; Ports: 25,465,587; Direction: 0; Trigger: LF_SMTPAUTH; Logs: 2026-05-11 14:59:31 dovecot_plain authenticator failed for H=(U289EEWT) [154.74.158.12]:22907: 535 Incorrect authentication data ([email protected] )
2026-05-11 14:59:35 dovecot_plain authenticator failed for H=(B9MP3) [154.74.158.12]:22908: 535 Incorrect authentication data ([email protected] )
2026-05-11 14:59:38 dovecot_login authenticator failed for H=(U289EEWT) [154.74.158.12]:22907: 535 Incorrect authentication data ([email protected] )
2026-05-11 14:59:44 dovecot_plain authenticator failed for H=(R27PCKV70FQ2DWX) [154.74.158.12]:22909: 535 Incorrect authentication data ([email protected] )
2026-05-11 14:59:45 dovecot_login authenticator failed for H=(B9MP3) [154.74.158.12]:22908: 535 Incorrect authentication data
show less
Brute-Force
SSH