Anonymous
2026-06-07 22:06:04
(1 hour ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 19:47:42
(3 hours ago)
(mod_security) mod_security (id:240335) triggered by 37.40.228.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 37.40.228.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 15:47:35.207027 2026] [security2:error] [pid 25518:tid 25518] [client 37.40.228.52:45958] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.40.228.52 (+1 hits since last alert)|iplayriichi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iplayriichi.com"] [uri "/xmlrpc.php"] [unique_id "aiXK1wxnRNBAugJyiCiysgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-07 19:12:40
(4 hours ago)
Attac
Brute-Force
๐ฆ๐บ
screwlooseit.com.au
2026-06-07 16:49:30
(6 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
OM/Oman/-
Web App Attack
๐ต๐ฑ
sefinek.net
2026-06-04 11:03:48
(3 days ago)
Triggered Cloudflare WAF (firewallCustom) from OM.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (G ...
show more
Triggered Cloudflare WAF (firewallCustom) from OM.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: /blocklist-generator/noip | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.128 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-06-03 18:08:04
(4 days ago)
[redacted] 37.40.228.52 - - [03/Jun/2026:20:07:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Je ...
show more
[redacted] 37.40.228.52 - - [03/Jun/2026:20:07:11 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.4)"
[redacted] 37.40.228.52 - - [03/Jun/2026:20:07:30 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack by WordPress.com"
[redacted] 37.40.228.52 - - [03/Jun/2026:20:07:40 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "Jetpack/12.1; WordPress/6.4; http://site32937126.com"
[redacted] 37.40.228.52 - - [03/Jun/2026:20:07:54 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
[redacted] 37.40.228.52 - - [03/Jun/2026:20:08:01 +0200] "POST /xmlrpc.php HTTP/1.1" 405 428 "-" "WordPress.com; https://wordpress.com"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 20:54:57
(5 days ago)
(mod_security) mod_security (id:240335) triggered by 37.40.228.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 37.40.228.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 16:54:52.761614 2026] [security2:error] [pid 8404:tid 8404] [client 37.40.228.52:45853] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.40.228.52 (+1 hits since last alert)|usaangelinvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "usaangelinvestors.com"] [uri "/xmlrpc.php"] [unique_id "ah9DHPtBkngS0jwTlz1n7QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 14:44:14
(5 days ago)
Attac
Brute-Force
๐ซ๐ท
masterguru
2026-06-01 13:26:48
(6 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 37.40.228.52 (OM/Oman/-): 10 in the last 3600 secs (0-201 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 37.40.228.52 (OM/Oman/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-31 17:00:58
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 37.40.228.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 37.40.228.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 13:00:51.899869 2026] [security2:error] [pid 28452:tid 28452] [client 37.40.228.52:45457] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.40.228.52 (+1 hits since last alert)|jaragoodrich.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "jaragoodrich.com"] [uri "/xmlrpc.php"] [unique_id "ahxpQ4-2uylrkIiym4bE_AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 21:17:19
(1 week ago)
(mod_security) mod_security (id:217210) triggered by 37.40.228.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 37.40.228.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 17:17:13.456294 2026] [security2:error] [pid 6443:tid 6443] [client 37.40.228.52:53008] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||usa61twos.shop|F|4"] [data "GET http://usa61twos.shop HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "usa61twos.shop"] [uri "/"] [unique_id "ahtT2bPDpkh1OfW-CEjqMQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
exxos
2025-08-28 16:03:01
(9 months ago)
http-no-verb
Hacking
๐ณ๐ฑ
exxos
2025-08-28 15:03:01
(9 months ago)
http-no-verb
Hacking
๐ช๐ธ
Global Cyber Police
2025-07-28 07:43:21
(10 months ago)
Malicious bot activity detected: Hitting honeypot page. Part of massive botnet.
DDoS Attack
Hacking
SQL Injection
Spoofing
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
www.elivecd.org
2025-07-04 12:42:01
(11 months ago)
37.40.228.52 - - [04/Jul/2025:13:42:00 +0100] "GET http://www.elivecd.org/newsletters/?reflect_4_day ...
show more
37.40.228.52 - - [04/Jul/2025:13:42:00 +0100] "GET http://www.elivecd.org/newsletters/?reflect_4_day=false&reflect_4_month=false&reflect_4_start=0&reflect_4_year=2007&reflect_956_day=false&reflect_956_month=3&reflect_956_start=0&reflect_956_year=2009 HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36"
...
show less
DDoS Attack