Anonymous
2026-07-29 03:36:56
(22 hours ago)
denied traffic to a honeypot network. destination port 23748.
Port Scan
Hacking
๐บ๐ธ
kosada.com
2026-06-29 13:21:01
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฉ๐ช
Vegascosmetics
2026-06-27 14:35:51
(1 month ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after obfuscated redirect. Vegas Security
DDoS Attack
Hacking
Exploited Host
Anonymous
2026-05-17 10:42:05
(2 months ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ณ๐ฑ
debestelapp
2026-05-17 08:10:07
(2 months ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 03:39:32
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 212.47.148.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.148.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 23:39:28.901054 2026] [security2:error] [pid 10480:tid 10480] [client 212.47.148.143:3572] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.148.143 (+1 hits since last alert)|technesa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "technesa.com"] [uri "/xmlrpc.php"] [unique_id "agk4cGG6dWE5SMooTXhDDwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 17:36:43
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 212.47.148.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.148.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 13:36:36.124018 2026] [security2:error] [pid 3659:tid 3659] [client 212.47.148.143:2241] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.148.143 (+1 hits since last alert)|goodfrequencies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "goodfrequencies.com"] [uri "/xmlrpc.php"] [unique_id "agirJCTWC9-6MP-Gl-KnBQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-05-16 15:52:18
(2 months ago)
(wordpress) Failed wordpress login from 212.47.148.143 (AZ/Azerbaijan/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-05-16 14:53:50
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 212.47.148.143 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.148.143 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 10:53:44.441576 2026] [security2:error] [pid 13600:tid 13623] [client 212.47.148.143:11365] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.148.143 (+1 hits since last alert)|grupojdg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "grupojdg.com"] [uri "/xmlrpc.php"] [unique_id "agiE-B5cBPdjiLpmwRbqLAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-16 13:50:41
(2 months ago)
Attac
Brute-Force
๐ธ๐ฌ
mypatricks
2026-03-21 07:06:41
(4 months ago)
212.47.148.143 | Port: 12072 | DNS: 212.47.148.143 2026-03-21T15:06:40+08:00 Asia/Baku | IPs Spam li ...
show more
212.47.148.143 | Port: 12072 | DNS: 212.47.148.143 2026-03-21T15:06:40+08:00 Asia/Baku | IPs Spam list | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/135.0.0.0 Safari/537.36 Edg/135.0.0.0 HTTP/1.1 443 GET | URL: /tracking/?634d8b94aa1a667070347fbdc7ae8871=1773032452 | Ref: https://xxxxxx/hashtag/goofy/?2802f093b02ddd8befe5c0c011f302a3=GBP&code=GBP | Country: AZ/Azerbaijan/+04:00 IP City: Ganja Windows 9dfb1d7e0c3bff9c-GYD/Baku, Azerbaijan 1 hits/0 secs Robots 2
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐ฉ๐ฐ
TransAdvice-Abuse
2025-12-26 13:09:09
(7 months ago)
IRC SPAM/Flood
DDoS Attack
Anonymous
2025-11-26 07:21:00
(8 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2025-11-17 05:26:35
(8 months ago)
scanning http requests from known botnet
Web App Attack
๐ฟ๐ฆ
maximonline.co.za
2023-06-15 22:30:01
(3 years ago)
Brute Force IMAP AUTH Attack
Brute-Force