🇩🇪
rh24
2026-09-11 06:36:36
(1 day ago)
(wordpress) Failed wordpress login from 202.66.180.34 (PK/Pakistan/-): (CF_ENABLE)
Brute-Force
🇧🇪
madeit
2026-09-11 05:34:07
(1 day ago)
Web App Attack
🇺🇸
gui-ying233
2026-08-30 15:09:35
(1 week ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
show less
Bad Web Bot
🇩🇪
konseptit
2026-08-28 13:16:02
(2 weeks ago)
(wordpress) Failed wordpress login from 202.66.180.34 (PK/Pakistan/-)
Brute-Force
🇳🇱
ConsulHosting
2026-08-28 12:35:33
(2 weeks ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
gui-ying233
2026-08-27 16:00:00
(2 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Bad Web Bot
🇮🇹
CoreTech srl
2026-08-15 11:53:57
(4 weeks ago)
cloudlinux2 fail2ban: 2026-08-15 13:48:55,671 fail2ban.filter [1695]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-15 13:48:55,671 fail2ban.filter [1695]: INFO [plesk-modsecurity] Found 124.123.166.246 - 2026-08-15 13:48:55cloudlinux2 fail2ban: 2026-08-15 13:49:09,149 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 216.24.219.163 - 2026-08-15 13:49:07cloudlinux2 fail2ban: 2026-08-15 13:49:04,794 fail2ban.filter [1695]: INFO [plesk-modsecurity] Found 202.66.180.34 - 2026-08-15 13:49:04cloudlinux2 fail2ban: 2026-08-15 13:49:06,406 fail2ban.filter [1695]: INFO [plesk-modsecurity] Found 124.123.166.246 - 2026-08-15 13:49:06cloudlinux2 fail2ban: 2026-08-15 13:50:18,619 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 193.36.224.164 - 2026-08-15 13:50:18cloudlinux2 fail2ban: 2026-08-15 13:50:18,980 fail2ban.filter [1695]: INFO [plesk-wordpress] Found 193.36.224.183 - 2026-08-15 13:50:18cloudlinux2 fail2ban: 2026-08-15 13:50:20,425 fail2ban.filter [1695]: INFO [recidive] Found 124.123.166.246 - 2026-08-15 13:50:20c
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-15 11:48:56
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 202.66.180.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.66.180.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 15 07:48:52.126480 2026] [security2:error] [pid 16703:tid 16703] [client 202.66.180.34:45168] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.66.180.34 (+1 hits since last alert)|epetsure.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "epetsure.co"] [uri "/xmlrpc.php"] [unique_id "aoBSJMhEBJyg8iKMR7XbogAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-08-15 08:28:58
(4 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
IN/India/-
Web App Attack
🇺🇸
TPI-Abuse
2026-08-14 13:11:27
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 202.66.180.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.66.180.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 09:11:22.655097 2026] [security2:error] [pid 31306:tid 31306] [client 202.66.180.34:45569] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.66.180.34 (+1 hits since last alert)|gvimmobilier.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "gvimmobilier.com"] [uri "/xmlrpc.php"] [unique_id "an8T-hMeLqgr9Vcj67NFWAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
madeit
2026-08-14 13:00:54
(4 weeks ago)
Web App Attack
🇺🇸
TPI-Abuse
2026-08-13 09:11:12
(4 weeks ago)
(mod_security) mod_security (id:240335) triggered by 202.66.180.34 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 202.66.180.34 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 05:11:05.860777 2026] [security2:error] [pid 1713838:tid 1713838] [client 202.66.180.34:45087] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 202.66.180.34 (+1 hits since last alert)|christineaholtz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "christineaholtz.com"] [uri "/xmlrpc.php"] [unique_id "an2KKXHD9uPpasVV8BNuXAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
maxxsense
2026-08-13 06:59:15
(4 weeks ago)
(wordpress) Failed wordpress login from 202.66.180.34 (PK/Pakistan/-)
Brute-Force
🇩🇪
LRob
2026-08-06 10:25:51
(1 month ago)
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_forma ...
show more
CrowdSec: Distributed L7 HTTP flood on WordPress 'The Events Calendar' AJAX endpoints (request_format~json) - DDoS | req: /calendrier-2/action~agenda/page_offset~1/time_limit~1763506800/cat_ids~194/tag_ids~536,538,482,340,242,638/request_format~json/ | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/100.0.4896.75 Safari/537.36
show less
DDoS Attack
Web App Attack
🇺🇸
kosada.com
2026-06-29 13:05:54
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot