๐ฌ๐ง
AvonleaConsulting
2026-08-23 22:58:34
(2 days ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 15:31:00
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 11:30:55.559221 2026] [security2:error] [pid 29275:tid 29275] [client 2.29.10.40:17116] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tonydelov.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tonydelov.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aosSL-wjMaJWHPdVMWOLXAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-23 15:07:02
(3 days ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: FI, Attack patterns: Auto ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: FI, Attack patterns: Automated scanning
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 13:37:39
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 09:37:35.620497 2026] [security2:error] [pid 2003837:tid 2003847] [client 2.29.10.40:21738] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sparkhypnotherapy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sparkhypnotherapy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aor3n3AgPPG8lXRlnJne2AAAAUM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 12:42:00
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:41:56.290006 2026] [security2:error] [pid 27906:tid 27906] [client 2.29.10.40:15624] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||richmondrents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "richmondrents.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aorqlPoYry4AbeSdhphndQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
ScamAware
2026-08-23 12:15:27
(3 days ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot / scanner behavior). Hits from same IP in last 60 minutes: 1. Unique request paths counted internally: 1. Cloudflare action: managed_challenge. Cloudflare source: botFight.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-23 12:03:37
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:03:32.684126 2026] [security2:error] [pid 1413:tid 1413] [client 2.29.10.40:46212] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prostar.industries|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prostar.industries"] [uri "/wp-json/wp/v2/users"] [unique_id "aorhlHkbmHtuToB3s6F7lQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-08-23 11:50:03
(3 days ago)
Unrecognised attack
IoT Targeted
๐ฎ๐น
CoreTech srl
2026-08-23 09:53:57
(3 days ago)
cloudlinux2 fail2ban: 2026-08-23 11:49:15,676 fail2ban.filter [1496]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-23 11:49:15,676 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 209.87.169.234 - 2026-08-23 11:49:14cloudlinux2 fail2ban: 2026-08-23 11:49:16,049 fail2ban.filter [1496]: INFO [plesk-modsecurity] Found 180.153.236.120 - 2026-08-23 11:49:15cloudlinux2 fail2ban: 2026-08-23 11:49:12,634 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 136.144.42.217 - 2026-08-23 11:49:12cloudlinux2 fail2ban: 2026-08-23 11:49:19,910 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 209.87.169.234 - 2026-08-23 11:49:19cloudlinux2 fail2ban: 2026-08-23 11:49:32,436 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 107.23.15.129 - 2026-08-23 11:49:32cloudlinux2 fail2ban: 2026-08-23 11:49:53,600 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 91.193.232.127 - 2026-08-23 11:49:53cloudlinux2 fail2ban: 2026-08-23 11:51:10,924 fail2ban.filter [1496]: INFO [plesk-wordpress] Found 172.98.32.213 - 2026-08-23 11:51:10c
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 09:04:40
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 05:04:36.496356 2026] [security2:error] [pid 21303:tid 21303] [client 2.29.10.40:21370] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||naominixon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "naominixon.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoq3pKgGUPgXykMZYCnzWQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐น
Evag Touf
2026-08-23 09:02:17
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 2.29.10.40 (DE/Germany/static.40.10.29. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 2.29.10.40 (DE/Germany/static.40.10.29.2.clients.your-server.de)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-23 07:19:32
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 03:19:28.525922 2026] [security2:error] [pid 20357:tid 20357] [client 2.29.10.40:46136] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lightupaustralia.com.au|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lightupaustralia.com.au"] [uri "/wp-json/wp/v2/users"] [unique_id "aoqfAEdDcOaMjAWdds4lngAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-23 06:44:36
(3 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2.29.10.40 (FI/Finland/static.40.10.29.2.clien ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2.29.10.40 (FI/Finland/static.40.10.29.2.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2.29.10.40 - - [23/Aug/2026:08:44:34 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 7845 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=mediaqualitylab.com
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-23 05:47:23
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-serv ...
show more
(mod_security) mod_security (id:225170) triggered by 2.29.10.40 (static.40.10.29.2.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 01:47:15.480935 2026] [security2:error] [pid 26079:tid 26079] [client 2.29.10.40:21720] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lajoze.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lajoze.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoqJYyZldUpv8XX5pRRe2QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-23 04:55:56
(3 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2.29.10.40 (FI/Finland/static.40.10.29.2.clien ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 2.29.10.40 (FI/Finland/static.40.10.29.2.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2.29.10.40 - - [23/Aug/2026:06:55:51 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 1416 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=kleos81.com
show less
Port Scan