๐ฉ๐ช
Lino Project
2026-09-16 03:59:45
(9 minutes ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-dos-swithcing-ua
Hacking
๐ฉ๐ช
Tha_14
2026-09-16 03:19:27
(49 minutes ago)
Attempt to log in with non-existing username: site_admin
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-15 23:05:23
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 19:05:15.455738 2026] [security2:error] [pid 2240:tid 2240] [client 134.209.104.26:63208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.partners.imagineyourphotos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.partners.imagineyourphotos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqnPK_RTUmr8Zn4nQ6-fRwAAAAc"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
palzer.IT
2026-09-15 22:37:33
(5 hours ago)
Fail2ban automatic report for plesk-wordpress: 134.209.104.26 - - [16/Sep/2026:00:37:13 +0200] POST ...
show more
Fail2ban automatic report for plesk-wordpress: 134.209.104.26 - - [16/Sep/2026:00:37:13 +0200] POST /wp-login.php [DOMAIN_REMOVED] 200 9396 [DOMAIN_REMOVED] Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:118.0) Gecko/20100101 Firefox/118.0
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
YF
2026-09-15 21:07:15
(7 hours ago)
wp-login.php Brute force
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:54:34
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:54:28.225958 2026] [security2:error] [pid 21787:tid 21787] [client 134.209.104.26:59104] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.dixiegeek.cosentient.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.dixiegeek.cosentient.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqmwhFdCUpI-2yOnL6GQ8wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
palzer.IT
2026-09-15 19:47:57
(8 hours ago)
Fail2ban automatic report for plesk-wordpress: 134.209.104.26 - - [15/Sep/2026:21:47:13 +0200] POST ...
show more
Fail2ban automatic report for plesk-wordpress: 134.209.104.26 - - [15/Sep/2026:21:47:13 +0200] POST /wp-login.php [DOMAIN_REMOVED] 200 9522 [DOMAIN_REMOVED] Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36 134.209.104.26 - - [15/Sep/2026:21:47:26 +0200] POST /wp-login.php [DOMAIN_REMOVED] 200 9520 [DOMAIN_REMOVED] Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1; rv:119.0) Gecko/20100101 Firefox/119.0 134.209.104.26 - - [15/Sep/2026:21:47:37 +0200] POST /wp-login.php [DOMAIN_REMOVED] 200 9520 [DOMAIN_REMOVED] Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:46:21
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:46:13.902896 2026] [security2:error] [pid 7909:tid 7909] [client 134.209.104.26:59874] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.plazahacienda.imerka.com.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.plazahacienda.imerka.com.mx"] [uri "/wp-json/wp/v2/users"] [unique_id "aqmghVIjB1i2er8wjI3t7AAAAAA"], referer: https://wordpress.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
outputblog.de
2026-09-15 19:03:50
(9 hours ago)
apache-wp-probephp
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-15 18:57:15
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:57:07.264186 2026] [security2:error] [pid 31035:tid 31035] [client 134.209.104.26:64234] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.crr-construction.321q.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.crr-construction.321q.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqmVA4sviPVJeSmINBVdrAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:32:58
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:32:51.185849 2026] [security2:error] [pid 1265:tid 1265] [client 134.209.104.26:55294] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.oruhu.org.circulodesonido.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.oruhu.org.circulodesonido.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aqmPUwFFhV1ZBxeY1TEyQwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:47:49
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:47:46.251969 2026] [security2:error] [pid 7546:tid 7546] [client 134.209.104.26:59532] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.edmontonareahomes.digitalracemedia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.edmontonareahomes.digitalracemedia.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqmEwlP5iBJtBd3pIdeRfwAAABw"], referer: https://t.co/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-09-15 16:44:32
(11 hours ago)
Wordpress Vunerability attack
Web App Attack
๐ซ๐ฎ
stinpriza
2026-09-15 16:43:04
(11 hours ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 16:29:21
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 134.209.104.26 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:29:14.707933 2026] [security2:error] [pid 28395:tid 28395] [client 134.209.104.26:53183] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||illumoonatedtarot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "illumoonatedtarot.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqlyWgxYjhmhy3eisYRopgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack