🇺🇸
TPI-Abuse
2026-09-09 07:00:54
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 212.73.159.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.73.159.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 03:00:47.387859 2026] [security2:error] [pid 7358:tid 7358] [client 212.73.159.120:44384] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||intothebigempty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "intothebigempty.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqEEH18NqaBLHDzVid_7bwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 02:12:22
(6 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-login.php | 2026-09-09 02:1 ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-login.php | 2026-09-09 02:12 UTC
show less
Port Scan
Web App Attack
🇫🇷
ingroscart.it
2026-09-09 01:27:59
(7 hours ago)
(wordpress) Failed wordpress login from 212.73.159.120 (BG/Bulgaria/-/-/-/[redacted])
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 22:08:06
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.73.159.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.73.159.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:08:00.251452 2026] [security2:error] [pid 30847:tid 30847] [client 212.73.159.120:52350] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||batesstrategygroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "batesstrategygroup.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCHQBaPoKjXIUp5Up3vfgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:46:16
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.73.159.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.73.159.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:46:08.849372 2026] [security2:error] [pid 9767:tid 9767] [client 212.73.159.120:38196] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.webseographics.smogsandiego.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.webseographics.smogsandiego.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBX8PLibiJoyKn24sd5xgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 14:18:58
(18 hours ago)
cloudlinux2 fail2ban: 2026-09-08 16:13:43,400 fail2ban.filter [1794]: INFO [recidive] Fou ...
show more
cloudlinux2 fail2ban: 2026-09-08 16:13:43,400 fail2ban.filter [1794]: INFO [recidive] Found 117.99.80.202 - 2026-09-08 16:13:43cloudlinux2 fail2ban: 2026-09-08 16:13:43,245 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 117.99.80.202 - 2026-09-08 16:13:43cloudlinux2 fail2ban: 2026-09-08 16:13:43,393 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Ban 117.99.80.202cloudlinux2 fail2ban: 2026-09-08 16:14:15,992 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 142.111.152.38 - 2026-09-08 16:14:15cloudlinux2 fail2ban: 2026-09-08 16:14:15,517 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 142.111.152.69 - 2026-09-08 16:14:14cloudlinux2 fail2ban: 2026-09-08 16:14:58,682 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 173.239.213.89 - 2026-09-08 16:14:58cloudlinux2 fail2ban: 2026-09-08 16:15:20,821 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 185.251.19.72 - 2026-09-08 16:15:20cloudlinux2 fail2ban: 2026-09-08
show less
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 13:11:44
(19 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:48:24
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.73.159.120 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 212.73.159.120 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:48:16.218792 2026] [security2:error] [pid 15572:tid 15572] [client 212.73.159.120:52657] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dancingbearprinting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dancingbearprinting.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAEEFdcUOvNV-2wHxHkKgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack