๐จ๐ญ
Mario Bretscher
2026-07-20 16:45:36
(2 days ago)
Jul 20 18:45:25 beat-band.ch Cerber(beat-band.ch)[947600]: Authentication failure for beat-band from ...
show more
Jul 20 18:45:25 beat-band.ch Cerber(beat-band.ch)[947600]: Authentication failure for beat-band from 43.231.208.80
Jul 20 18:45:35 beat-band.ch Cerber(beat-band.ch)[949115]: Authentication failure for beat-band from 43.231.208.80
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-07-20 14:52:19
(2 days ago)
(mod_security) mod_security (id:240335) triggered by 43.231.208.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.231.208.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 10:52:06.807604 2026] [security2:error] [pid 23534:tid 23534] [client 43.231.208.80:16953] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.231.208.80 (+1 hits since last alert)|kdgsf.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "kdgsf.xyz"] [uri "/xmlrpc.php"] [unique_id "al42FgWV_LghICM0HqjmYgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-20 12:54:05
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ฎ
YF
2026-07-20 02:30:32
(3 days ago)
xmlrpc.php Potential DDoS or brute force
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-19 11:40:50
(3 days ago)
(mod_security) mod_security (id:240335) triggered by 43.231.208.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.231.208.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 07:40:43.760542 2026] [security2:error] [pid 5685:tid 5735] [client 43.231.208.80:51113] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.231.208.80 (+1 hits since last alert)|pref-realestate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "pref-realestate.com"] [uri "/xmlrpc.php"] [unique_id "aly3uxEQa4JOjTpA73LZZgAAAE4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 06:34:46
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 43.231.208.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.231.208.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 02:34:36.315412 2026] [security2:error] [pid 26418:tid 26418] [client 43.231.208.80:34080] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.231.208.80 (+1 hits since last alert)|americanacademyofteachersofsinging.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "americanacademyofteachersofsinging.org"] [uri "/xmlrpc.php"] [unique_id "alxv_MsGfvmuNM64Ic2k6AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 01:43:35
(4 days ago)
(mod_security) mod_security (id:240335) triggered by 43.231.208.80 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 43.231.208.80 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 18 21:43:21.919281 2026] [security2:error] [pid 32027:tid 32027] [client 43.231.208.80:53576] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 43.231.208.80 (+1 hits since last alert)|barecreationsaz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "barecreationsaz.com"] [uri "/xmlrpc.php"] [unique_id "alwruYwHYDzzBZLta45e_AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-18 10:56:05
(4 days ago)
xmlrpc request blocked, no referer. Pattern match "xmlrpc.php" at REQUEST_URI. (88010-201)
Hacking
๐บ๐ธ
cwytech
2026-07-18 10:13:41
(4 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Paul Smith
2025-10-08 12:41:35
(9 months ago)
Email Auth Brute force attack 1/1 in last day
Brute-Force
๐ซ๐ท
dynamix
2025-10-08 11:16:47
(9 months ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
exxos
2025-10-02 19:03:01
(9 months ago)
Attacks with Bad user agents
Hacking