π©πͺ
Vegascosmetics
2026-06-26 17:01:22
(2 days ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
π±π»
garmtech.com
2026-06-25 17:28:47
(3 days ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-23 17:06:49
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 197.231.178.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 197.231.178.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 23 13:06:43.033775 2026] [security2:error] [pid 961:tid 961] [client 197.231.178.56:54486] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.231.178.56 (+1 hits since last alert)|midway-island.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "midway-island.com"] [uri "/xmlrpc.php"] [unique_id "ajq9Iyguevxr6batr1AU6wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-21 15:37:23
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 197.231.178.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 197.231.178.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 11:37:17.355038 2026] [security2:error] [pid 2153:tid 2153] [client 197.231.178.56:49919] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.231.178.56 (+1 hits since last alert)|lusineweb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lusineweb.com"] [uri "/xmlrpc.php"] [unique_id "ajgFLZ4LLB-8lIzVmkfsdAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-06-21 15:31:07
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-21 14:01:43
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 197.231.178.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 197.231.178.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 10:01:37.050800 2026] [security2:error] [pid 29414:tid 29449] [client 197.231.178.56:65012] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.231.178.56 (+1 hits since last alert)|campingcosmetics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "campingcosmetics.com"] [uri "/xmlrpc.php"] [unique_id "ajfuwebfUo8hdcyekBSmjAAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-19 15:31:23
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 197.231.178.56 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 197.231.178.56 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 11:31:18.580407 2026] [security2:error] [pid 18311:tid 18311] [client 197.231.178.56:52291] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 197.231.178.56 (+1 hits since last alert)|faithlines.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "faithlines.com"] [uri "/xmlrpc.php"] [unique_id "ajVgxl-cyPeOakrsIyFS0QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
pltcldvlpr
2026-06-09 00:19:39
(2 weeks ago)
Bogus Useragent: 197.231.178.56 - - [09/Jun/2026:02:19:38 +0200] "GET /protocol?id=rp_14_98&offset=1 ...
show more
Bogus Useragent: 197.231.178.56 - - [09/Jun/2026:02:19:38 +0200] "GET /protocol?id=rp_14_98&offset=1400&seq=1459 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; MSIE 8.0; Windows NT 6.2; Trident/5.0)" asn=37305 org="Frontier Optical Networks Ltd" country=KE
...
show less
Bad Web Bot
Anonymous
2026-06-01 10:30:22
(3 weeks ago)
Attac
Brute-Force
π©πͺ
Marc
2026-06-01 06:55:01
(3 weeks ago)
197.231.178.56 - - [01/Jun/2026:08:54:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3156 "-" "Jetpack by ...
show more
197.231.178.56 - - [01/Jun/2026:08:54:45 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3156 "-" "Jetpack by WordPress.com (Jetpack 12.1; WordPress 6.4)" 197.231.178.56 - - [01/Jun/2026:08:54:55 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3155 "-" "Jetpack/12.0; WordPress/6.3; http://site33765012.com" 197.231.178.56 - - [01/Jun/2026:08:55:00 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3157 "-" "Jetpack by WordPress.com"
show less
Brute-Force
Web App Attack
π―π΅
aPaJnJ32
2026-04-09 21:31:00
(2 months ago)
Email Spam
Spoofing
Phishing
Anonymous
2026-04-07 15:40:24
(2 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
π¨π
Origon
2026-02-08 13:58:32
(4 months ago)
NOQUEUE - IP: 197.231.178.56 - Feb 8 14:58:32 plesk postfix/smtpd[1710578]: NOQUEUE: reject: RCPT f ...
show more
NOQUEUE - IP: 197.231.178.56 - Feb 8 14:58:32 plesk postfix/smtpd[1710578]: NOQUEUE: reject: RCPT from unknown[197.231.178.56]: 554 5.7.1 Service unavailable; Client host [197.231.178.56] blocked using dnsbl-2.uceprotect.net; Net 197.231.176.0/21 is UCEPROTECT-Level2 listed because 40 impacts are seen from FON, KE/AS37305 there. See: http://www.uceprotect.net/rblcheck.php?ipr=197.231.178.56 / Net 197.231.178.0/24 is UCEPROTECT-Level2 listed because 6 impacts are seen from FON, KE/AS37305 there. See: http://www.uceprotect.net/rblcheck.php?ipr=197.231.178.56; from=<[email protected] > to=<REDACTED@REDACTED> proto=ESMTP helo=<localhost>
show less
Email Spam
π§π·
Michel Araujo
2025-12-10 10:52:09
(6 months ago)
DNS pkts/s > 15.0 k, src_ip: 197.231.178.56, src_port:53
DDoS Attack
Spoofing
Exploited Host
IoT Targeted
Anonymous
2025-11-24 17:45:52
(7 months ago)
scanning http requests from known botnet
Web App Attack