๐บ๐ธ
agabeckov
2026-09-14 16:32:27
(5 days ago)
Fail2Ban detected brute-force attempt on Cisco Anyconnect
VPN IP
Brute-Force
๐ธ๐ช
OnTheEdge
2026-09-14 15:39:59
(5 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
๐จ๐ฟ
Countryman
2026-09-12 00:10:01
(1 week ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐ฉ๐ช
LRob
2026-06-25 17:00:27
(2 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-04-20 12:42:05
(5 months ago)
157.22.100.30 - - [20/Apr/2026:14:42:04 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3978 "-" "Mozilla/5.0 ...
show more
157.22.100.30 - - [20/Apr/2026:14:42:04 +0200] "POST /xmlrpc.php HTTP/1.1" 403 3978 "-" "Mozilla/5.0 (X11; Linux i686 (x86_64)) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2026-03-11 15:15:18
(6 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-23 05:36:51
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.100.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.100.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 23 00:36:44.786099 2026] [security2:error] [pid 20670:tid 20670] [client 157.22.100.30:15669] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||artspacecleveland.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "artspacecleveland.org"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aXMI7GF029cvNyaXspCFMwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 13:27:20
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.100.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.100.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 08:27:16.666459 2026] [security2:error] [pid 20373:tid 20373] [client 157.22.100.30:12301] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||earthtwoworkshop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "earthtwoworkshop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXIltNdYhNlXP9Q1b62qNgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2026-01-02 14:23:41
(8 months ago)
1 attack(s) detected, such as these: {"event":"web_block","ip":"157.22.100.30","host":"marche-be.com ...
show more
1 attack(s) detected, such as these: {"event":"web_block","ip":"157.22.100.30","host":"marche-be.com","request":"GET /wp-login.php HTTP/1.1","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0","reason":"service:unknow","timestamp":"2026-01-02T14:23:41 00:00","logentry":"marche-be.com 157.22.100.30 - - [02/Jan/2026:14:23:41 0000] GET /wp-login.php HTTP/1.1 444 0 - Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0 - matched:service:unknow"} * Report Details *: https://p4u.xyz/RT3EGGJ7F39/1* IP Details *: https://p4u.xyz/RT3EGGJ7F39/2
show less
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-25 19:53:12
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 157.22.100.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 157.22.100.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Dec 25 14:53:01.330545 2025] [security2:error] [pid 9195:tid 9195] [client 157.22.100.30:35689] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bernsteinip.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aU2WHbD3rRaeQHsYHEfcnQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2025-12-21 17:35:50
(8 months ago)
Wordpress login attempts
Brute-Force
Web App Attack