Anonymous
2026-10-09 20:08:52
(1 day ago)
MikroTik Enterprise Honeypot
Port Scan
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-20 12:01:28
(2 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
้ฌผๅฝฑ233
2026-09-07 18:08:14
(1 month ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 Edg/145.0.0.0
show less
Bad Web Bot
Anonymous
2026-09-03 05:02:08
(1 month ago)
denied SSH access attempt. destination port 22.
Port Scan
Brute-Force
SSH
๐บ๐ธ
kosada.com
2026-08-26 17:34:33
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2026-07-31 23:00:18
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฉ๐ช
bsoft.de
2026-07-25 18:58:35
(2 months ago)
212.47.149.160 - - [25/Jul/2026:20:58:13 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by ...
show more
212.47.149.160 - - [25/Jul/2026:20:58:13 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.1)"
212.47.149.160 - - [25/Jul/2026:20:58:23 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
212.47.149.160 - - [25/Jul/2026:20:58:34 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/13.0; WordPress/6.2; http://site82802123.com"
show less
Web App Attack
๐บ๐ธ
WeekendWeb
2026-07-25 15:55:27
(2 months ago)
Wordpress Vunerability attack
Web App Attack
Anonymous
2026-07-25 15:26:24
(2 months ago)
[web.zebs.ch] httpd-xmlrpc-post: sites=www.swisscybertech.ch; logs=/var/log/httpd/domains/swisscyber ...
show more
[web.zebs.ch] httpd-xmlrpc-post: sites=www.swisscybertech.ch; logs=/var/log/httpd/domains/swisscybertech.ch.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 09:38:52
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 212.47.149.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.149.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 05:38:46.419126 2026] [security2:error] [pid 3567899:tid 3567899] [client 212.47.149.160:5491] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.149.160 (+1 hits since last alert)|solucionesmercadeodigital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "solucionesmercadeodigital.com"] [uri "/xmlrpc.php"] [unique_id "amSEJt0JDHTAWP3RTAcchQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-07-25 09:37:23
(2 months ago)
(wordpress) Failed wordpress login from 212.47.149.160 (AZ/Azerbaijan/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-25 08:39:50
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 212.47.149.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.149.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 04:39:43.160669 2026] [security2:error] [pid 1767985:tid 1767985] [client 212.47.149.160:15025] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.149.160 (+1 hits since last alert)|disio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "disio.com"] [uri "/xmlrpc.php"] [unique_id "amR2T-HbUm2BYhMpO8YzhAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 08:07:22
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 212.47.149.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.149.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 04:07:17.800269 2026] [security2:error] [pid 6785:tid 6785] [client 212.47.149.160:2732] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.149.160 (+1 hits since last alert)|seagrovesrealty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "seagrovesrealty.com"] [uri "/xmlrpc.php"] [unique_id "amRutcB2Yqladlf8KjjYpQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 03:59:42
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 212.47.149.160 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 212.47.149.160 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 23:59:34.242174 2026] [security2:error] [pid 3854987:tid 3854987] [client 212.47.149.160:2753] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 212.47.149.160 (+1 hits since last alert)|aholsniffsglue.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aholsniffsglue.com"] [uri "/xmlrpc.php"] [unique_id "amQ0podWB5OEV1CyxI51hgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
burlacu.org
2026-07-25 03:30:02
(2 months ago)
Nginx multi-log analysis detected: wordpress_scan. Evidence: XMLRPC abuse with 21 requests. Blocked ...
show more
Nginx multi-log analysis detected: wordpress_scan. Evidence: XMLRPC abuse with 21 requests. Blocked automatically.
show less
Web App Attack
Bad Web Bot