๐บ๐ธ
n2nguyenn2nguyen
2026-08-01 16:09:57
(4 hours ago)
Blocked by YFC Security on https://parcl9.com โ type: xmlrpc_attempts
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 13:43:40
(6 hours ago)
(mod_security) mod_security (id:240335) triggered by 37.61.118.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 37.61.118.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 09:43:36.015461 2026] [security2:error] [pid 2040247:tid 2040247] [client 37.61.118.17:2546] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.61.118.17 (+1 hits since last alert)|cassialifesci.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "cassialifesci.com"] [uri "/xmlrpc.php"] [unique_id "am34CCuRdamYGvUHHcpavQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-01 12:36:09
(7 hours ago)
(wordpress) Failed wordpress login from 37.61.118.17 (AZ/Azerbaijan/Baku City/Baku/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-01 08:00:24
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 37.61.118.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 37.61.118.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 04:00:16.546343 2026] [security2:error] [pid 1975944:tid 1975944] [client 37.61.118.17:2520] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.61.118.17 (+1 hits since last alert)|brianwhitty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "brianwhitty.com"] [uri "/xmlrpc.php"] [unique_id "am2nkPQUEvbpCah8BoXf8QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 07:33:41
(12 hours ago)
(mod_security) mod_security (id:240335) triggered by 37.61.118.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 37.61.118.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 03:33:37.908614 2026] [security2:error] [pid 1563631:tid 1563631] [client 37.61.118.17:6857] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.61.118.17 (+1 hits since last alert)|kimbrothersduluth.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kimbrothersduluth.com"] [uri "/xmlrpc.php"] [unique_id "am2hUUly8Z82lz7O3YMbLAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-01 05:48:56
(14 hours ago)
cloudlinux2 fail2ban: 2026-08-01 07:44:37,138 fail2ban.filter [1838]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-01 07:44:37,138 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 39.59.40.203 - 2026-08-01 07:44:36cloudlinux2 fail2ban: 2026-08-01 07:44:44,979 fail2ban.filter [1838]: INFO [plesk-wordpress] Found 45.131.193.42 - 2026-08-01 07:44:44cloudlinux2 fail2ban: 2026-08-01 07:45:08,004 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 37.61.118.17 - 2026-08-01 07:45:07cloudlinux2 fail2ban: 2026-08-01 07:45:29,307 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 37.61.118.17 - 2026-08-01 07:45:29cloudlinux2 fail2ban: 2026-08-01 07:45:29,480 fail2ban.filter [1838]: INFO [recidive] Found 37.61.118.17 - 2026-08-01 07:45:29cloudlinux2 fail2ban: 2026-08-01 07:45:29,472 fail2ban.actions [1838]: NOTICE [plesk-modsecurity] Ban 37.61.118.17cloudlinux2 fail2ban: 2026-08-01 07:45:54,773 fail2ban.filter [1838]: INFO [plesk-modsecurity] Found 49.36.33.48 - 2026-08-01 07:45:54cloudlinux2 fail2ban: 2026-08-01 07:46:
show less
Web App Attack
๐บ๐ธ
integrantservices.com
2026-08-01 03:57:55
(16 hours ago)
(wordpress) Failed wordpress login from 37.61.118.17 (AZ/Azerbaijan/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-31 19:16:16
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 37.61.118.17 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 37.61.118.17 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 15:16:09.767025 2026] [security2:error] [pid 3735878:tid 3735878] [client 37.61.118.17:12213] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 37.61.118.17 (+1 hits since last alert)|velvetculture.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "velvetculture.com"] [uri "/xmlrpc.php"] [unique_id "amz0eUyFtj2CJJ6758jtKAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-31 19:07:04
(1 day ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
soverin
2026-06-05 15:08:44
(1 month ago)
spam
Email Spam
๐ซ๐ท
security.rdmc.fr
2026-05-22 18:23:35
(2 months ago)
Port Scan Attack proto:TCP src:8368 dst:23
Port Scan
Anonymous
2025-11-18 07:28:28
(8 months ago)
scanning http requests from known botnet
Web App Attack
Anonymous
2025-10-09 17:34:17
(9 months ago)
DDoS botnet 510.000+ IPs; URL with bing/trustpilot/githubhelp and %C2%A4 or \xc2\xa4. NEW 09/2025: a ...
show more
DDoS botnet 510.000+ IPs; URL with bing/trustpilot/githubhelp and %C2%A4 or \xc2\xa4. NEW 09/2025: amplification attacks via third-parties e.g. HTTP_USER_AGENT facebookexternalhit/meta-externalagent/meta-externalfetcher or IPs from googleusercontent.com with fake HTTP_REFERER foxnews.com/newsweek.com/upwork.com/activision.com/... Port 443.
show less
DDoS Attack
Bad Web Bot
Web App Attack
Anonymous
2025-08-29 05:07:31
(11 months ago)
wordpress-trap
Web App Attack
๐ณ๐ฑ
exxos
2025-08-27 12:03:01
(11 months ago)
404 rapid attacks with bad user agents
DDoS Attack