๐บ๐ธ
lostswordfish.com
2026-08-28 17:02:03
(17 hours ago)
Wordfence brute block on kcuar
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-25 13:29:30
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 09:29:26.007166 2026] [security2:error] [pid 15918:tid 15918] [client 37.142.150.221:17443] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.142.150.221 (+1 hits since last alert)|mjkhan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mjkhan.com"] [uri "/xmlrpc.php"] [unique_id "ao2YtmahZFAUFE0d5G5I2QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 08:58:58
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 04:58:54.141860 2026] [security2:error] [pid 4788:tid 4788] [client 37.142.150.221:22117] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.142.150.221 (+1 hits since last alert)|rdhtrucking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rdhtrucking.com"] [uri "/xmlrpc.php"] [unique_id "ao1ZTjtVdxP-qHUiIvEuZAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 02:51:28
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 22:51:19.940246 2026] [security2:error] [pid 18682:tid 18682] [client 37.142.150.221:20739] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.142.150.221 (+1 hits since last alert)|the-it-man.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "the-it-man.com"] [uri "/xmlrpc.php"] [unique_id "ao0DJ0zivrK8Y2mOSKwAsgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
abdubhai
2026-08-25 01:08:02
(4 days ago)
37.142.150.221 - - [25/Aug/2026:
...
Brute-Force
๐บ๐ฆ
URAN Publishing Service
2026-08-24 13:55:20
(4 days ago)
[24/Aug/2026:16:55:19 +0300] -- 37.142.150.221 Ban reason: Scanner [CMS_GENERIC] | Request: POST /xm ...
show more
[24/Aug/2026:16:55:19 +0300] -- 37.142.150.221 Ban reason: Scanner [CMS_GENERIC] | Request: POST /xmlrpc.php HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-24 12:48:57
(4 days ago)
cloudlinux2 fail2ban: 2026-08-24 14:43:52,153 fail2ban.actions [1464]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-24 14:43:52,153 fail2ban.actions [1464]: NOTICE [plesk-modsecurity] Unban 38.134.139.66cloudlinux2 fail2ban: 2026-08-24 14:44:09,879 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 37.142.150.221 - 2026-08-24 14:44:09cloudlinux2 fail2ban: 2026-08-24 14:44:10,187 fail2ban.actions [1464]: NOTICE [plesk-modsecurity] Ban 37.142.150.221cloudlinux2 fail2ban: 2026-08-24 14:44:10,194 fail2ban.filter [1464]: INFO [recidive] Found 37.142.150.221 - 2026-08-24 14:44:10cloudlinux2 fail2ban: 2026-08-24 14:44:47,658 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 146.19.140.185 - 2026-08-24 14:44:47cloudlinux2 fail2ban: 2026-08-24 14:46:45,370 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 178.105.137.176 - 2026-08-24 14:46:45cloudlinux2 fail2ban: 2026-08-24 14:46:45,380 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 178.105.137.176 - 2026-08-24 14:46:45cloudlinux2 fail2ban: 2026-08-24 14:46:46,39
show less
Web App Attack
๐บ๐ธ
IndigoRidge
2026-08-24 12:42:49
(4 days ago)
37.142.150.221 - - [24/Aug/2026:08:41:03 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress. ...
show more
37.142.150.221 - - [24/Aug/2026:08:41:03 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
37.142.150.221 - - [24/Aug/2026:08:41:13 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
37.142.150.221 - - [24/Aug/2026:08:42:07 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
37.142.150.221 - - [24/Aug/2026:08:42:17 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
37.142.150.221 - - [24/Aug/2026:08:42:49 -0400] "POST /xmlrpc.php HTTP/1.0" 403 5788 "-" "WordPress.com; https://wordpress.com"
...
show less
Web App Attack
๐บ๐ธ
integrantservices.com
2026-08-24 03:56:06
(5 days ago)
(PERMBLOCK) 37.142.150.221 (IL/Israel/-) has had more than 4 temp blocks
Hacking
๐บ๐ธ
integrantservices.com
2026-08-24 00:26:04
(5 days ago)
(wordpress) Failed wordpress login from 37.142.150.221 (IL/Israel/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-23 17:23:07
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 13:23:03.613702 2026] [security2:error] [pid 5297:tid 5297] [client 37.142.150.221:18160] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.142.150.221 (+1 hits since last alert)|greatchristianadventure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "greatchristianadventure.com"] [uri "/xmlrpc.php"] [unique_id "aossd-fco7tKABtXbR6nvgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 13:47:59
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 09:47:55.178744 2026] [security2:error] [pid 10775:tid 10775] [client 37.142.150.221:17938] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.142.150.221 (+1 hits since last alert)|technesa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "technesa.com"] [uri "/xmlrpc.php"] [unique_id "aor6C_wg6VlTCeuRzMBB_AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 13:03:38
(5 days ago)
Attempt to POST to xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 11:03:48
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 07:03:41.573682 2026] [security2:error] [pid 10832:tid 10832] [client 37.142.150.221:18381] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.142.150.221 (+1 hits since last alert)|dalessalesandservice.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "dalessalesandservice.com"] [uri "/xmlrpc.php"] [unique_id "aorTjRQhYxkizkDJvFoVOAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 22:36:29
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 37.142.150.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 18:36:22.316528 2026] [security2:error] [pid 22620:tid 22620] [client 37.142.150.221:20731] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.142.150.221 (+1 hits since last alert)|sharonmauldin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "sharonmauldin.com"] [uri "/xmlrpc.php"] [unique_id "aookZoHWR6mxKNzIgnPrWwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack