🇮🇹
CoreTech srl
2026-09-09 02:33:57
(3 hours ago)
cloudlinux2 fail2ban: 2026-09-09 04:29:19,316 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-09 04:29:19,316 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 45.92.229.81 - 2026-09-09 04:29:19cloudlinux2 fail2ban: 2026-09-09 04:30:05,963 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 173.239.240.156 - 2026-09-09 04:30:05cloudlinux2 fail2ban: 2026-09-09 04:30:10,652 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 173.239.240.156 - 2026-09-09 04:30:10cloudlinux2 fail2ban: 2026-09-09 04:30:17,649 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 124.217.24.130cloudlinux2 fail2ban: 2026-09-09 04:30:29,156 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 117.187.54.90 - 2026-09-09 04:30:29cloudlinux2 fail2ban: 2026-09-09 04:30:51,407 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 170.101.96.39 - 2026-09-09 04:30:51cloudlinux2 fail2ban: 2026-09-09 04:30:53,950 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 92.119.36.60 - 2026-09-09 04:30:52cloudlinux2 fail2ban:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:04:28
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:04:21.674725 2026] [security2:error] [pid 20029:tid 20029] [client 212.59.30.145:44558] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sneedvillefarmersmarket.daisydoesoap.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sneedvillefarmersmarket.daisydoesoap.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC-pdomoYSL27N0nhRL0AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 01:04:06
(4 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:56:15
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:56:08.869866 2026] [security2:error] [pid 19269:tid 19269] [client 212.59.30.145:35508] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wp.sonnyvo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wp.sonnyvo.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCgmErk5mKHTylNaXYzKgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:18:49
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:18:43.632596 2026] [security2:error] [pid 23799:tid 23799] [client 212.59.30.145:57608] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||americanureport.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "americanureport.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCX0ygoC9PMxGgoNl8SsQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:10:05
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:09:58.864221 2026] [security2:error] [pid 1065:tid 1138] [client 212.59.30.145:44164] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lamcohomecare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lamcohomecare.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCHtjIf5E13drevx2g9gAAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
cwytech
2026-09-08 21:11:36
(8 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-08 20:21:24
(9 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:12:31
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:12:25.763195 2026] [security2:error] [pid 766:tid 766] [client 212.59.30.145:43618] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||odinathletes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "odinathletes.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBeGUIRo1uOEEQdI0E85AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 18:45:03
(11 hours ago)
Web attack blocked by Wordfence on vestingstadvalkenburg.nl (1 hit). Reported by CRMON.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:29:44
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 212.59.30.145 (ignet-212-59-30-145.ignet.lt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:29:40.025753 2026] [security2:error] [pid 1246:tid 1276] [client 212.59.30.145:49456] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ward-bergerhouse.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ward-bergerhouse.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBUFAxm6dtPr82acgoWyQAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 17:21:39
(12 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
kosada.com
2026-09-07 00:30:02
(2 days ago)
Repeated requests classified as pathological web bot behavior, for example: /[redacted]/search?f%5B0 ...
show more
Repeated requests classified as pathological web bot behavior, for example: /[redacted]/search?f%5B0%5D=digest_key_terms%3A336&f%5B1%5D=digest_key_terms%3A519&f%5B2%5D=digest_key_terms%3A522&field_article_edition%5B504%5D=504&field_key_terms%5B386%5D=386 (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36")
show less
DDoS Attack
Bad Web Bot
🇺🇸
gui-ying233
2026-09-02 16:35:51
(6 days ago)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0. ...
show more
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/144.0.0.0 Safari/537.36
show less
Bad Web Bot
🇺🇸
gui-ying233
2026-08-30 00:52:20
(1 week ago)
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Sa ...
show more
Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot