🇩🇪
FeG Deutschland
2026-08-25 03:12:35
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇮🇹
CoreTech srl
2026-08-24 17:48:59
(1 week ago)
cloudlinux2 fail2ban: 2026-08-24 19:44:05,505 fail2ban.filter [1464]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-24 19:44:05,505 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 5.181.171.171 - 2026-08-24 19:44:05cloudlinux2 fail2ban: 2026-08-24 19:44:10,339 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.15.246 - 2026-08-24 19:44:09cloudlinux2 fail2ban: 2026-08-24 19:44:09,154 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 217.181.86.112 - 2026-08-24 19:44:09cloudlinux2 fail2ban: 2026-08-24 19:44:22,156 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 217.181.95.148 - 2026-08-24 19:44:22cloudlinux2 fail2ban: 2026-08-24 19:44:16,412 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.87.190 - 2026-08-24 19:44:16cloudlinux2 fail2ban: 2026-08-24 19:44:22,494 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.95.136 - 2026-08-24 19:44:22cloudlinux2 fail2ban: 2026-08-24 19:44:15,604 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.85.35 - 2026-08-24 19:44:15c
show less
Web App Attack
🇩🇪
iGroupware
2026-08-14 03:40:51
(2 weeks ago)
{"req/ip"=>{:discriminator=>"195.63.20.82", :count=>3, :period=>180, :limit=>500, :epoch_time=>17866 ...
show more
{"req/ip"=>{:discriminator=>"195.63.20.82", :count=>3, :period=>180, :limit=>500, :epoch_time=>1786678851}, "signups/ip"=>{:discriminator=>"195.63.20.82", :count=>1, :period=>3600, :limit=>5, :epoch_time=>1786678851}, "signups/email"=>{:discriminator=>"[email protected] ", :count=>4, :period=>86400, :limit=>2, :epoch_time=>1786678851}}
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-12 05:57:58
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 195.63.20.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 195.63.20.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 01:57:50.572777 2026] [security2:error] [pid 1555908:tid 1555908] [client 195.63.20.82:44162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||salernospizza.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "salernospizza.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "anwLXv7M59cYgKK8AdPcKAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇽
octageeks.com
2026-08-08 04:08:51
(3 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
Anonymous
2026-07-27 15:34:28
(1 month ago)
Credential Stuffing attacks against Microsoft 365
Brute-Force
Anonymous
2026-07-20 20:11:33
(1 month ago)
2026-07-20T22:11:33.499318+02:00 polaris wp(sahpa.co.za)[89601]: Blocked authentication attempt for ...
show more
2026-07-20T22:11:33.499318+02:00 polaris wp(sahpa.co.za)[89601]: Blocked authentication attempt for Lisa from 195.63.20.82
...
show less
Brute-Force
Web App Attack
🇷🇴
gtheo99
2026-07-19 07:26:09
(1 month ago)
Unauthorized authenticated cPanel access (port 2083) as part of a rotating proxy pool; credential ab ...
show more
Unauthorized authenticated cPanel access (port 2083) as part of a rotating proxy pool; credential abuse across 19 hosting accounts, phishing page deployment and mail-sending capability probing. 1 requests logged.
show less
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-05-16 15:09:47
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.20.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.20.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 11:09:41.223777 2026] [security2:error] [pid 24318:tid 24318] [client 195.63.20.82:50132] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.humbliaslaw.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.humbliaslaw.com"] [uri "/wp-login.php"] [unique_id "agiItfl_MUtNG3iqoMheygAAAAg"], referer: http://humbliaslaw.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-12 17:23:55
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 195.63.20.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 195.63.20.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Mar 12 13:23:48.636029 2026] [security2:error] [pid 10548:tid 10548] [client 195.63.20.82:20134] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bacona.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bacona.org"] [uri "/wp-json/wp/v2/users"] [unique_id "abL2pHq3lqlIC4TO4QfRmAAAAA8"], referer: https://bacona.org
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-10 11:44:34
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 195.63.20.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 195.63.20.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 10 07:44:26.903308 2026] [security2:error] [pid 12488:tid 12488] [client 195.63.20.82:42022] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "abAEGlH0H2Ht2XBJvIAHPQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-02 03:59:31
(6 months ago)
(mod_security) mod_security (id:210350) triggered by 195.63.20.82 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 195.63.20.82 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 01 22:59:25.637682 2026] [security2:error] [pid 10224:tid 10241] [client 195.63.20.82:14076] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.sallykimmel.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.sallykimmel.com"] [uri "/wp-login.php"] [unique_id "aaULHWq2GrHELANFyeMTIAAAAI4"], referer: http://sallykimmel.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack