🇬🇧
thetomtaylor.co.uk
2026-09-08 20:07:01
(20 hours ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice01,wa01,wa02]
Bad Web Bot
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-08 19:08:01
(21 hours ago)
Fail2Ban - [NGINX]WordPress Logins Sniffings on nginx-wordpress-sniffer ... [ice02]
Bad Web Bot
Web App Attack
🇺🇸
integrantservices.com
2026-09-08 18:57:24
(21 hours ago)
(wordpress) Failed wordpress login from 150.251.225.221 (AT/Austria/-)
Brute-Force
Anonymous
2026-09-08 18:52:36
(21 hours ago)
(wordpress) Failed wordpress login from 150.251.225.221 (AT/Austria/-)
Brute-Force
Anonymous
2026-09-08 18:37:05
(22 hours ago)
(wordpress) Failed wordpress login from 150.251.225.221 (AT/Austria/State of Vienna/Vienna/-/[redact ...
show more
(wordpress) Failed wordpress login from 150.251.225.221 (AT/Austria/State of Vienna/Vienna/-/[redacted])
show less
Brute-Force
🇯🇵
S.O.B.A. Dev.
2026-09-08 17:46:46
(22 hours ago)
Web vulnerability scanning
Brute-Force
Web Spam
Web App Attack
🇺🇸
integrantservices.com
2026-08-29 15:52:38
(1 week ago)
(wordpress) Failed wordpress login from 150.251.225.221 (AT/Austria/-)
Brute-Force
🇺🇸
nyt
2026-07-07 20:18:22
(2 months ago)
WP login POST blocked by WAF, Repeated access to wp-admin profile page
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-07-06 00:03:39
(2 months ago)
(mod_security) mod_security (id:220020) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:220020) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 20:03:33.790153 2026] [security2:error] [pid 16714:tid 16714] [client 150.251.225.221:49761] ModSecurity: Access denied with code 403 (phase 1). Pattern match "(^|;)=(;|$)" at REQUEST_HEADERS:Cookie. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "74"] [id "220020"] [rev "2"] [msg "COMODO WAF: DoS vulnerability in Apache 2.2.17 - 2.2.21 (CVE-2012-0021)||blacksheepoffroad.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blacksheepoffroad.com"] [uri "/"] [unique_id "akrw1ReK1LUggdMhLLDnzAAAADc"], referer: http://satanoufi.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-05 22:26:25
(2 months ago)
(mod_security) mod_security (id:220020) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:220020) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 18:26:18.782683 2026] [security2:error] [pid 18550:tid 18550] [client 150.251.225.221:34731] ModSecurity: Access denied with code 403 (phase 1). Pattern match "(^|;)=(;|$)" at REQUEST_HEADERS:Cookie. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "74"] [id "220020"] [rev "2"] [msg "COMODO WAF: DoS vulnerability in Apache 2.2.17 - 2.2.21 (CVE-2012-0021)||www.stat-alliance.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stat-alliance.com"] [uri "/"] [unique_id "akraCqwZJpsYGRnAr2_s_gAAAA8"], referer: https://a-b-rcc.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-05 21:17:48
(2 months ago)
(mod_security) mod_security (id:220020) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:220020) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 17:17:44.839547 2026] [security2:error] [pid 25865:tid 25891] [client 150.251.225.221:64763] ModSecurity: Access denied with code 403 (phase 1). Pattern match "(^|;)=(;|$)" at REQUEST_HEADERS:Cookie. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "74"] [id "220020"] [rev "2"] [msg "COMODO WAF: DoS vulnerability in Apache 2.2.17 - 2.2.21 (CVE-2012-0021)||rainbowbb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rainbowbb.com"] [uri "/"] [unique_id "akrJ-G-NO_95ArRL-ZT7DgAAAJI"], referer: https://paintingsinperil.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Reinhard
2026-07-05 18:50:01
(2 months ago)
Unknown activity, but too many attacks with too many users.
Hacking
🇺🇸
TPI-Abuse
2026-07-05 17:52:02
(2 months ago)
(mod_security) mod_security (id:220020) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:220020) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 05 13:51:58.250048 2026] [security2:error] [pid 28724:tid 28724] [client 150.251.225.221:28303] ModSecurity: Access denied with code 403 (phase 1). Pattern match "(^|;)=(;|$)" at REQUEST_HEADERS:Cookie. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "74"] [id "220020"] [rev "2"] [msg "COMODO WAF: DoS vulnerability in Apache 2.2.17 - 2.2.21 (CVE-2012-0021)||7bsuperfruit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "7bsuperfruit.com"] [uri "/"] [unique_id "akqZvpgNAcWCdjrOnEaG1wAAAA4"], referer: http://seelensnacks.de
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-13 19:43:27
(2 months ago)
(mod_security) mod_security (id:210801) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 15:43:19.534036 2026] [security2:error] [pid 11029:tid 11029] [client 150.251.225.221:20581] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||www.naturephotographyadventures.com|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "www.naturephotographyadventures.com"] [uri "/license.txt"] [unique_id "ai2y18ALWWuKtzLrBIl6zwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-13 16:45:06
(2 months ago)
(mod_security) mod_security (id:210801) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210801) triggered by 150.251.225.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 12:44:56.174944 2026] [security2:error] [pid 1450:tid 1450] [client 150.251.225.221:44261] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "paros" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "17"] [id "210801"] [rev "2"] [msg "COMODO WAF: Request Indicates a Security Scanner Scanned the Site||network22.net|F|2"] [data "mozilla/5.0 (windows nt 5.1; rv:22.0) gecko/20100101 firefox/22.0 paros/3.2.13"] [severity "CRITICAL"] [tag "CWAF"] [tag "Agents"] [hostname "network22.net"] [uri "/license.txt"] [unique_id "ai2JCJiqJkZgX16cuiLUuwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack