๐ซ๐ท
applemooz
2026-08-21 13:55:41
(8 hours ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 11:54:13
(10 hours ago)
(mod_security) mod_security (id:240335) triggered by 41.223.117.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.223.117.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 07:54:06.642680 2026] [security2:error] [pid 14776:tid 14776] [client 41.223.117.40:14651] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.223.117.40 (+1 hits since last alert)|thebrotherhoodlounge.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "thebrotherhoodlounge.com"] [uri "/xmlrpc.php"] [unique_id "aog8XvihgsjceSVv9_8rewAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-08-21 10:55:08
(11 hours ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-08-20 22:31:16
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
ZM/Zambia/-
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 21:34:35
(1 day ago)
(mod_security) mod_security (id:240335) triggered by 41.223.117.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 41.223.117.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 17:34:28.194148 2026] [security2:error] [pid 18524:tid 18524] [client 41.223.117.40:54047] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5965"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 41.223.117.40 (+1 hits since last alert)|christineaholtz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "christineaholtz.com"] [uri "/xmlrpc.php"] [unique_id "aody5CpPR-u_d6JqQZIIyQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Teufel100
2026-08-20 21:04:12
(1 day ago)
Brutforceangriff auf /xmlrpc.php
Brute-Force
Hacking
Web App Attack
๐ฎ๐น
A000Z
2026-08-20 01:20:26
(1 day ago)
Fail2Ban: 41.223.117.40 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5. ...
show more
Fail2Ban: 41.223.117.40 was banned for Aggressive Bad Bot detected by Nginx/Fail2Ban. UA: Mozilla/5.0 (Linux; Android 5.0; SM-G900P Build/LRX21T) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.1714.1119 Mobile Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
kosada.com
2026-07-03 10:07:37
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-05-04 09:28:09
(3 months ago)
Unauthorized connection attempt on Port 2323
Port Scan
Hacking
Exploited Host
Anonymous
2026-04-13 16:15:18
(4 months ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
๐จ๐ฟ
lp
2026-03-27 23:50:52
(4 months ago)
Email account brute force: 2 attempts were recorded from 41.223.117.40
2026-03-27T23:57:50+01:00 war ...
show more
Email account brute force: 2 attempts were recorded from 41.223.117.40
2026-03-27T23:57:50+01:00 warning: unknown[41.223.117.40]: SASL PLAIN authentication failed: authentication failure, [email protected]
2026-03-27T23:57:50+01:00 warning: unknown[41.223.117.40]: SASL LOGIN authentication failed: authentication failure, [email protected]
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-12-26 09:55:43
(7 months ago)
(mod_security) mod_security (id:210350) triggered by 41.223.117.40 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 41.223.117.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Dec 26 04:55:24.781302 2025] [security2:error] [pid 1123:tid 1123] [client 41.223.117.40:34974] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||spittingimageprint.kathrynmcbride.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "spittingimageprint.kathrynmcbride.com"] [uri "/"] [unique_id "aU5bjABAUe_qbi1oJO25_gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 14:52:11
(8 months ago)
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized ac ...
show more
"Participant in large-scale DDoS Attack in which data injection was attmpted to gain unauthorized access"
show less
DDoS Attack
SQL Injection
Exploited Host
๐ธ๐ช
Johan Finn
2025-09-30 11:41:53
(10 months ago)
malicious activity, botnet
Web App Attack
Anonymous
2025-09-12 20:02:30
(11 months ago)
Web attack
Bad Web Bot
Web App Attack