๐ฉ๐ช
rh24
2026-07-27 03:32:47
(1 day ago)
(wordpress) Failed wordpress login from 37.61.112.211 (AZ/Azerbaijan/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-27 02:35:22
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 22:35:15.055365 2026] [security2:error] [pid 15011:tid 15021] [client 37.61.112.211:1068] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.61.112.211 (+1 hits since last alert)|vinylnotespodcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "vinylnotespodcast.com"] [uri "/xmlrpc.php"] [unique_id "ambD4znydVQBYPbN8UsNwgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 01:36:20
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 21:36:14.767335 2026] [security2:error] [pid 3252635:tid 3252635] [client 37.61.112.211:1476] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.61.112.211 (+1 hits since last alert)|wsffjatc.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "wsffjatc.org"] [uri "/xmlrpc.php"] [unique_id "ama2DjDuyby4rPnmuRRPcgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-07-27 00:19:31
(1 day ago)
xmlrpc.php attack DOS
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 23:39:18
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 19:39:11.244572 2026] [security2:error] [pid 1567186:tid 1567204] [client 37.61.112.211:7886] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.61.112.211 (+1 hits since last alert)|iancaird.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iancaird.com"] [uri "/xmlrpc.php"] [unique_id "amaan1q15uww7bnLSz7heQAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-07-26 22:33:42
(1 day ago)
Wordpress brute force attempt
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-07-26 21:30:56
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
cwytech
2026-07-26 09:02:44
(1 day ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 08:04:53
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 04:04:49.300444 2026] [security2:error] [pid 2461609:tid 2461609] [client 37.61.112.211:2373] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.61.112.211 (+1 hits since last alert)|apexandroids.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "apexandroids.com"] [uri "/xmlrpc.php"] [unique_id "amW_oYG1ombeGUwCt2QulAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 06:32:26
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 02:32:21.935166 2026] [security2:error] [pid 1926377:tid 1926377] [client 37.61.112.211:2500] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.61.112.211 (+1 hits since last alert)|southernstatespool.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "southernstatespool.com"] [uri "/xmlrpc.php"] [unique_id "amWp9X4PvjbWb51CqwtvrgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-26 06:08:55
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 37.61.112.211 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 26 02:08:48.920238 2026] [security2:error] [pid 3841427:tid 3841536] [client 37.61.112.211:8832] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.61.112.211 (+1 hits since last alert)|kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kettlehill.com"] [uri "/xmlrpc.php"] [unique_id "amWkcOGWS72bHGuzXC2dbgAAAYs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
lp
2026-07-09 19:50:44
(2 weeks ago)
Email account brute force: 1 attempts were recorded from 37.61.112.211
2026-07-09T21:26:59+02:00 war ...
show more
Email account brute force: 1 attempts were recorded from 37.61.112.211
2026-07-09T21:26:59+02:00 warning: unknown[37.61.112.211]: SASL PLAIN authentication failed: authentication failure, [email protected]
show less
Brute-Force
๐ณ๐ฑ
soverin
2026-06-05 15:42:04
(1 month ago)
spam
Email Spam
๐ฌ๐ง
transcom
2026-05-10 09:45:51
(2 months ago)
Spam #2 to magichost.co.uk (trap_type=honeypot_direct, from=magichost.co.uk)
Web Spam
๐ณ๐ด
Fredrik_2015
2026-05-05 05:36:28
(2 months ago)
Tries for open relay
Hacking
Brute-Force