Anonymous
2026-08-26 11:50:45
(18 hours ago)
denied traffic to a honeypot network. destination port 23.
Port Scan
Hacking
๐บ๐ธ
HamSammich
2026-08-26 08:05:12
(22 hours ago)
Automated sensor: 1 SSH connection/probe attempts over the last 24h (latest 2026-08-26T08:05Z).
Brute-Force
SSH
Anonymous
2026-08-24 23:58:08
(2 days ago)
denied SSH access attempt. destination port 22.
Port Scan
Brute-Force
SSH
๐บ๐ธ
kosada.com
2026-08-24 01:32:27
(3 days ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ฎ๐ฉ
bps-statistics
2026-08-18 11:57:42
(1 week ago)
Malicious Access
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-13 06:44:02
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 45.198.148.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.198.148.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 02:43:57.672215 2026] [security2:error] [pid 15872:tid 15872] [client 45.198.148.5:57535] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.198.148.5 (+1 hits since last alert)|latentpixel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "latentpixel.com"] [uri "/xmlrpc.php"] [unique_id "an1nrVaUrFyQhILyWyCxwgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-13 05:31:33
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 45.198.148.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.198.148.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 13 01:31:28.917121 2026] [security2:error] [pid 1451443:tid 1451460] [client 45.198.148.5:8612] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.198.148.5 (+1 hits since last alert)|coasterdvdsonline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "coasterdvdsonline.com"] [uri "/xmlrpc.php"] [unique_id "an1WsN3-q4wwpsuokawoWAAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
CDiehl
2026-08-12 00:45:44
(2 weeks ago)
Aug 12 02:45:32 centrum sshd-session[3888]: Connection closed by 45.198.148.5 port 58248 [preauth]
A ...
show more
Aug 12 02:45:32 centrum sshd-session[3888]: Connection closed by 45.198.148.5 port 58248 [preauth]
Aug 12 02:45:43 centrum sshd-session[3895]: Connection closed by 45.198.148.5 port 64563 [preauth]
...
show less
Brute-Force
SSH
๐ฉ๐ช
FeG Deutschland
2026-08-07 09:14:07
(2 weeks ago)
Mail: - login with unknown user - bruteforce
Brute-Force
๐ฎ๐น
VHosting
2026-08-07 09:10:03
(2 weeks ago)
Detected mail brute force attack from 4 different servers
Brute-Force
๐บ๐ธ
kosada.com
2026-07-27 03:18:51
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2026-07-15 14:10:01
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
Anonymous
2026-07-05 05:57:29
(1 month ago)
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to ...
show more
Distributed web crawl botnet attack (like Mellowtel), likely illicit scraping of AI training data to bypass firewall/robots.txt restrictions in printer-friendly.asp
show less
Exploited Host
Bad Web Bot
๐บ๐ธ
kosada.com
2026-07-05 05:18:39
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-04 14:07:57
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 45.198.148.5 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240335) triggered by 45.198.148.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 10:07:52.628150 2026] [security2:error] [pid 8241:tid 8241] [client 45.198.148.5:34463] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 45.198.148.5 (+1 hits since last alert)|tenmenband.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "tenmenband.com"] [uri "/xmlrpc.php"] [unique_id "akkTuLBjGrPswIhuHvlYjQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack