๐บ๐ธ
wineposzach
2026-07-29 07:36:37
(2 hours ago)
Distributed web scraper targeting /store/filtered/ on www.bouharouns.com. Residential proxy โ IP+tim ...
show more
Distributed web scraper targeting /store/filtered/ on www.bouharouns.com. Residential proxy โ IP+timestamp provided for ISP DHCP log attribution.
show less
Bad Web Bot
Anonymous
2026-07-29 07:00:00
(3 hours ago)
Automated Apache web application probing in selected 24h window; attempts=187, unique_paths=1, error ...
show more
Automated Apache web application probing in selected 24h window; attempts=187, unique_paths=1, error_responses=187; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(3 hours ago)
Apache probe; attempts=187; exact paths: /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 10:40:04
(23 hours ago)
(mod_security) mod_security (id:240335) triggered by 212.47.145.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.145.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 06:39:56.548306 2026] [security2:error] [pid 3734717:tid 3735141] [client 212.47.145.6:3682] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.145.6 (+1 hits since last alert)|wedgwoodclub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wedgwoodclub.com"] [uri "/xmlrpc.php"] [unique_id "amiG_LUn5fx7dlY8RTVhJgAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 09:33:17
(1 day ago)
(wordpress) Failed wordpress login from 212.47.145.6 (AZ/Azerbaijan/-)
Brute-Force
Anonymous
2026-07-28 08:10:07
(1 day ago)
IP banned by Fail2Ban in jail wordpress
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-28 05:59:51
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 212.47.145.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.145.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 01:59:46.495630 2026] [security2:error] [pid 8563:tid 8563] [client 212.47.145.6:7614] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.145.6 (+1 hits since last alert)|avvmarchetticollini.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "avvmarchetticollini.it"] [uri "/xmlrpc.php"] [unique_id "amhFUpI5KohIsOcAHd7NLgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-07-28 05:57:56
(1 day ago)
Wordpress Vunerability attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 05:29:26
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 212.47.145.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.145.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 01:29:18.581676 2026] [security2:error] [pid 383665:tid 383665] [client 212.47.145.6:7160] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.145.6 (+1 hits since last alert)|ucommsi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ucommsi.com"] [uri "/xmlrpc.php"] [unique_id "amg-LvuuQp3Fi8mh6IqVxwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-07-28 05:26:34
(1 day ago)
CrowdSec: lrob/wp-xmlrpc-bf | req: /xmlrpc.php | UA: Jetpack by WordPress.com
Brute-Force
Web App Attack
๐บ๐ธ
kosada.com
2026-07-06 19:02:14
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฉ๐ช
Vegascosmetics
2026-07-05 12:17:07
(3 weeks ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
๐ฉ๐ช
Oakley
2026-05-20 18:05:38
(2 months ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-13 11:17:36
(4 months ago)
(mod_security) mod_security (id:218580) triggered by 212.47.145.6 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:218580) triggered by 212.47.145.6 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 07:17:32.598756 2026] [security2:error] [pid 14991:tid 14994] [client 212.47.145.6:7987] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:\\\\/\\\\*[!+](?:[\\\\w\\\\s=_\\\\-()]+)?\\\\*\\\\/)" at ARGS:g. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/22_SQL_SQLi.conf"] [line "76"] [id "218580"] [rev "1"] [msg "COMODO WAF: MySQL in-line comment detected.||uoexpanse.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "SQLi"] [hostname "uoexpanse.com"] [uri "/forums/memberlist.php"] [unique_id "abPyTGA0kBV-pX3rhUXJhwAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 14:52:11
(7 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host