๐ฎ๐ฉ
sockominfo
2026-07-21 09:00:53
(1 week ago)
Zimbra: Login failures from malicious IP: 13.40.11.3. Threat Score: 6.2/10 (MEDIUM). Confidence: 40% ...
show more
Zimbra: Login failures from malicious IP: 13.40.11.3. Threat Score: 6.2/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 76%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-07-21 08:00:53
(1 week ago)
Zimbra: Login failures from malicious IP: 13.40.11.3. Threat Score: 6.4/10 (MEDIUM). Confidence: 40% ...
show more
Zimbra: Login failures from malicious IP: 13.40.11.3. Threat Score: 6.4/10 (MEDIUM). Confidence: 40%. CVSS v3.1: 4.6/10 (Medium). CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L. Bayesian Probability: 76%. MITRE ATT&CK: T1083 (File and Directory Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-19 18:33:56
(1 week ago)
cloudlinux2 fail2ban: 2026-07-19 20:29:11,177 fail2ban.filter [1918]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-19 20:29:11,177 fail2ban.filter [1918]: INFO [plesk-wordpress] Found 104.234.53.94 - 2026-07-19 20:29:10cloudlinux2 fail2ban: 2026-07-19 20:29:31,090 fail2ban.filter [1918]: INFO [plesk-modsecurity] Found 13.40.11.3 - 2026-07-19 20:29:31cloudlinux2 fail2ban: 2026-07-19 20:29:29,461 fail2ban.actions [1918]: NOTICE [plesk-modsecurity] Unban 20.9.15.100cloudlinux2 fail2ban: 2026-07-19 20:29:38,694 fail2ban.filter [1918]: INFO [plesk-wordpress] Found 173.239.240.100 - 2026-07-19 20:29:38cloudlinux2 fail2ban: 2026-07-19 20:29:50,470 fail2ban.filter [1918]: INFO [plesk-wordpress] Found 203.161.62.87 - 2026-07-19 20:29:49cloudlinux2 fail2ban: 2026-07-19 20:30:47,567 fail2ban.actions [1918]: NOTICE [plesk-modsecurity] Unban 116.90.103.83cloudlinux2 fail2ban: 2026-07-19 20:30:56,119 fail2ban.filter [1918]: INFO [plesk-wordpress] Found 130.51.180.8 - 2026-07-19 20:30:55cloudlinux2 fail2ban: 2026-07-19 20:31:08,024 fail2
show less
Web App Attack
๐บ๐ธ
derekgallardo01
2026-07-16 19:16:18
(1 week ago)
Auto-reported by Worker: AiTM toolkit UA fingerprint CRITICAL: auto-add to BadIPS Named Location + r ...
show more
Auto-reported by Worker: AiTM toolkit UA fingerprint CRITICAL: auto-add to BadIPS Named Location + report to AbuseIPDB.. Detection: AiTM toolkit UA fingerprint (Tycoon/EvilProxy portal-browser). Blocked at Conditional Access gate.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-11 17:08:08
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 13.40.11.3 (ec2-13-40-11-3.eu-west-2.compute.am ...
show more
(mod_security) mod_security (id:240335) triggered by 13.40.11.3 (ec2-13-40-11-3.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 13:08:05.247622 2026] [security2:error] [pid 12920:tid 12920] [client 13.40.11.3:46581] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 13.40.11.3 (+1 hits since last alert)|troop9weymouth.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "troop9weymouth.com"] [uri "/xmlrpc.php"] [unique_id "alJ4dVhO6yrFi3Rcv5sNYQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-10 18:24:23
(2 weeks ago)
(mod_security) mod_security (id:240335) triggered by 13.40.11.3 (ec2-13-40-11-3.eu-west-2.compute.am ...
show more
(mod_security) mod_security (id:240335) triggered by 13.40.11.3 (ec2-13-40-11-3.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 10 14:24:18.041981 2026] [security2:error] [pid 22569:tid 22649] [client 13.40.11.3:17780] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 13.40.11.3 (+1 hits since last alert)|ccgparquitectos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "ccgparquitectos.com"] [uri "/xmlrpc.php"] [unique_id "alE40oZzSVMWDX5DvDv4oQAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-07-10 18:21:25
(2 weeks ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฌ๐ง
contactcrm
2026-07-10 09:09:17
(2 weeks ago)
Form Spam : Form Spam
Web Spam
Anonymous
2026-07-08 17:38:14
(2 weeks ago)
[osotir.org] httpd-xmlrpc-post: sites=www.synathlountes.agonistes.gr; logs=/var/log/httpd/domains/ag ...
show more
[osotir.org] httpd-xmlrpc-post: sites=www.synathlountes.agonistes.gr; logs=/var/log/httpd/domains/agonistes.gr.synathlountes.log; samples=/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-07 11:49:36
(3 weeks ago)
(mod_security) mod_security (id:240335) triggered by 13.40.11.3 (ec2-13-40-11-3.eu-west-2.compute.am ...
show more
(mod_security) mod_security (id:240335) triggered by 13.40.11.3 (ec2-13-40-11-3.eu-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 07 07:49:31.552828 2026] [security2:error] [pid 23001:tid 23001] [client 13.40.11.3:58241] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 13.40.11.3 (+1 hits since last alert)|milliondollarbelt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "milliondollarbelt.com"] [uri "/xmlrpc.php"] [unique_id "akznyztr9q4oWVZuBxq5NgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-07-03 05:11:57
(3 weeks ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/ec2-13-40-11-3.eu-west-2.compute.amazonaw ...
show more
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/ec2-13-40-11-3.eu-west-2.compute.amazonaws.com
show less
Web App Attack
๐ซ๐ท
bazter.pro
2026-06-25 19:42:37
(1 month ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-25 19:18:48
(1 month ago)
IM360 WAF: Rate limit exceeded for XMLRPC DoS
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-25 18:44:17
(1 month ago)
(wordpress) Failed wordpress login from 13.40.11.3 (GB/United Kingdom/ec2-13-40-11-3.eu-west-2.compu ...
show more
(wordpress) Failed wordpress login from 13.40.11.3 (GB/United Kingdom/ec2-13-40-11-3.eu-west-2.compute.amazonaws.com)
show less
Brute-Force
๐ฉ๐ช
EGP Abuse Dept
2026-06-16 02:45:18
(1 month ago)
Scanning for web/db/file exploits on brederaad-010.nl
SQL Injection
Bad Web Bot
Web App Attack