🇪🇸
librebit
2026-07-26 00:50:30
(1 month ago)
Brute force
Brute-Force
🇧🇷
Peregrine
2026-07-21 03:13:14
(1 month ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 170.168.242.64 172.69.136.240 - - [18/Jul/2026:16:3 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 170.168.242.64 172.69.136.240 - - [18/Jul/2026:16:32:23 -0300] "GET /wp-login.php HTTP/1.1" 404 18193
show less
Bad Web Bot
🇧🇷
Peregrine
2026-07-20 03:13:07
(1 month ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 170.168.242.64 172.69.136.240 - - [18/Jul/2026:16:3 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 170.168.242.64 172.69.136.240 - - [18/Jul/2026:16:32:23 -0300] "GET /wp-login.php HTTP/1.1" 404 18193
show less
Bad Web Bot
🇧🇷
Peregrine
2026-07-18 19:32:33
(1 month ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 170.168.242.64 172.69.136.240 - - [18/Jul/2026:16:3 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 170.168.242.64 172.69.136.240 - - [18/Jul/2026:16:32:23 -0300] "GET /wp-login.php HTTP/1.1" 404 18193
show less
Bad Web Bot
🇪🇸
librebit
2026-07-16 15:25:39
(1 month ago)
Brute force
Brute-Force
🇧🇪
Saec
2026-06-30 17:00:14
(2 months ago)
Jarvis auto-ban: CF honeypot path /wp-login.php (1× on saec.me)
Port Scan
Web App Attack
🇺🇸
TRoden
2026-06-19 17:41:34
(2 months ago)
Geo Block Plugin: Escalation flag(s): rce_attempt
Hacking
🇺🇸
oralunal
2026-06-13 00:24:06
(2 months ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-06-10 21:13:07
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.242.64 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.242.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 17:13:02.596004 2026] [security2:error] [pid 29759:tid 29759] [client 170.168.242.64:62163] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dietzengineers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dietzengineers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ainTXgbhkJmxsWE0lTnOywAAAAU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-30 17:20:16
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.242.64 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.242.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 13:20:12.294243 2026] [security2:error] [pid 30822:tid 30822] [client 170.168.242.64:45169] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||2pollards.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "2pollards.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahscTIdxCBQnKCEUnXk6NAAAAAQ"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-18 15:02:38
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 170.168.242.64 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 170.168.242.64 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 11:02:34.034850 2026] [security2:error] [pid 1671:tid 1671] [client 170.168.242.64:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aslanhan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aslanhan.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agsqCo6vDHCyw1CAlW5zVQAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
netclix.gr
2026-04-24 15:55:11
(4 months ago)
(wordpress) Failed wordpress login from 170.168.242.64 (NL/Netherlands/-): (CF_ENABLE)
Brute-Force
🇮🇹
VHosting
2026-03-26 22:53:03
(5 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
🇩🇪
big-cloud.nl
2026-03-15 15:32:16
(5 months ago)
Try to access /xmlrpc.php
Web App Attack
🇨🇿
lp
2026-02-27 12:03:39
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 170.168.242.64
2026-02-27T12:07:18+01 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 170.168.242.64
2026-02-27T12:07:18+01:00 vpn Access-Reject 'sexyguy' station: 170.168.242.64 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack