๐จ๐ฟ
Countryman
2026-09-14 13:19:02
(1 day ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
๐จ๐ญ
backslash
2026-09-13 17:06:19
(2 days ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฉ๐ช
4server
2026-06-09 19:22:16
(3 months ago)
[TueJun0921:22:12.4095612026][security2:error][pid3400475:tid3400606][client170.168.241.153:0]ModSec ...
show more
[TueJun0921:22:12.4095612026][security2:error][pid3400475:tid3400606][client170.168.241.153:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"www.restaurantgandria.ch\"][uri\"/wp-login.php\"][unique_id\"aihn5AJxKGLW-AIv8mk0rgAAAJQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-05-21 20:38:34
(3 months ago)
Fail2Ban banned 170.168.241.153 for security violations in jail wp-armour. Log: 2026/05/21 20:38:34 ...
show more
Fail2Ban banned 170.168.241.153 for security violations in jail wp-armour. Log: 2026/05/21 20:38:34 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 170.168.241.153 | Target: wplogin" , client: 170.168.241.153, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐ฆ๐บ
[email protected]
2026-05-07 13:47:50
(4 months ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-03 10:22:28
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.241.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.241.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 03 06:22:23.026134 2026] [security2:error] [pid 9617:tid 9617] [client 170.168.241.153:57333] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||computergeek.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "computergeek.us"] [uri "/wp-json/wp/v2/users"] [unique_id "afch3-t9Iofai9wJjLUGKQAAABo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 23:19:40
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.241.153 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.241.153 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 19:19:36.153040 2026] [security2:error] [pid 2225:tid 2225] [client 170.168.241.153:50345] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||secuencia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "secuencia.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae6diFTMqBamKToRvaKO3AAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2026-03-11 14:56:54
(6 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐ฎ๐น
VHosting
2026-02-12 12:15:08
(7 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack