๐ซ๐ฎ
gnom4ik
2026-02-21 20:32:20
(4 months ago)
ban-reviewer auto report; ip=216.250.113.234; scenario=http:scan; verdict=valid_ban; confidence=0.85 ...
show more
ban-reviewer auto report; ip=216.250.113.234; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,18; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for 'http:scan' scenario; AbuseIPDB category 14 (Port Scan) is applicable; Decision made within a short time window indicating immediate threat; IP has no active decisions in lookback window, suggesting new threat
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
[email protected]
2026-02-12 00:06:16
(5 months ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-02-12T00:06:15Z
Brute-Force
Anonymous
2026-02-01 06:20:34
(5 months ago)
SMTP AUTH 216.250.113.234 (SMTP_LOGIN_ATTEMPT)
Brute-Force
๐ฉ๐ช
LRob
2026-01-31 14:36:14
(5 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-01-24 04:01:09
(5 months ago)
216.250.113.234 - - [24/Jan/2026:05:01:09 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows ...
show more
216.250.113.234 - - [24/Jan/2026:05:01:09 +0100] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/65.0.3325.146 Safari/537.36"
Brute-force password attempt
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
R.G.
2026-01-19 12:06:21
(6 months ago)
(XMLRPCorWHATEVER) Get lost please 216.250.113.234 (US/United States/infong-us-sd0018.perfora.net): ...
show more
(XMLRPCorWHATEVER) Get lost please 216.250.113.234 (US/United States/infong-us-sd0018.perfora.net): 3 in the last 900 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
myagent.site
2026-01-18 12:35:20
(6 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ฉ๐ช
big-cloud.nl
2026-01-13 20:31:14
(6 months ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
etu brutus
2026-01-13 17:13:17
(6 months ago)
216.250.113.234 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
myagent.site
2026-01-13 16:25:55
(6 months ago)
Blocking for trying to access an exploit file: /xmlrpc.php
Hacking
๐ฌ๐ง
poundawebsiteltd
2026-01-13 14:16:40
(6 months ago)
Apache 403 Forbidden Access. Evidence: [REDACTED_DOMAIN]:443 216.250.113.234 - - [13/Jan/2026:14:16: ...
show more
Apache 403 Forbidden Access. Evidence: [REDACTED_DOMAIN]:443 216.250.113.234 - - [13/Jan/2026:14:16:39 +0000] POST /wp-login.php HTTP/2.0 403 64 https://[REDACTED_DOMAIN]/wp-login.php Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.3; WOW64; Trident/7.0)
show less
Web App Attack
๐ฉ๐ช
ardexter
2026-01-11 09:55:23
(6 months ago)
Wordpress attack and DDOS
DDoS Attack
Web App Attack
๐ฉ๐ช
hchristo
2026-01-11 09:43:52
(6 months ago)
[Sun Jan 11 10:42:16.447675 2026] [access_compat:error] [pid 32460:tid 32532] [remote 216.250.113.23 ...
show more
[Sun Jan 11 10:42:16.447675 2026] [access_compat:error] [pid 32460:tid 32532] [remote 216.250.113.234:58860] AH01797: client denied by server configuration: /var/www/kd1129/htdocs/mg-ambulante-pflege.de/www.mg-ambulante-pflege.de/xmlrpc.php
[Sun Jan 11 10:42:39.985411 2026] [access_compat:error] [pid 32460:tid 32541] [remote 216.250.113.234:58868] AH01797: client denied by server configuration: /var/www/kd1129/htdocs/mg-ambulante-pflege.de/www.mg-ambulante-pflege.de/xmlrpc.php
[Sun Jan 11 10:42:58.998585 2026] [access_compat:error] [pid 32460:tid 32605] [remote 216.250.113.234:58876] AH01797: client denied by server configuration: /var/www/kd1129/htdocs/mg-ambulante-pflege.de/www.mg-ambulante-pflege.de/xmlrpc.php
[Sun Jan 11 10:43:29.766705 2026] [access_compat:error] [pid 32460:tid 32622] [remote 216.250.113.234:58882] AH01797: client denied by server configuration: /var/www/kd1129/htdocs/mg-ambulante-pflege.de/www.mg-ambulante-pflege.de/xmlrpc.php
[Sun Jan 11 10:43:51.677447 2026] [a
...
show less
Brute-Force
๐บ๐ธ
octageeks.com
2025-12-31 05:06:38
(6 months ago)
Wordpress malicious attack:[octaxmlrpc]
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-12 04:12:05
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 216.250.113.234 (infong-us-sd0018.perfora.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 216.250.113.234 (infong-us-sd0018.perfora.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 11 23:11:59.588188 2025] [security2:error] [pid 30856:tid 30856] [client 216.250.113.234:46876] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||the-it-man.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "the-it-man.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aTuWD02I_BIyDxltwvosKgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack