๐จ๐ญ
backslash
2026-08-27 21:21:12
(23 hours ago)
block ruleset 486D2EE5E731CC049D1E480D68D04DFFE28AADF1
Bad Web Bot
๐ฎ๐น
CoreTech srl
2026-07-20 22:03:59
(1 month ago)
cloudlinux2 fail2ban: 2026-07-21 00:00:48,563 fail2ban.filter [1927]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-21 00:00:48,563 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 193.203.9.121 - 2026-07-21 00:00:47cloudlinux2 fail2ban: 2026-07-21 00:00:49,106 fail2ban.filter [1927]: INFO [plesk-modsecurity] Found 170.168.242.181 - 2026-07-21 00:00:48cloudlinux2 fail2ban: 2026-07-21 00:00:52,356 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 146.19.140.43 - 2026-07-21 00:00:51cloudlinux2 fail2ban: 2026-07-21 00:01:06,847 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 89.19.35.125 - 2026-07-21 00:01:06cloudlinux2 fail2ban: 2026-07-21 00:01:09,987 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 45.132.184.94 - 2026-07-21 00:01:09cloudlinux2 fail2ban: 2026-07-21 00:01:04,440 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 122.8.93.48 - 2026-07-21 00:01:03cloudlinux2 fail2ban: 2026-07-21 00:01:12,057 fail2ban.filter [1927]: INFO [plesk-wordpress] Found 122.8.92.155 - 2026-07-21 00:01:11cloudlinu
show less
Web App Attack
๐ช๐ธ
librebit
2026-07-16 06:45:21
(1 month ago)
Brute force
Brute-Force
๐ช๐ธ
librebit
2026-07-15 03:21:48
(1 month ago)
Brute force
Brute-Force
๐ฎ๐ฉ
sockominfo
2026-06-27 09:00:53
(2 months ago)
Stacked query SQL injection. Threat Score: 8.7/10 (CRITICAL). Confidence: 70%. CVSS v3.1: 10/10 (Cri ...
show more
Stacked query SQL injection. Threat Score: 8.7/10 (CRITICAL). Confidence: 70%. CVSS v3.1: 10/10 (Critical). CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H. Bayesian Probability: 87%. MITRE ATT&CK: T1190 (Exploit Public-Facing Application). Tactic: TA0001. Freshness: Fresh. Source Reputation: KNOWN_MALICIOUS. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Brute-Force
๐ฎ๐ฉ
sockominfo
2026-06-27 08:00:09
(2 months ago)
Stacked query SQL injection. Threat Score: 7.5/10 (HIGH). Reported by TangerangKota-CSIRT. Status: M ...
show more
Stacked query SQL injection. Threat Score: 7.5/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Brute-Force
๐ฎ๐ฉ
sockominfo
2026-06-27 07:00:08
(2 months ago)
Stacked query SQL injection. Threat Score: 7.6/10 (HIGH). Reported by TangerangKota-CSIRT. Status: M ...
show more
Stacked query SQL injection. Threat Score: 7.6/10 (HIGH). Reported by TangerangKota-CSIRT. Status: MALICIOUS
show less
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-30 16:20:21
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 146.19.140.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 146.19.140.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 12:20:15.060484 2026] [security2:error] [pid 13846:tid 13846] [client 146.19.140.43:29411] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||miszewski.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "miszewski.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afOBPwa0g2of49PeKJr8CQAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-25 08:41:48
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 146.19.140.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 146.19.140.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 04:41:41.598107 2026] [security2:error] [pid 7126:tid 7126] [client 146.19.140.43:34843] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pages4you.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pages4you.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aex-RUhRWl71b094LDqdVwAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-23 10:37:59
(4 months ago)
FPROCO WEBEXPLOIT 146.19.140.43 (146.19.140.43)
Web App Attack
๐บ๐ธ
ambor
2026-04-17 14:55:33
(4 months ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-08 01:36:52
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 146.19.140.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 146.19.140.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 21:36:49.030788 2026] [security2:error] [pid 3404186:tid 3404186] [client 146.19.140.43:58731] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fsmfl.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fsmfl.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adWxMYev3Uh8XyBXR_o7DAAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-05 16:29:46
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 146.19.140.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 146.19.140.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 12:29:38.882247 2026] [security2:error] [pid 16109:tid 16109] [client 146.19.140.43:52541] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||i-med.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "i-med.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adKN8ttncleEtLMkTFha0gAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neogenius
2026-03-28 18:04:41
(5 months ago)
Web App Attack
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-03-26 02:18:36
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 146.19.140.43 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 146.19.140.43 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 25 22:18:29.850330 2026] [security2:error] [pid 1350:tid 1350] [client 146.19.140.43:35883] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sentientresearch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sentientresearch.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acSXdSKtKVliulSEmTzcuAAAABU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack