Anonymous
2026-09-08 21:52:05
(56 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 21:38:56
(1 hour ago)
cloudlinux2 fail2ban: 2026-09-08 23:34:13,097 fail2ban.filter [1794]: INFO [plesk-proftpd ...
show more
cloudlinux2 fail2ban: 2026-09-08 23:34:13,097 fail2ban.filter [1794]: INFO [plesk-proftpd] Found 45.32.198.114 - 2026-09-08 23:34:13cloudlinux2 fail2ban: 2026-09-08 23:34:18,596 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 84.25.156.163 - 2026-09-08 23:34:18cloudlinux2 fail2ban: 2026-09-08 23:34:36,023 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 110.235.18.218 - 2026-09-08 23:34:35cloudlinux2 fail2ban: 2026-09-08 23:34:42,560 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 216.73.161.178 - 2026-09-08 23:34:41cloudlinux2 fail2ban: 2026-09-08 23:34:43,322 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 136.144.42.134 - 2026-09-08 23:34:43cloudlinux2 fail2ban: 2026-09-08 23:34:47,967 fail2ban.actions [1794]: NOTICE [plesk-wordpress] Ban 216.73.161.178cloudlinux2 fail2ban: 2026-09-08 23:34:47,974 fail2ban.filter [1794]: INFO [recidive] Found 216.73.161.178 - 2026-09-08 23:34:47cloudlinux2 fail2ban: 2026-09-08 23
show less
FTP Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:28:02
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:27:55.126696 2026] [security2:error] [pid 1069:tid 1199] [client 110.235.18.218:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mindgardens.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mindgardens.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBvy4d8PLLgmH7CDnZQNQAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:50:38
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:50:34.619262 2026] [security2:error] [pid 10816:tid 10816] [client 110.235.18.218:48570] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||portlunchgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "portlunchgroup.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBK6tE2XbfmRYe5KFqjnAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:22:02
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:21:57.259568 2026] [security2:error] [pid 22394:tid 22394] [client 110.235.18.218:51468] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||georgegourmet.visionremota.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "georgegourmet.visionremota.info"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBENYrXrKWkBuHXLJNe2QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-08 16:29:09
(6 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
brechtr
2026-09-08 16:11:22
(6 hours ago)
[Press84-BanHammer] bad username — Sourced from: www.langsvlaamsewegen.be — Request: POST /wp-login. ...
show more
[Press84-BanHammer] bad username — Sourced from: www.langsvlaamsewegen.be — Request: POST /wp-login.php
show less
Brute-Force
🇺🇸
cwytech
2026-09-08 15:59:35
(6 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-08 14:30:56
(8 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:22:31
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:22:26.810521 2026] [security2:error] [pid 7051:tid 7051] [client 110.235.18.218:37822] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cynosurehomeservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cynosurehomeservices.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAaIjZGCWAdkd6-h72o1QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:18:06
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:18:02.180700 2026] [security2:error] [pid 27996:tid 27996] [client 110.235.18.218:32818] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||renjunews.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "renjunews.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqALCu4eVAruHyOqfB8mPAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:50:17
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:50:11.332317 2026] [security2:error] [pid 14485:tid 14485] [client 110.235.18.218:37850] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doublenaughtspycar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doublenaughtspycar.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAEg06FB2n_1VYJ63pK-wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:33:17
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:33:09.403667 2026] [security2:error] [pid 10510:tid 10510] [client 110.235.18.218:50702] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||edgecomix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "edgecomix.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAAhcPk9r9yZDqn6mnuHQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:50:49
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:50:43.747613 2026] [security2:error] [pid 10137:tid 10137] [client 110.235.18.218:38320] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||j3pr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "j3pr.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_2k-kPySNjndg4BRnrygAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:40:53
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 110.235.18.218 (110235018218.ctinets.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:40:49.028077 2026] [security2:error] [pid 19011:tid 19011] [client 110.235.18.218:33318] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||loneoakhoney.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "loneoakhoney.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_YIfHbDdX3eVHJQgRKyQAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack