Anonymous
2026-08-24 15:06:16
(4 hours ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 10:31:42
(9 hours ago)
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 06:31:36.222813 2026] [security2:error] [pid 5220:tid 5230] [client 158.181.41.252:2154] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 158.181.41.252 (+1 hits since last alert)|fastestcopyright.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fastestcopyright.com"] [uri "/xmlrpc.php"] [unique_id "aowdiHLaYPkCjAoJU6V2MgAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 07:27:10
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:27:06.777840 2026] [security2:error] [pid 22336:tid 22336] [client 158.181.41.252:2169] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 158.181.41.252 (+1 hits since last alert)|orcastrong.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "orcastrong.com"] [uri "/xmlrpc.php"] [unique_id "aovyStPsoHYxU0FhabhpIAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 06:55:10
(13 hours ago)
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 02:55:03.840205 2026] [security2:error] [pid 26100:tid 26100] [client 158.181.41.252:10567] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 158.181.41.252 (+1 hits since last alert)|laecovillage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "laecovillage.org"] [uri "/xmlrpc.php"] [unique_id "aovqxw0O5bd7K7YGvfS4dAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 05:20:41
(14 hours ago)
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 01:20:33.241246 2026] [security2:error] [pid 25756:tid 25776] [client 158.181.41.252:1575] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 158.181.41.252 (+1 hits since last alert)|tnccivic.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tnccivic.org"] [uri "/xmlrpc.php"] [unique_id "aovUoTv5CLKG7xOqdePYmQAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 04:12:42
(15 hours ago)
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 00:12:35.265848 2026] [security2:error] [pid 22301:tid 22301] [client 158.181.41.252:7637] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 158.181.41.252 (+1 hits since last alert)|gpusa-ca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gpusa-ca.com"] [uri "/xmlrpc.php"] [unique_id "aovEs9vrnKHA25h5fqRuqgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-08-23 17:12:31
(1 day ago)
(wordpress) Failed wordpress login from 158.181.41.252 (AZ/Azerbaijan/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-23 16:43:44
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 158.181.41.252 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 12:43:38.917912 2026] [security2:error] [pid 21528:tid 21528] [client 158.181.41.252:3021] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 158.181.41.252 (+1 hits since last alert)|thereisaplaceonearth.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thereisaplaceonearth.com"] [uri "/xmlrpc.php"] [unique_id "aosjOk9w8zWFQ817hL3PbQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-23 15:43:44
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ท
dynamix
2026-08-23 14:56:06
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ฎ
YF
2026-08-23 13:00:33
(1 day ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
Anonymous
2026-08-23 12:06:04
(1 day ago)
Trying to access config files
Web App Attack
Anonymous
2026-08-04 04:10:38
(2 weeks ago)
unsolicited UDP packet to port 58833 (520 bytes)
Hacking
๐ซ๐ท
Petre 21_ip
2026-08-03 16:58:08
(3 weeks ago)
2026-08-03T18:58:08.070582+02:00 vmi2775508 kernel: [UFW BLOCK] IN=eth0 OUT= MAC=00:50:56:5c:a7:cf:c ...
show more
2026-08-03T18:58:08.070582+02:00 vmi2775508 kernel: [UFW BLOCK] IN=eth0 OUT= MAC=00:50:56:5c:a7:cf:c0:69:11:b3:85:db:08:00 SRC=158.181.41.252 DST=155.133.26.57 LEN=1004 TOS=0x00 PREC=0x00 TTL=52 ID=26780 DF PROTO=UDP SPT=9755 DPT=59195 LEN=984
...
show less
Port Scan
Anonymous
2026-08-03 11:51:54
(3 weeks ago)
denied traffic to a honeypot network. destination port 36240.
Port Scan
Hacking