๐บ๐ธ
TPI-Abuse
2026-08-24 18:48:24
(5 hours ago)
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodac ...
show more
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodacom.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 14:48:16.707547 2026] [security2:error] [pid 31373:tid 31373] [client 41.13.212.221:60773] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.13.212.221 (+1 hits since last alert)|iostation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "iostation.com"] [uri "/xmlrpc.php"] [unique_id "aoyR8Gs9v-rWyz4zVBDIsAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-24 16:07:28
(8 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 15:52:30
(8 hours ago)
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodac ...
show more
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodacom.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 11:52:24.667029 2026] [security2:error] [pid 25579:tid 25579] [client 41.13.212.221:50034] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.13.212.221 (+1 hits since last alert)|desdier.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "desdier.com"] [uri "/xmlrpc.php"] [unique_id "aoxouJih84tPD2tPd0Bq9QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-08-23 17:04:16
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 15:31:44
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodac ...
show more
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodacom.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 11:31:37.413487 2026] [security2:error] [pid 30251:tid 30251] [client 41.13.212.221:59063] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.13.212.221 (+1 hits since last alert)|36sovereignchambers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "36sovereignchambers.com"] [uri "/xmlrpc.php"] [unique_id "aosSWTnZ9mxdb4YdyerROAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 14:22:08
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodac ...
show more
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodacom.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:22:02.954661 2026] [security2:error] [pid 31673:tid 31673] [client 41.13.212.221:39925] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.13.212.221 (+1 hits since last alert)|reyadecostarica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "reyadecostarica.com"] [uri "/xmlrpc.php"] [unique_id "aosCCn2CfPL9k4_089C2WwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-22 15:17:27
(2 days ago)
Web App Attack
๐บ๐ธ
integrantservices.com
2026-08-22 14:49:36
(2 days ago)
(wordpress) Failed wordpress login from 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodacom.co.za)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-22 09:03:28
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodac ...
show more
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodacom.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 05:03:16.374585 2026] [security2:error] [pid 9811:tid 9811] [client 41.13.212.221:32656] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.13.212.221 (+1 hits since last alert)|billwegener.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "billwegener.net"] [uri "/xmlrpc.php"] [unique_id "aoll1JsV5ROl8-zLgsrWYAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-19 16:30:00
(5 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 18:32:02
(6 days ago)
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodac ...
show more
(mod_security) mod_security (id:240335) triggered by 41.13.212.221 (vc-gp-n-41-13-212-221.umts.vodacom.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 14:31:57.098313 2026] [security2:error] [pid 4402:tid 4420] [client 41.13.212.221:45925] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.13.212.221 (+1 hits since last alert)|fastesttrademark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "fastesttrademark.com"] [uri "/xmlrpc.php"] [unique_id "aoSlHZrukPnpdrjvma0RrQAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-11-16 07:56:33
(9 months ago)
scanning http requests from known botnet
Web App Attack
๐จ๐ฆ
Justmee
2023-05-08 18:22:25
(3 years ago)
May 8 12:22:23 RT-AX58U-50D8-8E617D2-C kernel: DROP IN=eth4 OUT=br0 MAC=d4:be:d9:99:6f:95:0c:a4:02: ...
show more
May 8 12:22:23 RT-AX58U-50D8-8E617D2-C kernel: DROP IN=eth4 OUT=br0 MAC=d4:be:d9:99:6f:95:0c:a4:02:35:6d:87:08:00 SRC=41.13.212.221 DST=192.168.100.108 LEN=52 TOS=0x00 PREC=0x00 TTL=48 ID=31597 DF PROTO=TCP SPT=8176 DPT=8892 SEQ=1796994761 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (020405460402010101030308) MARK=0x8000000
May 8 12:22:24 RT-AX58U-50D8-8E617D2-C kernel: DROP IN=eth4 OUT=br0 MAC=d4:be:d9:99:6f:95:0c:a4:02:35:6d:87:08:00 SRC=41.13.212.221 DST=192.168.100.108 LEN=52 TOS=0x00 PREC=0x00 TTL=48 ID=31597 DF PROTO=TCP SPT=8176 DPT=8892 SEQ=1796994761 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (020405460402010101030308) MARK=0x8000000
May 8 12:22:24 RT-AX58U-50D8-8E617D2-C kernel: DROP IN=eth4 OUT=br0 MAC=d4:be:d9:99:6f:95:0c:a4:02:35:6d:87:08:00 SRC=41.13.212.221 DST=192.168.100.108 LEN=52 TOS=0x00 PREC=0x00 TTL=48 ID=31598 DF PROTO=TCP SPT=8176 DPT=8892 SEQ=1796994761 ACK=0 WINDOW=65535 RES=0x00 SYN URGP=0 OPT (020405460402010101030308) MARK=0x8000000
...
show less
Hacking
Brute-Force