๐บ๐ธ
TPI-Abuse
2025-08-11 22:36:05
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 212.30.37.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.30.37.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 11 18:36:01.069961 2025] [security2:error] [pid 12585:tid 12585] [client 212.30.37.58:36309] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "capitalinvestingguides.com"] [uri "/sftp-config.json"] [unique_id "aJpwUQqLkwrF06oUFVpHlwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-08 05:51:31
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 212.30.37.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 212.30.37.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 08 01:51:27.659692 2025] [security2:error] [pid 15787:tid 15787] [client 212.30.37.58:44945] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/sftp-config.json" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gcigmbh.com"] [uri "/back/sftp-config.json"] [unique_id "aJWQX5JLd53T3AAS-vMkzwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2025-08-02 04:19:49
(10 months ago)
5.673 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
Anonymous
2025-07-30 16:32:54
(10 months ago)
(PERMBLOCK) 212.30.37.58 (NL/The Netherlands/-) has had more than 4 temp blocks
Hacking
Anonymous
2025-07-30 15:19:23
(10 months ago)
(wordpress) Failed wordpress login from 212.30.37.58 (NL/The Netherlands/-)
Brute-Force
๐ง๐ช
cmbplf
2025-07-30 03:21:12
(10 months ago)
4.000 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
Anonymous
2025-07-29 13:18:51
(10 months ago)
Failed Wordpress Logins
Web App Attack
๐ง๐ช
cmbplf
2025-07-24 23:24:38
(10 months ago)
5.950 requests with url.path */xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-20 02:22:29
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 212.30.37.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 212.30.37.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 19 22:22:22.072577 2025] [security2:error] [pid 19863:tid 19863] [client 212.30.37.58:35067] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wendeenicole.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wendeenicole.com"] [uri "/bak/dump.sql"] [unique_id "aHxS3r-_xOQKQHcdw2n4DgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-19 19:16:51
(10 months ago)
(PERMBLOCK) 212.30.37.58 (NL/The Netherlands/South Holland/Rotterdam/-/[redacted]) has had more than ...
show more
(PERMBLOCK) 212.30.37.58 (NL/The Netherlands/South Holland/Rotterdam/-/[redacted]) has had more than 4 temp blocks
show less
Hacking
Anonymous
2025-07-19 17:43:59
(10 months ago)
(wordpress) Failed wordpress login from 212.30.37.58 (NL/The Netherlands/South Holland/Rotterdam/-/[ ...
show more
(wordpress) Failed wordpress login from 212.30.37.58 (NL/The Netherlands/South Holland/Rotterdam/-/[redacted])
show less
Brute-Force
Anonymous
2025-07-19 00:01:56
(10 months ago)
[redacted] 212.30.37.58 - - [19/Jul/2025:02:01:08 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "M ...
show more
[redacted] 212.30.37.58 - - [19/Jul/2025:02:01:08 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 212.30.37.58 - - [19/Jul/2025:02:01:12 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 212.30.37.58 - - [19/Jul/2025:02:01:19 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 212.30.37.58 - - [19/Jul/2025:02:01:21 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 212.30.37.58 - - [19/Jul/2025:02:01:26 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0
...
show less
Hacking
Web App Attack
Anonymous
2025-07-18 03:36:23
(10 months ago)
[redacted] 212.30.37.58 - - [18/Jul/2025:05:35:36 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "M ...
show more
[redacted] 212.30.37.58 - - [18/Jul/2025:05:35:36 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 212.30.37.58 - - [18/Jul/2025:05:35:38 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
chillytrippydippy.com 212.30.37.58 - - [18/Jul/2025:05:35:42 +0200] "POST //xmlrpc.php HTTP/1.1" 200 446 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
chillytrippydippy.com 212.30.37.58 - - [18/Jul/2025:05:35:47 +0200] "POST //xmlrpc.php HTTP/1.1" 200 446 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 212.30.37.58 - - [18/Jul/2025:05:35:49 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-
...
show less
Hacking
Web App Attack
๐ฎ๐น
VHosting
2025-07-15 12:32:07
(10 months ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-13 03:59:48
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 212.30.37.58 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 212.30.37.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 12 23:59:40.163695 2025] [security2:error] [pid 12429:tid 12429] [client 212.30.37.58:44513] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cayman-islands-real-estate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cayman-islands-real-estate.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aHMvLNPfI49FSJtHoy20uAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack