๐ซ๐ท
Kenshin869
2026-08-18 18:14:09
(1 month ago)
Wordpress unauthorized access attempt
Brute-Force
๐ซ๐ท
dwmp
2026-08-18 15:59:16
(1 month ago)
WordPress login Brute-Force
Brute-Force
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-18 15:23:37
(1 month ago)
(wordpress) Failed wordpress login from 156.213.148.55 (EG/Egypt/Cairo Governorate/Cairo/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-18 14:24:26
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 156.213.148.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 156.213.148.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 10:24:19.517144 2026] [security2:error] [pid 11445:tid 11445] [client 156.213.148.55:52926] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.213.148.55 (+1 hits since last alert)|reallifelearninghub.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "reallifelearninghub.com"] [uri "/xmlrpc.php"] [unique_id "aoRrE2xo6V_NJzx6Vb-GIwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-18 14:13:56
(1 month ago)
cloudlinux2 fail2ban: 2026-08-18 16:08:51,917 fail2ban.filter [1456]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-18 16:08:51,917 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 193.36.224.61 - 2026-08-18 16:08:51cloudlinux2 fail2ban: 2026-08-18 16:08:53,038 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 156.213.148.55 - 2026-08-18 16:08:52cloudlinux2 fail2ban: 2026-08-18 16:08:51,923 fail2ban.filter [1456]: INFO [plesk-wordpress] Found 193.36.224.74 - 2026-08-18 16:08:51cloudlinux2 fail2ban: 2026-08-18 16:08:56,430 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 45.41.105.201 - 2026-08-18 16:08:56cloudlinux2 fail2ban: 2026-08-18 16:09:13,544 fail2ban.filter [1456]: INFO [recidive] Found 156.213.148.55 - 2026-08-18 16:09:13cloudlinux2 fail2ban: 2026-08-18 16:09:13,538 fail2ban.actions [1456]: NOTICE [plesk-modsecurity] Ban 156.213.148.55cloudlinux2 fail2ban: 2026-08-18 16:09:13,433 fail2ban.filter [1456]: INFO [plesk-modsecurity] Found 156.213.148.55 - 2026-08-18 16:09:13cloudlinux2 fail2ban: 2026-0
show less
Web App Attack
๐บ๐ธ
Lee Daniel
2026-08-18 13:49:50
(1 month ago)
[18/Aug/2026:09:49:29.422360 --0400] aoRi6elJ857vpaWrgbR-lAAAAME 156.213.148.55 42524 127.0.0.1 7081 ...
show more
[18/Aug/2026:09:49:29.422360 --0400] aoRi6elJ857vpaWrgbR-lAAAAME 156.213.148.55 42524 127.0.0.1 7081
[18/Aug/2026:09:49:39.283592 --0400] aoRi83mUH7IoIY5aebKkcAAAAEs 156.213.148.55 34412 127.0.0.1 7081
[18/Aug/2026:09:49:49.784802 --0400] aoRi-XmUH7IoIY5aebKkdwAAAEY 156.213.148.55 42466 127.0.0.1 7081
...
show less
DDoS Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-18 13:21:25
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 156.213.148.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 156.213.148.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 09:21:17.562125 2026] [security2:error] [pid 24297:tid 24297] [client 156.213.148.55:58433] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.213.148.55 (+1 hits since last alert)|clipper1970.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "clipper1970.com"] [uri "/xmlrpc.php"] [unique_id "aoRcTWce34I4LKNCYIgXXQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Dunham Support
2026-08-18 12:49:51
(1 month ago)
(wordpress) Failed wordpress login from 156.213.148.55 (EG/Egypt/-)
Brute-Force
๐ฉ๐ช
pscriptos
2026-08-18 12:48:33
(1 month ago)
{"ClientAddr":"156.213.148.55:55946","ClientHost":"156.213.148.55","ClientPort":"55946","ClientUsern ...
show more
{"ClientAddr":"156.213.148.55:55946","ClientHost":"156.213.148.55","ClientPort":"55946","ClientUsername":"-","DownstreamContentSize":418,"DownstreamStatus":403,"Duration":171603358,"OriginContentSize":418,"OriginDuration":167612825,"OriginStatus":403,"Overhead":3990533,"RequestAddr":"www.cleveradmin.de","RequestContentSize":711,"RequestCount":4199687,"RequestHost":"www.cleveradmin.de","RequestMethod":"POST","RequestPath":"/xmlrpc.php","RequestPort":"-","RequestProtocol":"HTTP/1.1","RequestScheme":"https","RetryAttempts":0,"RouterName":"cleveradmin-www-websecure@file","ServiceAddr":"172.16.80.10:80","ServiceName":"cleveradmin-www@file","ServiceURL":"http://172.16.80.10:80","StartLocal":"2026-08-18T14:48:12.159054834+02:00","StartUTC":"2026-08-18T12:48:12.159054834Z","TLSCipher":"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256","TLSVersion":"1.2","entryPointName":"websecure","level":"info","msg":"","time":"2026-08-18T14:48:12+02:00"}
{"ClientAddr":"156.213.148.55:55946","ClientHost":"156.213.148.5
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 11:18:41
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 156.213.148.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 156.213.148.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 07:18:33.577926 2026] [security2:error] [pid 24462:tid 24462] [client 156.213.148.55:49551] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.213.148.55 (+1 hits since last alert)|naominixon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "naominixon.com"] [uri "/xmlrpc.php"] [unique_id "aoQ_iWkZvL6uEhug4oWR-AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 10:48:11
(1 month ago)
(mod_security) mod_security (id:240335) triggered by 156.213.148.55 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:240335) triggered by 156.213.148.55 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 06:48:05.171843 2026] [security2:error] [pid 14168:tid 14187] [client 156.213.148.55:63896] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 156.213.148.55 (+1 hits since last alert)|neotienda.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "neotienda.com"] [uri "/xmlrpc.php"] [unique_id "aoQ4ZRSB-zO19vSdl7LNggAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-08-17 17:27:33
(1 month ago)
(wordpress) Failed wordpress login from 156.213.148.55 (EG/Egypt/-): (CF_ENABLE)
Brute-Force