๐บ๐ธ
TPI-Abuse
2026-08-24 02:24:10
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 188.240.58.62 (62.58.240.188.baremetal.zare.com ...
show more
(mod_security) mod_security (id:240335) triggered by 188.240.58.62 (62.58.240.188.baremetal.zare.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 22:24:04.003161 2026] [security2:error] [pid 878:tid 878] [client 188.240.58.62:36608] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 188.240.58.62 (+1 hits since last alert)|paulsingdahlsen.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "paulsingdahlsen.com"] [uri "/xmlrpc.php"] [unique_id "aourQxTWuFb2IyYuMvY3PgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 13:53:52
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 188.240.58.62 (62.58.240.188.baremetal.zare.com ...
show more
(mod_security) mod_security (id:240335) triggered by 188.240.58.62 (62.58.240.188.baremetal.zare.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 09:53:45.147225 2026] [security2:error] [pid 6884:tid 6884] [client 188.240.58.62:41948] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 188.240.58.62 (+1 hits since last alert)|hotpay.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hotpay.co"] [uri "/xmlrpc.php"] [unique_id "aor7aYkLC2bgUKOIHSYBHgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 16:29:46
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 188.240.58.62 (62.58.240.188.baremetal.zare.com ...
show more
(mod_security) mod_security (id:240335) triggered by 188.240.58.62 (62.58.240.188.baremetal.zare.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 12:29:42.132243 2026] [security2:error] [pid 20346:tid 20346] [client 188.240.58.62:51830] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 188.240.58.62 (+1 hits since last alert)|renomarsh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "renomarsh.com"] [uri "/xmlrpc.php"] [unique_id "aoh89u6vBoQ5NUgr3vXUzwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
ljo
2026-08-21 16:27:37
(1 week ago)
188.240.58.62 - - [21/Aug/2026:18:26:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5335 "-" "Jetpack/12. ...
show more
188.240.58.62 - - [21/Aug/2026:18:26:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5335 "-" "Jetpack/12.0; WordPress/6.1; http://site33658358.com"
188.240.58.62 - - [21/Aug/2026:18:26:11 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5335 "-" "WordPress.com; https://wordpress.com"
188.240.58.62 - - [21/Aug/2026:18:26:22 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5335 "-" "Jetpack by WordPress.com"
188.240.58.62 - - [21/Aug/2026:18:26:33 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5335 "-" "Jetpack/12.0; WordPress/6.3; http://site36496348.com"
188.240.58.62 - - [21/Aug/2026:18:26:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5335 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
188.240.58.62 - - [21/Aug/2026:18:26:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5335 "-" "Jetpack/12.1; WordPress/6.4; http://site32756180.com"
188.240.58.62 - - [21/Aug/2026:18:27:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 5335 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.4)"
188.240.58.62 - - [21/Aug/2026:18:27:15
...
show less
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-20 04:03:06
(1 week ago)
[20/Aug/2026:00:02:23.868082 --0400] aoZ8T1sDgXrVGIHIs7q2sgAAAUw 188.240.58.62 37142 127.0.0.1 7081
...
show more
[20/Aug/2026:00:02:23.868082 --0400] aoZ8T1sDgXrVGIHIs7q2sgAAAUw 188.240.58.62 37142 127.0.0.1 7081
[20/Aug/2026:00:02:34.384947 --0400] aoZ8WlsDgXrVGIHIs7q3FAAAAVE 188.240.58.62 37236 127.0.0.1 7081
[20/Aug/2026:00:02:44.947248 --0400] aoZ8ZEIHN8BgxLZsKP5CfQAAAQc 188.240.58.62 52390 127.0.0.1 7081
[20/Aug/2026:00:02:55.565557 --0400] aoZ8b1sDgXrVGIHIs7q3WAAAAUc 188.240.58.62 41736 127.0.0.1 7081
[20/Aug/2026:00:03:06.180648 --0400] aoZ8erfLpVqitS5OoVi03QAAAgc 188.240.58.62 56584 127.0.0.1 7081
...
show less
DDoS Attack
Brute-Force
๐จ๐ฆ
Anytech
2026-08-20 04:01:41
(1 week ago)
Blocked by ConnMonitor
Web App Attack
๐ซ๐ท
applemooz
2026-08-19 23:39:12
(1 week ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐น๐ท
Doruk
2026-08-16 16:40:02
(2 weeks ago)
Unauthorized connection attempt
Brute-Force
๐จ๐ญ
backslash
2026-07-07 17:03:00
(1 month ago)
block ruleset 1E8A9918B1655D0828F2EEF05553DD2681055C9A
Web Spam
๐ฑ๐ป
garmtech.com
2026-06-26 21:22:33
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-22.188.240.58.62.web-spamme ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 00-22.188.240.58.62.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ฌ๐ง
Oakley
2026-06-13 18:23:39
(2 months ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐ฆ๐บ
MAGIC
2026-06-03 01:17:41
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2026-06-01 01:46:28
(3 months ago)
Failed Wordpress Logins
Web App Attack
๐ฉ๐ช
Oakley
2026-05-23 03:05:28
(3 months ago)
(confirmed_bot_sig) Confirmed bot
Hacking
Anonymous
2026-05-21 08:46:29
(3 months ago)
Failed Wordpress Logins
Web App Attack