๐ณ๐ฟ
Tripwire
2026-07-01 09:10:44
(4 weeks ago)
Wordpress login attempts
Brute-Force
Web App Attack
๐ฉ๐ช
UlrikeLG
2026-06-26 07:36:00
(1 month ago)
[wordpress] unauthorised access attempts via wp_login
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-06 19:44:45
(1 month ago)
[SatJun0621:44:42.5833962026][security2:error][pid2760027:tid2760084][client194.99.27.46:0]ModSecuri ...
show more
[SatJun0621:44:42.5833962026][security2:error][pid2760027:tid2760084][client194.99.27.46:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"craniosacraltherapy.ch\"][uri\"/xmlrpc.php\"][unique_id\"aiR4qssNGD2Rrq7mq4vI2AAAAFA\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-05-22 17:06:26
(2 months ago)
Blocked: Reason='Possible SQL injection activity (39/60 min)'; Requests=39
SQL Injection
๐บ๐ธ
mind5t0rm
2026-02-06 14:04:30
(5 months ago)
(WPLOGIN) WP Login Attack 194.99.27.46 (US/United States/-): 3 in the last 3600 secs; Ports: *; Dire ...
show more
(WPLOGIN) WP Login Attack 194.99.27.46 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 194.99.27.46 - - [06/Feb/2026:21:04:23 +0700] "GET /wp-login.php HTTP/2.0" 200 2451 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 Safari/605.1.15"
194.99.27.46 - - [06/Feb/2026:21:04:26 +0700] "GET /wp-login.php?wp_lang=en_US HTTP/2.0" 200 2451 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.207 Safari/537.36"
194.99.27.46 - - [06/Feb/2026:21:04:28 +0700] "POST /wp-login.php?wp_lang=en_US HTTP/2.0" 302 0 "https://zerowaterthailand.com/wp-login.php?wp_lang=en_US" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.6367.207 Safari/537.36"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-01-22 18:27:13
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 194.99.27.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 194.99.27.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 13:27:06.632627 2026] [security2:error] [pid 3095:tid 3095] [client 194.99.27.46:38305] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||d-sinema.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "d-sinema.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aXJr-gLjZtpN2hEZDXDDPQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2025-12-18 07:02:28
(7 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 194.99.27.46 (NL/The Netherlands/-): 1 in the ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 194.99.27.46 (NL/The Netherlands/-): 1 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
nowyouknow
2025-12-14 08:53:21
(7 months ago)
(From [email protected] ) Hello there,
I ran a specific analysis on your website and fo ...
show more
(From [email protected] ) Hello there,
I ran a specific analysis on your website and found a solid path to increase your monthly organic traffic by 200% to 300% within the next 4 months.
Most websites in your niche are missing 40% of their potential customers simply due to fixable & poor keyword targeting.
I have a plan ready to fix this.
Can I share it with you?
Regards,
Juliet
show less
Phishing
Web Spam
๐ฉ๐ช
Packets-Decreaser.NET
2025-11-17 16:50:44
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
๐ฉ๐ช
LRob
2025-06-15 19:00:06
(1 year ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-04-06 06:25:03
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐จ๐ฆ
wil.com
2025-04-01 10:35:21
(1 year ago)
GlobalProtect login attempts with user pvasavd.
VPN IP
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-03-30 09:02:51
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 194.99.27.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211120) triggered by 194.99.27.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 30 05:02:46.079960 2025] [security2:error] [pid 15704:tid 15810] [client 194.99.27.46:14313] [client 194.99.27.46] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||brucejoell.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/canto/includes/lib/download.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brucejoell.com"] [uri "/wp-content/plugins/canto/includes/lib/download.php"] [unique_id "Z-kItrDwRCrc3Ql-5bpDMQAAAhM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-28 16:58:58
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 194.99.27.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211120) triggered by 194.99.27.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 28 12:58:50.813507 2025] [security2:error] [pid 19092:tid 19092] [client 194.99.27.46:32881] [client 194.99.27.46] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||bonvivantorganics.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/wp-super-cache/js/cache-loader.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bonvivantorganics.com"] [uri "/wp-content/plugins/wp-super-cache/js/cache-loader.php"] [unique_id "Z-bVSuCuLfh2yFyyjnlbpgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-24 04:30:17
(1 year ago)
(mod_security) mod_security (id:211120) triggered by 194.99.27.46 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:211120) triggered by 194.99.27.46 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 24 00:30:08.443686 2025] [security2:error] [pid 16695:tid 16695] [client 194.99.27.46:47597] [client 194.99.27.46] ModSecurity: Access denied with code 403 (phase 2). Match of "endsWith /modules/paypal/express_checkout/payment.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "29"] [id "211120"] [rev "12"] [msg "COMODO WAF: Remote File Inclusion Attack||beckyslittlecreations.com|F|2"] [data "Matched Data: http://adguard.digital/payload/index.php? found within REQUEST_FILENAME: /wp-content/plugins/wp-super-cache/js/cache-loader.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "beckyslittlecreations.com"] [uri "/wp-content/plugins/wp-super-cache/js/cache-loader.php"] [unique_id "Z-Df0ADAO2BYuzHf29ofEAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack