Anonymous
2026-09-24 20:00:48
(3 days ago)
Large-scale coordinated botnet (6M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/S ...
show more
Large-scale coordinated botnet (6M+ IPs). Ordered by Alexander Pen'kov (alexander-pen-kov-7b41aa6a/Shursky [yordim|LIS|MOW]): Retaliation after theft; Attacker: Mikhail Smirnov (mikhail-smirnov-79830323/Aidan [MOW]): Employed by Angara Technologies Group | Offpeak: Sessionless Catalog Access Blocked: /brands/shopby/manufacturer-gefen-rcf-lsi-evoko-acer-inspur-xyz.html | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/106.0.5249.119 Safari/537.36 | (Magento Site)
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-16 18:46:54
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 39.34.171.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.171.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 14:46:49.416221 2026] [security2:error] [pid 20356:tid 20356] [client 39.34.171.78:49372] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.171.78 (+1 hits since last alert)|hotpay.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "hotpay.co"] [uri "/xmlrpc.php"] [unique_id "alknGeymTr25AQVFxeOB2gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-07-16 18:25:26
(2 months ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-07-16 17:52:58
(2 months ago)
(xmlrpc) Failed xmlrpc access from 39.34.171.78 (PK/Pakistan/-): 5 in the last 3600 secs (0-122)
Hacking
๐ซ๐ท
Yepngo
2026-07-16 17:49:27
(2 months ago)
39.34.171.78 - - [16/Jul/2026:19:49:17 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "Jetpack by Wo ...
show more
39.34.171.78 - - [16/Jul/2026:19:49:17 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "Jetpack by WordPress.com (Jetpack 12.0; WordPress 6.1)"
39.34.171.78 - - [16/Jul/2026:19:49:27 +0200] "POST /xmlrpc.php HTTP/2.0" 200 410 "-" "Jetpack by WordPress.com"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 17:11:53
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 39.34.171.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.171.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 13:11:46.298784 2026] [security2:error] [pid 16669:tid 16669] [client 39.34.171.78:49036] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.171.78 (+1 hits since last alert)|lawrencehale.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "lawrencehale.net"] [uri "/xmlrpc.php"] [unique_id "alkQ0pwkoopovUxiDmJLZAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 15:27:21
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 39.34.171.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.171.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 11:27:14.332448 2026] [security2:error] [pid 15835:tid 15835] [client 39.34.171.78:49818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.171.78 (+1 hits since last alert)|pcga.golf|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pcga.golf"] [uri "/xmlrpc.php"] [unique_id "alj4Ujfrtwe8Ll8sbnBxWgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-16 14:18:57
(2 months ago)
cloudlinux2 fail2ban: 2026-07-16 16:14:27,080 fail2ban.filter [1812]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-16 16:14:27,080 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 173.239.213.11 - 2026-07-16 16:14:24cloudlinux2 fail2ban: 2026-07-16 16:14:27,030 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 173.239.213.14 - 2026-07-16 16:14:24cloudlinux2 fail2ban: 2026-07-16 16:15:37,698 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 193.37.33.27 - 2026-07-16 16:15:37cloudlinux2 fail2ban: 2026-07-16 16:16:40,125 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 45.131.195.149 - 2026-07-16 16:16:40cloudlinux2 fail2ban: 2026-07-16 16:17:32,829 fail2ban.filter [1812]: INFO [plesk-modsecurity] Found 39.34.171.78 - 2026-07-16 16:17:32cloudlinux2 fail2ban: 2026-07-16 16:17:50,506 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 173.239.214.216 - 2026-07-16 16:17:48cloudlinux2 fail2ban: 2026-07-16 16:17:49,586 fail2ban.filter [1812]: INFO [plesk-wordpress] Found 173.239.214.216 - 2026-07-16 16:17:48cl
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-16 14:05:30
(2 months ago)
(mod_security) mod_security (id:240335) triggered by 39.34.171.78 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 39.34.171.78 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 10:05:24.536857 2026] [security2:error] [pid 4725:tid 4797] [client 39.34.171.78:49833] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 39.34.171.78 (+1 hits since last alert)|woofnrose.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "woofnrose.com"] [uri "/xmlrpc.php"] [unique_id "aljlJE88d2F18UD12SNZswAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack