🇺🇸
kosada.com
2026-08-26 09:18:53
(3 days ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-24 19:27:07
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 15:27:01.218546 2026] [security2:error] [pid 11892:tid 11892] [client 27.125.240.226:35997] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.125.240.226 (+1 hits since last alert)|thenolangroup.llc|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thenolangroup.llc"] [uri "/xmlrpc.php"] [unique_id "aoybBRFVS0y_i0gFTvl6SgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 15:45:54
(5 days ago)
Large-scale coordinated botnet (2M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/S ...
show more
Large-scale coordinated botnet (2M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]); Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]) employed by Angara Technologies Group | Attack Signature Blocked: /catalog/product_compare/add/product/10964/uenc/aHR0cHM6Ly93d3cuZDJvZmZpY2UucnUvY2F0YWxvZ3NlYXJjaC9yZXN1bHQvP2NhdD0zMysmYW1wO3Byb2plY3Rvcl9jbGFzcz04NSZhbXA7cT1uZWMrbnA0MDM,/form_key/IhuTM88qhGcxrpVp/ | UA: Mozilla/5.0 (compatible; MSIE 5.0; Windows CE; Trident/5.0) | (Magento Site)
show less
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 21:32:18
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 17:32:14.276947 2026] [security2:error] [pid 2091:tid 2091] [client 27.125.240.226:45230] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.125.240.226 (+1 hits since last alert)|grancanariaholidays.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "grancanariaholidays.com"] [uri "/xmlrpc.php"] [unique_id "aotm3qxdOpVuflXFRzhTBAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 19:59:15
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 15:59:09.058500 2026] [security2:error] [pid 25518:tid 25518] [client 27.125.240.226:2433] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.125.240.226 (+1 hits since last alert)|visionremota.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "visionremota.info"] [uri "/xmlrpc.php"] [unique_id "aotRDV2NSx0n-Yypy7_NiQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WeekendWeb
2026-08-23 15:24:43
(6 days ago)
Wordpress Vunerability attack
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 11:39:35
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:39:27.237613 2026] [security2:error] [pid 15149:tid 15149] [client 27.125.240.226:53408] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.125.240.226 (+1 hits since last alert)|kmindonesia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kmindonesia.com"] [uri "/xmlrpc.php"] [unique_id "aorb7_P8uN8-_0kwZUNSFwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
integrantservices.com
2026-08-23 09:14:21
(6 days ago)
(wordpress) Failed wordpress login from 27.125.240.226 (MY/Malaysia/-)
Brute-Force
🇮🇹
CoreTech srl
2026-08-23 06:33:57
(6 days ago)
cloudlinux2 fail2ban: 2026-08-23 08:29:19,296 fail2ban.actions [1496]: NOTICE [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-23 08:29:19,296 fail2ban.actions [1496]: NOTICE [plesk-wordpress] Unban 134.209.220.184cloudlinux2 fail2ban: 2026-08-23 08:29:49,015 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 27.125.240.226 - 2026-08-23 08:29:48cloudlinux2 fail2ban: 2026-08-23 08:30:12,654 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 170.64.159.153 - 2026-08-23 08:30:11cloudlinux2 fail2ban: 2026-08-23 08:30:11,166 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 91.236.136.50 - 2026-08-23 08:30:10cloudlinux2 fail2ban: 2026-08-23 08:30:21,088 fail2ban.actions [1496]: NOTICE [plesk-modsecurity] Ban 27.125.240.226cloudlinux2 fail2ban: 2026-08-23 08:30:20,862 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 27.125.240.226 - 2026-08-23 08:30:20cloudlinux2 fail2ban: 2026-08-23 08:30:22,302 fail2ban.actions [1496]: NOTICE [plesk-modsecurity] Unban 27.125.240.197cloudlinux2 fail2ban: 2026-08-23 08:30:21,094 fail2ban.filter
show less
Web App Attack
🇺🇸
cwytech
2026-08-23 06:16:49
(6 days ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-23 05:35:27
(6 days ago)
WordPress login brute-force | path: /xmlrpc.php
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 04:51:14
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 00:51:09.623066 2026] [security2:error] [pid 3581:tid 3581] [client 27.125.240.226:5346] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.125.240.226 (+1 hits since last alert)|diamondtrailerserv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "diamondtrailerserv.com"] [uri "/xmlrpc.php"] [unique_id "aop8Pa4oxX7wQ4EaD3sYIwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 00:17:52
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 20:17:44.418383 2026] [security2:error] [pid 8775:tid 8775] [client 27.125.240.226:12767] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.125.240.226 (+1 hits since last alert)|indoorsfinishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "indoorsfinishing.com"] [uri "/xmlrpc.php"] [unique_id "aoo8KMIweprgURo_huxVVgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 15:31:33
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 27.125.240.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 11:31:26.469725 2026] [security2:error] [pid 22758:tid 22764] [client 27.125.240.226:23083] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 27.125.240.226 (+1 hits since last alert)|darkestmoonart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "darkestmoonart.com"] [uri "/xmlrpc.php"] [unique_id "aonAzuCUicNFigKX63ZtXgAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-07-24 15:51:34
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot