๐ฎ๐น
CoreTech srl
2026-09-01 01:13:56
(15 hours ago)
cloudlinux2 fail2ban: 2026-09-01 03:08:58,353 fail2ban.actions [1605]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-01 03:08:58,353 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 34.47.16.132cloudlinux2 fail2ban: 2026-09-01 03:09:16,083 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 185.146.22.250 - 2026-09-01 03:09:16cloudlinux2 fail2ban: 2026-09-01 03:10:18,881 fail2ban.actions [1605]: WARNING [plesk-modsecurity] 34.81.120.87 already bannedcloudlinux2 fail2ban: 2026-09-01 03:10:16,659 fail2ban.actions [1605]: WARNING [plesk-modsecurity] 34.81.120.87 already bannedcloudlinux2 fail2ban: 2026-09-01 03:10:18,510 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.81.120.87 - 2026-09-01 03:10:18cloudlinux2 fail2ban: 2026-09-01 03:10:19,303 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.81.120.87 - 2026-09-01 03:10:19cloudlinux2 fail2ban: 2026-09-01 03:10:20,083 fail2ban.actions [1605]: WARNING [plesk-modsecurity] 34.81.120.87 already bannedcloudlinux2 fail2ban: 2026-09-01 03:10:17,453 fail2ban.filter
show less
Web App Attack
Anonymous
2026-08-31 23:46:02
(16 hours ago)
Bot / scanning and/or hacking attempts: [2/2] done, GET /wp-login.php HTTP/2.0
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 23:42:32
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.146.22.250 (nl1-sr100.supercp.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 185.146.22.250 (nl1-sr100.supercp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 19:42:28.117894 2026] [security2:error] [pid 20245:tid 20245] [client 185.146.22.250:41078] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iostation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iostation.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apYRZICjJCwWyDghh7w9QQAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-08-31 20:53:07
(19 hours ago)
(wordpress) Failed wordpress login from 185.146.22.250 (US/United States/nl1-sr100.supercp.com): (C ...
show more
(wordpress) Failed wordpress login from 185.146.22.250 (US/United States/nl1-sr100.supercp.com): (CF_ENABLE)
show less
Brute-Force
๐ฉ๐ช
4server
2026-08-31 20:13:31
(20 hours ago)
[MonAug3122:13:27.5005542026][security2:error][pid3161917:tid3162000][client185.146.22.250:0]ModSecu ...
show more
[MonAug3122:13:27.5005542026][security2:error][pid3161917:tid3162000][client185.146.22.250:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"agilityrossoblu.ch\"][uri\"/wp-login.php\"][unique_id\"apXgZ66KDE4sGQxPE4VeSwAAAM0\"]\,referer:https://agilityrossoblu.ch/wp-login.php
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 19:54:48
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.146.22.250 (nl1-sr100.supercp.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 185.146.22.250 (nl1-sr100.supercp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 15:54:45.015382 2026] [security2:error] [pid 28252:tid 28252] [client 185.146.22.250:45730] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||skintormint.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "skintormint.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apXcBdN4FUAo6Sz7O7eetQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-31 04:21:39
(1 day ago)
Wordpress malicious attack:[octaflood]
Web App Attack
Anonymous
2026-08-30 21:50:06
(1 day ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-08-30 20:09:06
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฉ๐ช
iNetWorker
2026-08-30 19:32:47
(1 day ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 11:05:06
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 185.146.22.250 (nl1-sr100.supercp.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 185.146.22.250 (nl1-sr100.supercp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 07:04:58.486318 2026] [security2:error] [pid 22430:tid 22430] [client 185.146.22.250:36640] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||robotsinme.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "robotsinme.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apQOWutOTWS3n0nGACKi9QAAABI"], referer: https://robotsinme.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-29 15:33:53
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 15:03:41
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.146.22.250 (nl1-sr100.supercp.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 185.146.22.250 (nl1-sr100.supercp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 11:03:34.309844 2026] [security2:error] [pid 32167:tid 32167] [client 185.146.22.250:41730] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aifactoid.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aifactoid.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apL0xp2XGwfB1nUanYfduAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 13:23:01
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.146.22.250 (nl1-sr100.supercp.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 185.146.22.250 (nl1-sr100.supercp.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 09:22:58.360916 2026] [security2:error] [pid 7741:tid 7741] [client 185.146.22.250:49556] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aquanauticsige.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aquanauticsige.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apLdMpf1jnuWehFX-KrrIQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-29 06:18:15
(3 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-29 06:18 UTC
show less
Hacking
Web App Attack