๐ฉ๐ช
FeG Deutschland
2026-08-28 14:45:10
(7 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
Anonymous
2026-08-28 14:32:03
(7 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-26 17:31:31
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 02:42:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 185.251.19.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.251.19.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:41:31.634171 2026] [security2:error] [pid 18748:tid 18748] [client 185.251.19.30:61053] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.103"] [uri "/cgi-bin/.env"] [unique_id "ao5SWwKiV-jLn5XXF4XUsQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 02:25:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 185.251.19.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 185.251.19.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 22:25:22.273734 2026] [security2:error] [pid 22093:tid 22093] [client 185.251.19.30:51717] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.196"] [uri "/src/.env"] [unique_id "aokIkmFVBqohlqE5mrsrnQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
tall1oN
2026-07-29 19:24:15
(4 weeks ago)
185.251.19.30 - - [29/Jul/2026:21:24:08 +0200] "HEAD /xmlrpc.php HTTP/2.0" 200 0 "-" "Mozilla/5.0 (X ...
show more
185.251.19.30 - - [29/Jul/2026:21:24:08 +0200] "HEAD /xmlrpc.php HTTP/2.0" 200 0 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:45.0) Gecko/20100101 Firefox/45.0" "exatek.de"
185.251.19.30 - - [29/Jul/2026:21:24:15 +0200] "GET /xmlrpc.php HTTP/2.0" 200 6760 "-" "Mozilla/5.0 (iPad; CPU OS 9_3_5 like Mac OS X) AppleWebKit/601.1.46 (KHTML, like Gecko) Version/9.0 Mobile/13G36 Safari/601.1" "exatek.de"
...
show less
Web App Attack
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-29 14:08:07
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.251.19.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.251.19.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 10:08:00.272570 2026] [security2:error] [pid 9587:tid 9605] [client 185.251.19.30:35107] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iamfluff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iamfluff.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amoJQBERNZgI4vMx2ofpHgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-29 09:48:57
(4 weeks ago)
cloudlinux2 fail2ban: 2026-07-29 11:45:06,975 fail2ban.filter [1584]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-29 11:45:06,975 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.132.227.163 - 2026-07-29 11:45:01cloudlinux2 fail2ban: 2026-07-29 11:45:06,980 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 136.144.42.158 - 2026-07-29 11:45:01cloudlinux2 fail2ban: 2026-07-29 11:45:07,078 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 45.132.227.164 - 2026-07-29 11:45:01cloudlinux2 fail2ban: 2026-07-29 11:45:06,978 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 185.251.19.30 - 2026-07-29 11:45:01cloudlinux2 fail2ban: 2026-07-29 11:45:01,513 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 185.251.19.18 - 2026-07-29 11:45:01cloudlinux2 fail2ban: 2026-07-29 11:45:07,176 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 185.251.19.15 - 2026-07-29 11:45:01cloudlinux2 fail2ban: 2026-07-29 11:45:06,481 fail2ban.filter [1584]: INFO [plesk-wordpress] Found 185.251.19.23 - 2026-07-29 11:45:01cloudl
show less
Web App Attack
๐ซ๐ฎ
YF
2026-07-29 09:30:40
(4 weeks ago)
WordPress author enumeration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 09:25:55
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 185.251.19.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.251.19.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 05:25:47.156807 2026] [security2:error] [pid 366954:tid 367039] [client 185.251.19.30:60063] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nicholsinvest.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nicholsinvest.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amnHG5A2SRPKErOc-goIMAAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-07-29 08:19:56
(4 weeks ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-29 06:06:32
(4 weeks ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (88020-196)
Hacking
๐ฎ๐น
CoreTech srl
2026-07-17 09:28:56
(1 month ago)
cloudlinux2 fail2ban: 2026-07-17 11:25:33,152 fail2ban.filter [1598]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-07-17 11:25:33,152 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 185.251.19.30 - 2026-07-17 11:25:32cloudlinux2 fail2ban: 2026-07-17 11:25:33,187 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 185.251.19.30 - 2026-07-17 11:25:32cloudlinux2 fail2ban: 2026-07-17 11:25:41,569 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 185.251.19.19 - 2026-07-17 11:25:41cloudlinux2 fail2ban: 2026-07-17 11:26:36,536 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 103.160.26.112 - 2026-07-17 11:26:36cloudlinux2 fail2ban: 2026-07-17 11:26:58,478 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 103.160.26.112 - 2026-07-17 11:26:58cloudlinux2 fail2ban: 2026-07-17 11:27:58,601 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 45.130.83.133 - 2026-07-17 11:27:58cloudlinux2 fail2ban: 2026-07-17 11:28:17,307 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 103.160.26.112 - 2026-07-17 11:28:17
show less
Web App Attack
๐ฉ๐ช
langenkamp-media
2026-07-17 05:47:38
(1 month ago)
Fail2Ban: Banned from jail nginx-nohome on 3dausdu.de
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-07-15 09:54:11
(1 month ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack