๐ฆ๐น
joe-abuse
2026-09-01 01:38:16
(6 hours ago)
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-31 0 ...
show more
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-31 00:00:21. Events: 1. Reported by ipdb-security/fitzgerald.eu
show less
Web App Attack
Anonymous
2026-08-31 23:12:48
(8 hours ago)
"GET /wp-login.php HTTP/1.1"
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 12:51:30
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 08:51:24.981714 2026] [security2:error] [pid 7514:tid 7514] [client 213.199.32.224:51066] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||amywoodruff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "amywoodruff.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apV4zG3xXhXjky5-xo1yZAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sfmet-admin
2026-08-31 12:20:19
(19 hours ago)
213.199.32.224 - - [31/Aug/2026:12:20:18 +0000] "GET /wp-login.php HTTP/2.0" 200 33 "http://sfmet.co ...
show more
213.199.32.224 - - [31/Aug/2026:12:20:18 +0000] "GET /wp-login.php HTTP/2.0" 200 33 "http://sfmet.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
...
show less
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-31 11:29:44
(20 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 10:39:05
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 06:38:57.429269 2026] [security2:error] [pid 31891:tid 31923] [client 213.199.32.224:35730] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||woodamy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "woodamy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apVZwdTUJoPcF9c0M8afLAAAAVM"], referer: http://woodamy.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-08-31 10:11:05
(21 hours ago)
(y3) Failed access -byebye- from 213.199.32.224 (FR/France/vmd191431.contaboserver.net): (CF_ENABLE ...
show more
(y3) Failed access -byebye- from 213.199.32.224 (FR/France/vmd191431.contaboserver.net): (CF_ENABLE)
show less
Hacking
๐ฉ๐ช
iNetWorker
2026-08-31 08:51:15
(23 hours ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 08:30:43
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:30:35.860126 2026] [security2:error] [pid 25330:tid 25330] [client 213.199.32.224:35482] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ashleycroft.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ashleycroft.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apU7q12bJhXdlvkwCC7XUwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 08:08:49
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:08:41.444538 2026] [security2:error] [pid 26354:tid 26354] [client 213.199.32.224:51758] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.billymitchell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.billymitchell.com"] [uri "/wordpress/wp-json/wp/v2/users"] [unique_id "apU2ieGsMC8cL9oL8GGRoQAAAAE"], referer: http://www.billymitchell.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-08-31 08:07:11
(23 hours ago)
Wordpress hacking attempt
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 07:52:42
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:52:34.611506 2026] [security2:error] [pid 15884:tid 15884] [client 213.199.32.224:37008] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||j3pr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "j3pr.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apUywuu2Gao4aLjprBzthwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-08-31 07:21:36
(1 day ago)
L0ss Honeypot: WordPress login access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐ฉ๐ช
on-com
2026-08-31 07:20:49
(1 day ago)
URL scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 06:20:28
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 213.199.32.224 (vmd191431.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 02:20:24.769461 2026] [security2:error] [pid 2933:tid 2933] [client 213.199.32.224:34680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||superlamb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "superlamb.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apUdKIYDVOQylQOjZ_vshAAAAA0"], referer: http://superlamb.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack