π©πͺ
LRob
2026-08-04 20:38:49
(1 month ago)
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_forma ...
show more
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/time_limit~1763766000/cat_ids~155,156/tag_ids~679,452,645,575,342/request_format~json/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/99.0.4844.51 Safari/537.36
show less
DDoS Attack
Web App Attack
πΊπΈ
kosada.com
2026-07-29 14:19:34
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-07-12 04:43:13
(2 months ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in email-link.asp
show less
Exploited Host
Bad Web Bot
π³π±
Site.eu
2026-06-30 02:13:23
(3 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
π¦πΊ
clapper
2026-06-29 19:28:01
(3 months ago)
(mod_security) mod_security (id:350202) triggered by 186.211.101.182 (BR/Brazil/186-211-101-182.gegn ...
show more
(mod_security) mod_security (id:350202) triggered by 186.211.101.182 (BR/Brazil/186-211-101-182.gegnet.com.br): 5 in the last 600 secs; ID: rub
show less
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-29 15:45:25
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 186.211.101.182 (186-211-101-182.gegnet.com.br) ...
show more
(mod_security) mod_security (id:240335) triggered by 186.211.101.182 (186-211-101-182.gegnet.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 11:45:19.708068 2026] [security2:error] [pid 16475:tid 16475] [client 186.211.101.182:52390] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.211.101.182 (+1 hits since last alert)|broneksuchanek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "broneksuchanek.com"] [uri "/xmlrpc.php"] [unique_id "akKTDyQhxdQ_q9z7xckq_AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-06-29 15:13:29
(3 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
kosada.com
2026-06-29 14:13:29
(3 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
π²πΎ
Rizzy
2026-06-21 02:07:42
(3 months ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-06-20 17:36:11
(3 months ago)
[redacted] 186.211.101.182 - - [20/Jun/2026:19:35:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" ...
show more
[redacted] 186.211.101.182 - - [20/Jun/2026:19:35:29 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.3; http://site38994950.com"
[redacted] 186.211.101.182 - - [20/Jun/2026:19:35:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.4; http://site44923711.com"
[redacted] 186.211.101.182 - - [20/Jun/2026:19:35:50 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 186.211.101.182 - - [20/Jun/2026:19:36:00 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.5; WordPress/6.3; http://site31531541.com"
[redacted] 186.211.101.182 - - [20/Jun/2026:19:36:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.0; WordPress/6.2; http://site69403982.com"
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-14 21:02:27
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 186.211.101.182 (186-211-101-182.gegnet.com.br) ...
show more
(mod_security) mod_security (id:240335) triggered by 186.211.101.182 (186-211-101-182.gegnet.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:02:21.522959 2026] [security2:error] [pid 14964:tid 14964] [client 186.211.101.182:48977] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.211.101.182 (+1 hits since last alert)|riser-astrology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "riser-astrology.com"] [uri "/xmlrpc.php"] [unique_id "ai8W3TKc0RVWWiE6Xx_l0AAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-14 00:01:20
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 186.211.101.182 (186-211-101-182.gegnet.com.br) ...
show more
(mod_security) mod_security (id:240335) triggered by 186.211.101.182 (186-211-101-182.gegnet.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 20:01:13.671217 2026] [security2:error] [pid 30656:tid 30656] [client 186.211.101.182:29402] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 186.211.101.182 (+1 hits since last alert)|mytapt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mytapt.com"] [uri "/xmlrpc.php"] [unique_id "ai3vSXt1OnjutPgE7XB47QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 21:23:43
(3 months ago)
WordPress Brute Force
Brute-Force
π«π·
dynamix
2026-06-13 19:59:34
(3 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
π³π±
Site.eu
2026-06-11 16:07:22
(3 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH