🇳🇿
Tripwire
2026-09-07 13:43:46
(38 minutes ago)
Wordpress login attempts
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-09-07 13:28:56
(53 minutes ago)
cloudlinux2 fail2ban: 2026-09-07 15:24:04,297 fail2ban.filter [1794]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-07 15:24:04,297 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 154.180.202.240 - 2026-09-07 15:24:04cloudlinux2 fail2ban: 2026-09-07 15:24:12,354 fail2ban.filter [1794]: INFO [plesk-proftpd] Found 162.240.152.18 - 2026-09-07 15:24:12cloudlinux2 fail2ban: 2026-09-07 15:24:38,951 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 103.254.33.226 - 2026-09-07 15:24:38cloudlinux2 fail2ban: 2026-09-07 15:24:47,560 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 154.180.202.240 - 2026-09-07 15:24:47cloudlinux2 fail2ban: 2026-09-07 15:25:19,610 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 154.180.202.240 - 2026-09-07 15:25:19cloudlinux2 fail2ban: 2026-09-07 15:25:19,699 fail2ban.filter [1794]: INFO [recidive] Found 154.180.202.240 - 2026-09-07 15:25:19cloudlinux2 fail2ban: 2026-09-07 15:25:19,692 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Ban 154.180.202.240cloudlinux2 fail2ban:
show less
FTP Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-07-03 07:36:05
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 03:35:59.546898 2026] [security2:error] [pid 21355:tid 21461] [client 103.254.33.226:43040] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||supercyprus.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "supercyprus.com"] [uri "/wp-json/wp/v2/users/5"] [unique_id "akdmX5hoXP1a_ZlJ0H8VjgAAAk8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-07-02 16:59:00
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-07-02 14:11:18
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 10:11:14.232498 2026] [security2:error] [pid 1596:tid 1596] [client 103.254.33.226:55498] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||firebelly.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "firebelly.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "akZxgnHg24umjeOonv5AkwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-07-02 08:30:51
(2 months ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.254.33.226 (IN/India/-): 1 in the last 36 ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.254.33.226 (IN/India/-): 1 in the last 3600 secs (0-196)
show less
Hacking
🇩🇪
ger-stg-sifi1
2026-07-02 08:22:44
(2 months ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
FeG Deutschland
2026-07-01 08:23:43
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇩🇪
brechtr
2026-07-01 07:00:23
(2 months ago)
[Press84-BanHammer] bad username — Sourced from: www.langsvlaamsewegen.be — Request: POST /wp-login. ...
show more
[Press84-BanHammer] bad username — Sourced from: www.langsvlaamsewegen.be — Request: POST /wp-login.php
show less
Brute-Force
🇫🇷
masterguru
2026-07-01 05:59:16
(2 months ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.254.33.226 (-): 1 in the last 3600 secs ( ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.254.33.226 (-): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-06-30 06:39:39
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 02:39:33.829528 2026] [security2:error] [pid 12496:tid 12496] [client 103.254.33.226:40778] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dianamead.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dianamead.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "akNkpSq6QSAbsa5b_mrh3wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-29 22:10:00
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 18:09:56.973722 2026] [security2:error] [pid 11940:tid 11940] [client 103.254.33.226:54590] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iconconstructors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iconconstructors.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "akLtND9AzbpDx4qpdRbMYQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-29 18:52:47
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 14:52:39.650019 2026] [security2:error] [pid 19401:tid 19401] [client 103.254.33.226:51028] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||concentricsteel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "concentricsteel.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "akK-9yEo3L9k19ISrDfbFQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-06-29 14:28:27
(2 months ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.254.33.226 (IN/India/-): 1 in the last 36 ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.254.33.226 (IN/India/-): 1 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-06-29 12:13:24
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 103.254.33.226 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 08:13:19.297676 2026] [security2:error] [pid 9178:tid 9178] [client 103.254.33.226:56114] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wc2023.renju.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wc2023.renju.net"] [uri "/wp-json/wp/v2/users"] [unique_id "akJhX34MAsTvAV33IpTHRwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack