π«π·
glmx
2026-08-24 06:43:28
(1 day ago)
SSH honeypot interaction detected. The source host initiated a connection to a monitored SSH endpoin ...
show more
SSH honeypot interaction detected. The source host initiated a connection to a monitored SSH endpoint, behavior consistent with automated SSH scanning or brute-force reconnaissance.
show less
Brute-Force
SSH
Anonymous
2026-08-16 00:32:17
(1 week ago)
denied SSH access attempt. destination port 22.
Port Scan
Brute-Force
SSH
π«π·
applemooz
2026-08-14 06:15:09
(1 week ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
πΊπΈ
kosada.com
2026-06-29 14:25:30
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-16 15:26:47
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 212.47.145.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.145.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 11:26:41.548353 2026] [security2:error] [pid 372:tid 372] [client 212.47.145.218:9999] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.145.218 (+1 hits since last alert)|comobarbershop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "comobarbershop.com"] [uri "/xmlrpc.php"] [unique_id "ajFrMW9UqfjooapJnyRsPwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-16 14:24:50
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 212.47.145.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.145.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 10:24:42.588933 2026] [security2:error] [pid 15405:tid 15405] [client 212.47.145.218:3665] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.145.218 (+1 hits since last alert)|barkatthemoonpetsitting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "barkatthemoonpetsitting.com"] [uri "/xmlrpc.php"] [unique_id "ajFcqjrYpRp_9tCIMFdjUQAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-16 09:06:26
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 212.47.145.218 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.145.218 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 05:06:22.666318 2026] [security2:error] [pid 26658:tid 26658] [client 212.47.145.218:5746] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.145.218 (+1 hits since last alert)|servecon.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "servecon.net"] [uri "/xmlrpc.php"] [unique_id "ajESDoMD3ErEPzhMW5g6swAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
WeekendWeb
2026-06-16 06:48:01
(2 months ago)
Wordpress Vunerability attack
Web App Attack
π¨π
backslash
2026-01-11 15:45:11
(7 months ago)
block ruleset 6B63410D189E6343B910F7440B8499558BEC52EB
Bad Web Bot
Anonymous
2025-12-04 12:26:37
(8 months ago)
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.12.04 is noted in report tim ...
show more
Attempted brute force login to web vpn 1 time(s); last attempt for 2025.12.04 is noted in report timestamp
show less
Hacking
Brute-Force
Anonymous
2025-11-16 05:43:18
(9 months ago)
scanning http requests from known botnet
Web App Attack