๐จ๐ญ
backslash
2026-08-28 15:09:07
(4 days ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฎ๐น
CoreTech srl
2026-07-28 23:13:56
(1 month ago)
cloudlinux2 fail2ban: 2026-07-29 01:10:48,174 fail2ban.filter [1917]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-29 01:10:48,174 fail2ban.filter [1917]: INFO [plesk-modsecurity] Found 45.159.22.48 - 2026-07-29 01:10:48cloudlinux2 fail2ban: 2026-07-29 01:11:34,580 fail2ban.filter [1917]: INFO [plesk-wordpress] Found 135.148.171.117 - 2026-07-29 01:11:34cloudlinux2 fail2ban: 2026-07-29 01:13:18,644 fail2ban.filter [1917]: INFO [plesk-wordpress] Found 77.83.24.210 - 2026-07-29 01:13:18cloudlinux2 fail2ban: 2026-07-29 01:13:20,837 fail2ban.filter [1917]: INFO [plesk-wordpress] Found 5.183.255.90 - 2026-07-29 01:13:20cloudlinux2 fail2ban: 2026-07-29 01:13:23,412 fail2ban.filter [1917]: INFO [plesk-wordpress] Found 130.49.79.15 - 2026-07-29 01:13:23cloudlinux2 fail2ban: 2026-07-29 01:13:25,626 fail2ban.filter [1917]: INFO [plesk-wordpress] Found 146.19.140.227 - 2026-07-29 01:13:25cloudlinux2 fail2ban: 2026-07-29 01:13:28,094 fail2ban.filter [1917]: INFO [plesk-wordpress] Found 157.22.127.32 - 2026-07-29 01:13:27cloudlin
show less
Web App Attack
๐ฆ๐บ
MAGIC
2026-04-25 01:39:40
(4 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ฉ๐ช
LRob
2026-04-13 21:45:10
(4 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-10 07:58:17
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 03:58:13.585752 2026] [security2:error] [pid 1534093:tid 1534093] [client 146.19.140.227:14025] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rocketcityhotwheelers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rocketcityhotwheelers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aditlbr4bdo2bxCyjDP3fAAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-26 23:31:08
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 26 19:31:02.642563 2025] [security2:error] [pid 4879:tid 4879] [client 146.19.140.227:40543] [client 146.19.140.227] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||bitcoinsubscribers.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/all-in-one-seo-pack/classes/aiosp.class.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bitcoinsubscribers.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/classes/aiosp.class.php"] [unique_id "Z-SONloPjqRH7_zJfNoedgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-21 23:09:07
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 21 19:08:57.887020 2025] [security2:error] [pid 16885:tid 16885] [client 146.19.140.227:59005] [client 146.19.140.227] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||b2c-llc.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/canto/includes/lib/download.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "b2c-llc.com"] [uri "/wp-content/plugins/canto/includes/lib/download.php"] [unique_id "Z93xiWe-MNxEq9TaqJQ6HQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-18 10:58:28
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 18 06:58:23.285634 2025] [security2:error] [pid 304537:tid 304537] [client 146.19.140.227:61973] [client 146.19.140.227] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||arriagarealestate.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/all-in-one-seo-pack/classes/aiosp.class.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arriagarealestate.com"] [uri "/wp-content/plugins/all-in-one-seo-pack/classes/aiosp.class.php"] [unique_id "Z9lRz2JDhG3HI0JBEmZViQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-11 11:26:53
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 11 07:26:45.551219 2025] [security2:error] [pid 26002:tid 26002] [client 146.19.140.227:43453] [client 146.19.140.227] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "11"] [msg "COMODO WAF: Remote File Inclusion Attack||aemcmullin.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/w3-total-cache/lib/w3/pager.class.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aemcmullin.com"] [uri "/wp-content/plugins/w3-total-cache/lib/W3/Pager.class.php"] [unique_id "Z9Ad9VCvZ3x7nfJ2IYS33AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-11 07:30:38
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 11 03:30:32.812189 2025] [security2:error] [pid 16416:tid 16416] [client 146.19.140.227:39509] [client 146.19.140.227] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||advantagesystemsgroup.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/wp-super-cache/js/cache-loader.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "advantagesystemsgroup.com"] [uri "/wp-content/plugins/wp-super-cache/js/cache-loader.php"] [unique_id "Z8_mmHpeeuIEejtlFhhUPgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-09 21:16:30
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 09 17:16:25.515175 2025] [security2:error] [pid 5876:tid 5876] [client 146.19.140.227:61919] [client 146.19.140.227] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||abilityengraving.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/canto/includes/lib/download.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abilityengraving.com"] [uri "/wp-content/plugins/canto/includes/lib/download.php"] [unique_id "Z84FKUftV8pAqanxGkAb1QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-26 22:34:04
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 26 17:34:00.198752 2025] [security2:error] [pid 29254:tid 29254] [client 146.19.140.227:62123] [client 146.19.140.227] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||xirin.net|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/canto/includes/lib/download.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xirin.net"] [uri "/wp-content/plugins/canto/includes/lib/download.php"] [unique_id "Z7-W2OA3b3bCXE4jHCDOJwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-26 16:41:50
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:211120) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 26 11:41:42.946819 2025] [security2:error] [pid 30966:tid 30966] [client 146.19.140.227:40659] [client 146.19.140.227] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "11"] [msg "COMODO WAF: Remote File Inclusion Attack||www.stoveclockrepair.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/canto/includes/lib/download.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stoveclockrepair.com"] [uri "/wp-content/plugins/canto/includes/lib/download.php"] [unique_id "Z79ERokYjfKJIqkck07rfAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-20 19:31:01
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 146.19.140.227 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 20 14:30:57.116229 2025] [security2:error] [pid 901439:tid 901439] [client 146.19.140.227:16039] [client 146.19.140.227] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "collectivedzgn.com"] [uri "/.env"] [unique_id "Z7eC8bi69p53n5HmreMSYQAAAAI"], referer: https://tasamm.com/about/ccc66.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
JimArchon72
2025-01-23 15:25:02
(1 year ago)
2025/01/23 15:23:47 "GET /wp-login.php HTTP/1.1"
Web App Attack