Anonymous
2026-06-27 05:11:44
(17 hours ago)
<jail> banned by fail2ban
Brute-Force
Web App Attack
๐ฌ๐ง
BRHosting
2026-06-27 04:49:02
(18 hours ago)
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-27 04:03:08
(19 hours ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 197.221.2.30 (ZA/South Africa/www30.cpt1.host ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 197.221.2.30 (ZA/South Africa/www30.cpt1.host-h.net): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ฉ๐ช
Hazzard
2026-06-27 03:37:16
(19 hours ago)
(wordpress) Failed wordpress login from 197.221.2.30 (ZA/South Africa/-/-/www30.cpt1.host-h.net/[red ...
show more
(wordpress) Failed wordpress login from 197.221.2.30 (ZA/South Africa/-/-/www30.cpt1.host-h.net/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐ฉ๐ช
LRob.fr
2026-06-27 03:15:15
(19 hours ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ฌ๐ง
spamverify.com
2026-06-27 00:15:59
(22 hours ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
Anonymous
2026-06-26 23:40:02
(23 hours ago)
| CMS scanner: 3 domains targeted (CMS (WordPress or Joomla) login attempt.)
Web App Attack
Hacking
SQL Injection
๐ฆ๐บ
FSB.ru - Is it?
2026-06-26 22:57:05
(1 day ago)
Brute force login for honeypot user accounts
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 22:13:28
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 197.221.2.30 (www30.cpt1.host-h.net): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 197.221.2.30 (www30.cpt1.host-h.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 18:13:23.361945 2026] [security2:error] [pid 3070:tid 3070] [client 197.221.2.30:36816] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||plazahacienda.imerka.com.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "plazahacienda.imerka.com.mx"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aj75g8F3SPdeMenr14Y9LQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tecnicorioja
2026-06-26 22:00:56
(1 day ago)
wp-login attack [26/Jun/2026:16:31:10
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 21:54:00
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 197.221.2.30 (www30.cpt1.host-h.net): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 197.221.2.30 (www30.cpt1.host-h.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 17:53:54.310129 2026] [security2:error] [pid 27553:tid 27553] [client 197.221.2.30:52882] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||comicpreservation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "comicpreservation.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aj708o7DurW8kFculJkIkAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
tilellit.pro
2026-06-26 21:39:54
(1 day ago)
Fail2Ban banned 197.221.2.30 for security violations in jail wp-armour. Log: 2026/06/26 21:39:54 [er ...
show more
Fail2Ban banned 197.221.2.30 for security violations in jail wp-armour. Log: 2026/06/26 21:39:54 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 197.221.2.30 | Target: wplogin" , client: 197.221.2.30, server: [REDACTED], request: "POST /wp-login.php HTTP/2.0", upstream: [REDACTED], host: [REDACTED], referrer: "https://espsformacion.com/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
TPI-Abuse
2026-06-26 20:55:34
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 197.221.2.30 (www30.cpt1.host-h.net): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 197.221.2.30 (www30.cpt1.host-h.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 16:55:30.437410 2026] [security2:error] [pid 25965:tid 25965] [client 197.221.2.30:55542] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||38floorsupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "38floorsupply.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aj7nQkN0KkQ7yWApGDs1KAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
spamverify.com
2026-06-26 19:38:35
(1 day ago)
Honeypot Hit: WordPress Users
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-26 18:52:04
(1 day ago)
Wordfence waf block on restore georgia
Web App Attack