๐บ๐ธ
gui-ying233
2026-09-05 09:44:17
(2 weeks ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/142.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
kosada.com
2026-08-30 02:19:10
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
lcvblotter
2026-08-25 20:38:00
(3 weeks ago)
40+ attempts in 5 min to brute force xmlrpc.php.
User agent: WordPress Jetpack
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
dmallet
2026-08-19 21:36:03
(1 month ago)
UDP flood (DDoS) vs AS215599: 721 pkts / 1.03 MB to UDP 8443 across 139 dst IP(s), 2026-08-19 21:46 ...
show more
UDP flood (DDoS) vs AS215599: 721 pkts / 1.03 MB to UDP 8443 across 139 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
DDoS Attack
Exploited Host
๐ซ๐ท
Zkillu
2026-08-19 21:36:03
(1 month ago)
UDP flood (DDoS) vs AS215599: 721 pkts / 1.03 MB to UDP 8443 across 139 dst IP(s), 2026-08-19 21:46 ...
show more
UDP flood (DDoS) vs AS215599: 721 pkts / 1.03 MB to UDP 8443 across 139 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
DDoS Attack
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-08-18 10:44:37
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 06:44:32.838605 2026] [security2:error] [pid 26382:tid 26382] [client 36.50.148.83:58366] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.83 (+1 hits since last alert)|bonesband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "bonesband.com"] [uri "/xmlrpc.php"] [unique_id "aoQ3kKLdwonRNZ9D5RGlMgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-18 09:12:12
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ซ๐ท
dynamix
2026-08-14 05:52:49
(1 month ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 10:06:45
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 06:06:40.820464 2026] [security2:error] [pid 2268236:tid 2268236] [client 36.50.148.83:52422] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.83 (+1 hits since last alert)|kdgsf.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kdgsf.xyz"] [uri "/xmlrpc.php"] [unique_id "anr0MPJW-UPrxE73KRSNVAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-08-07 06:05:07
(1 month ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ฎ๐น
IRT@Unisi
2026-08-03 05:11:39
(1 month ago)
Multiple web server 400 error codes from same source ip.
Bad Web Bot
๐ฉ๐ช
dbmwebdesign
2026-07-24 04:40:03
(1 month ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-14 06:33:17
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 02:33:09.621349 2026] [security2:error] [pid 14010:tid 14047] [client 36.50.148.83:59560] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.83 (+1 hits since last alert)|tnccivic.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tnccivic.org"] [uri "/xmlrpc.php"] [unique_id "alXYJXU7gNqIe9SJzc2RjAAAAkc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 09:38:49
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 36.50.148.83 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 36.50.148.83 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 05:38:41.221612 2026] [security2:error] [pid 8330:tid 8345] [client 36.50.148.83:60113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 36.50.148.83 (+1 hits since last alert)|daraluz.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "daraluz.net"] [uri "/xmlrpc.php"] [unique_id "alSyIT_vKp2NLItdby0pQQAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-07-13 05:27:53
(2 months ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot