๐ฎ๐น
CoreTech srl
2026-08-25 23:38:56
(9 hours ago)
cloudlinux2 fail2ban: 2026-08-26 01:34:11,959 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-26 01:34:11,959 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 104.23.225.178 - 2026-08-26 01:34:11cloudlinux2 fail2ban: 2026-08-26 01:34:11,947 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 104.23.225.178 - 2026-08-26 01:34:11cloudlinux2 fail2ban: 2026-08-26 01:34:49,186 fail2ban.actions [1464]: NOTICE [plesk-modsecurity] Unban 35.188.151.45cloudlinux2 fail2ban: 2026-08-26 01:34:49,091 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 217.181.76.189 - 2026-08-26 01:34:49cloudlinux2 fail2ban: 2026-08-26 01:34:54,599 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.82.92 - 2026-08-26 01:34:54cloudlinux2 fail2ban: 2026-08-26 01:34:52,009 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 213.108.0.253 - 2026-08-26 01:34:51cloudlinux2 fail2ban: 2026-08-26 01:34:57,478 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.12.47 - 2026-08-26 01:34:57cloudlinux2 fail2ban:
show less
Web App Attack
๐จ๐ฆ
DRI
2026-07-29 10:32:15
(3 weeks ago)
Web attack/Malicious activity detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 23:42:57
(4 weeks ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 19:42:53.642586 2026] [security2:error] [pid 233555:tid 233555] [client 213.108.0.253:19431] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||red-jacket.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "red-jacket.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amk-fTEnVf9nX-Jd2QYtkQAAABs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-25 16:44:41
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 12:44:36.675994 2026] [security2:error] [pid 1814828:tid 1814828] [client 213.108.0.253:12775] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lbee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lbee.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amTn9NZUBjdD4rHAEyDleQAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
DRI
2026-07-24 02:34:43
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
Anonymous
2026-07-19 19:22:19
(1 month ago)
FPROCO WEBEXPLOIT 213.108.0.253 (213.108.0.253)
Web App Attack
๐จ๐ฆ
DRI
2026-07-18 22:57:26
(1 month ago)
Web attack/Malicious activity detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-15 20:26:29
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 16:26:24.913553 2026] [security2:error] [pid 10389:tid 10389] [client 213.108.0.253:25079] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||keysenterprise.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "keysenterprise.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alfs8NljG1ZxelCVldJ7kAAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 20:09:57
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 16:09:49.512350 2026] [security2:error] [pid 29336:tid 29336] [client 213.108.0.253:44281] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||seanevans.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "seanevans.com"] [uri "/wp-json/wp/v2/users"] [unique_id "alVGDR7bbkRwVF_rDRVlJwAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
electronico
2026-07-11 18:53:55
(1 month ago)
213.108.0.253 - - [12/Jul/2026:05:53:54 +1100] "POST /xmlrpc.php HTTP/1.1" 301 4054 "-" "Apache-Http ...
show more
213.108.0.253 - - [12/Jul/2026:05:53:54 +1100] "POST /xmlrpc.php HTTP/1.1" 301 4054 "-" "Apache-HttpClient/4.5.13 (Java/11.0.31)"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-24 10:10:17
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 24 06:10:12.276214 2026] [security2:error] [pid 519308:tid 519308] [client 213.108.0.253:60767] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nekstlevel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nekstlevel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acJjBANqv1sx3BYmAUbtnwAAAA4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-23 23:10:01
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 213.108.0.253 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 23 19:09:53.732189 2026] [security2:error] [pid 28693:tid 28693] [client 213.108.0.253:58611] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kratka.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kratka.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acHIQX9gIHQXAqhHDcNMWQAAABU"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kjaerulff
2026-03-22 18:53:38
(5 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
ambor
2026-03-06 02:37:03
(5 months ago)
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Web App Attack
Anonymous
2025-11-28 12:14:51
(8 months ago)
wordpress-trap
Web App Attack