Anonymous
2026-08-29 09:27:03
(47 minutes ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 07:53:05
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 198.54.114.190 (server122.web-hosting.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 198.54.114.190 (server122.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:53:00.435004 2026] [security2:error] [pid 24587:tid 24587] [client 198.54.114.190:48674] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.toepferlab.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.toepferlab.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apKP3FuN5vaRgWZcmV1AbQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-08-29 06:31:34
(3 hours ago)
198.54.114.190 - - [29/Aug/2026:08:31:32 +0200] "POST /wp-login.php HTTP/1.1" 200 15983 "https://han ...
show more
198.54.114.190 - - [29/Aug/2026:08:31:32 +0200] "POST /wp-login.php HTTP/1.1" 200 15983 "https://hans.wp-knowhow.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
198.54.114.190 - - [29/Aug/2026:08:31:32 +0200] "POST /wp-login.php HTTP/1.1" 200 15985 "https://hans.wp-knowhow.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
198.54.114.190 - - [29/Aug/2026:08:31:32 +0200] "POST /wp-login.php HTTP/1.1" 200 15979 "https://hans.wp-knowhow.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-29 02:53:38
(7 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ท
SpaceHost-Server
2026-08-29 02:49:57
(7 hours ago)
198.54.114.190 - - [29/Aug/2026:04:49:55 +0200] "POST /wp-login.php HTTP/1.1" 200 9515 "https://star ...
show more
198.54.114.190 - - [29/Aug/2026:04:49:55 +0200] "POST /wp-login.php HTTP/1.1" 200 9515 "https://start-the-loop.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
198.54.114.190 - - [29/Aug/2026:04:49:55 +0200] "POST /wp-login.php HTTP/1.1" 200 9516 "https://start-the-loop.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
198.54.114.190 - - [29/Aug/2026:04:49:55 +0200] "POST /wp-login.php HTTP/1.1" 200 9521 "https://start-the-loop.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-29 01:09:25
(9 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ท
Lunix
2026-08-28 21:28:39
(12 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:52:14
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 198.54.114.190 (server122.web-hosting.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 198.54.114.190 (server122.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:52:06.743196 2026] [security2:error] [pid 12907:tid 12907] [client 198.54.114.190:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ipv6.local639.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ipv6.local639.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apHKxhmlB_53IGxfZCt5SgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 07:53:38
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 198.54.114.190 (server122.web-hosting.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 198.54.114.190 (server122.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 03:53:32.577243 2026] [security2:error] [pid 18820:tid 18820] [client 198.54.114.190:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||duct.cloudex.click|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "duct.cloudex.click"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apE-fC_ns8sf_zwnR2UMhgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
SpamStopper
2026-08-28 04:18:40
(1 day ago)
Fail2Ban - WP Spoofing
Port Scan
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-28 03:08:58
(1 day ago)
cloudlinux2 fail2ban: 2026-08-28 05:03:48,156 fail2ban.actions [1478]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-28 05:03:48,156 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] 77.90.185.230 already bannedcloudlinux2 fail2ban: 2026-08-28 05:03:47,893 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 77.90.185.230 - 2026-08-28 05:03:47cloudlinux2 fail2ban: 2026-08-28 05:03:52,281 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 198.54.114.97 - 2026-08-28 05:03:52cloudlinux2 fail2ban: 2026-08-28 05:04:04,004 fail2ban.filter [1478]: WARNING [plesk-wordpress] Detected a log entry 1m 1s before the current time in operation mode. This looks like a latency problem. Treating such entries as if they just happened.cloudlinux2 fail2ban: 2026-08-28 05:04:04,005 fail2ban.filter [1478]: WARNING [plesk-apache-badbot] Detected a log entry 1m 1s before the current time in operation mode. This looks like a latency problem. Treating such entries as if they just happened.cloudlinux2 fail2ban: 2026-08-28 05:04:04,005 fail2ban.filter [1478]: WA
show less
Web App Attack
Bad Web Bot
๐ฎ๐น
CoreTech srl
2026-08-27 16:48:56
(1 day ago)
cloudlinux2 fail2ban: 2026-08-27 18:44:02,568 fail2ban.actions [1775]: NOTICE [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-27 18:44:02,568 fail2ban.actions [1775]: NOTICE [plesk-wordpress] Unban 129.225.125.127cloudlinux2 fail2ban: 2026-08-27 18:44:10,926 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 68.65.120.167 - 2026-08-27 18:44:10cloudlinux2 fail2ban: 2026-08-27 18:44:16,456 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 102.221.29.107 - 2026-08-27 18:44:16cloudlinux2 fail2ban: 2026-08-27 18:44:29,048 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 104.219.248.36 - 2026-08-27 18:44:28cloudlinux2 fail2ban: 2026-08-27 18:44:37,382 fail2ban.actions [1775]: NOTICE [plesk-modsecurity] Unban 34.70.242.96cloudlinux2 fail2ban: 2026-08-27 18:45:17,458 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 198.54.114.37 - 2026-08-27 18:45:16cloudlinux2 fail2ban: 2026-08-27 18:46:02,574 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 102.221.29.107 - 2026-08-27 18:46:02cloudlinux2 fail2ban: 2026-08-27 18:46:19,9
show less
Web App Attack
๐ฒ๐น
Malta
2026-08-27 14:51:24
(1 day ago)
198.54.114.190 - - [27/Aug/2026:16:51:24 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows ...
show more
198.54.114.190 - - [27/Aug/2026:16:51:24 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-27 12:38:25
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 198.54.114.190 (server122.web-hosting.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 198.54.114.190 (server122.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:38:19.702031 2026] [security2:error] [pid 3673:tid 3673] [client 198.54.114.190:33564] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grandpont-house.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grandpont-house.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apAvuxXEKDBuBae9xbeN-wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-08-27 12:28:03
(1 day ago)
Wordfence waf block on registrymatters
Web App Attack