๐ฌ๐ง
thetomtaylor.co.uk
2026-05-05 10:09:02
(2 months ago)
Fail2Ban - [RECIDIVE]Repeat offender across multiple jails on recidive ... [mx02,mx03]
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-05-05 07:08:01
(2 months ago)
Fail2Ban - [RECIDIVE]Repeat offender across multiple jails on recidive ... [ice02,mx01,wa01,wa02]
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-04-09 04:12:03
(3 months ago)
Bot / scanning and/or hacking attempts: GET /wp-login.php HTTP/1.1, GET / HTTP/1.1
Hacking
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-08 23:42:22
(3 months ago)
152.42.240.111 - - [09/Apr/2026:02:42:22 +0300] "GET /wp-login.php HTTP/1.1" 404 3372 "https://t.co/ ...
show more
152.42.240.111 - - [09/Apr/2026:02:42:22 +0300] "GET /wp-login.php HTTP/1.1" 404 3372 "https://t.co/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-04-08 18:07:09
(3 months ago)
Fail2Ban - [RECIDIVE]Repeat offender across multiple jails on recidive ... [wa02]
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-08 04:56:39
(3 months ago)
152.42.240.111 - - [08/Apr/2026:07:56:39 +0300] "GET /wp-login.php HTTP/1.1" 404 3411 "https://www.b ...
show more
152.42.240.111 - - [08/Apr/2026:07:56:39 +0300] "GET /wp-login.php HTTP/1.1" 404 3411 "https://www.bing.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 22:52:50
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 152.42.240.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 152.42.240.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 18:52:46.133161 2026] [security2:error] [pid 2799046:tid 2799046] [client 152.42.240.111:40762] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rambleandprose.cyberclay.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rambleandprose.cyberclay.net"] [uri "/wp-json/wp/v2/users"] [unique_id "adWKvtwB7c2bh2g5Wy1k0QAAABA"], referer: https://duckduckgo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-04-07 22:06:51
(3 months ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-07 19:42:03
(3 months ago)
152.42.240.111 - - [07/Apr/2026:22:42:03 +0300] "GET /wp-login.php HTTP/1.1" 404 3413 "https://duckd ...
show more
152.42.240.111 - - [07/Apr/2026:22:42:03 +0300] "GET /wp-login.php HTTP/1.1" 404 3413 "https://duckduckgo.com/" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 16:02:12
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 152.42.240.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 152.42.240.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 12:02:07.408437 2026] [security2:error] [pid 1289433:tid 1289433] [client 152.42.240.111:39388] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||qed-consulting.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "qed-consulting.co"] [uri "/wp-json/wp/v2/users"] [unique_id "adUqfwcg6Tddb3lBlNgltAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-04-07 14:55:34
(3 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-04-07 07:23:34
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 152.42.240.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 152.42.240.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 03:23:27.610038 2026] [security2:error] [pid 2098427:tid 2098510] [client 152.42.240.111:37558] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pruebas.emehache.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pruebas.emehache.net"] [uri "/wp-json/wp/v2/users"] [unique_id "adSw78ZjGo1jQnoasnac3AAAAQ4"], referer: https://duckduckgo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-04-07 06:54:53
(3 months ago)
152.42.240.111 - - [07/Apr/2026:09:54:52 +0300] "GET /wp-login.php HTTP/1.1" 404 3358 "-" "Mozilla/5 ...
show more
152.42.240.111 - - [07/Apr/2026:09:54:52 +0300] "GET /wp-login.php HTTP/1.1" 404 3358 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
factor1
2026-04-07 04:04:50
(3 months ago)
Fail2ban at saturn Reports Abuse.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-06 22:51:19
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 152.42.240.111 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 152.42.240.111 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 18:51:12.453790 2026] [security2:error] [pid 458553:tid 458553] [client 152.42.240.111:49886] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ralphharris.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ralphharris.org"] [uri "/wp-json/wp/v2/users"] [unique_id "adQ44MwTV0szS-bpFLtulAAAAAw"], referer: https://www.google.com/search?q=wordpress
show less
Brute-Force
Bad Web Bot
Web App Attack