🇨🇭
backslash
2026-09-08 05:12:00
(10 hours ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 08:14:16
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 213.47.19.10 (213-47-19-10.static.upcbusiness.a ...
show more
(mod_security) mod_security (id:225170) triggered by 213.47.19.10 (213-47-19-10.static.upcbusiness.at): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:14:07.442580 2026] [security2:error] [pid 23667:tid 23667] [client 213.47.19.10:49474] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nationalenq.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nationalenq.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ap5yTwDEOfUodXRiNLp4RAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-08-26 08:10:09
(1 week ago)
Detected mail brute force attack from different servers
Brute-Force
🇨🇦
DRI
2026-08-22 03:47:34
(2 weeks ago)
Web attack/Malicious activity detected
Web App Attack
🇦🇺
screwlooseit.com.au
2026-08-21 18:29:54
(2 weeks ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
AT/Austria/213-47-19-10.static.upcbusiness.at
Web App Attack
🇨🇦
DRI
2026-08-20 19:45:48
(2 weeks ago)
Web attack/Malicious activity detected
Web App Attack
🇨🇦
DRI
2026-08-18 16:55:23
(2 weeks ago)
Web attack/Malicious activity detected
Web App Attack
🇨🇿
ptlab
2026-07-25 02:45:18
(1 month ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-07-23 17:52:07
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 213.47.19.10 (213-47-19-10.static.upcbusiness.a ...
show more
(mod_security) mod_security (id:225170) triggered by 213.47.19.10 (213-47-19-10.static.upcbusiness.at): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 13:51:54.710314 2026] [security2:error] [pid 141372:tid 141372] [client 213.47.19.10:37406] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hodlmoser.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hodlmoser.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "amJUutY9NVn8nbbCUn6yCQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-07-23 00:57:00
(1 month ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇧🇪
voormedia
2026-07-14 12:29:30
(1 month ago)
Accessed trap at '/wp-login.php'
Web App Attack
🇺🇸
helios.live
2026-07-13 19:58:28
(1 month ago)
2026/07/13 19:58:24 [error] 279309#279309: *1667106 FastCGI sent in stderr: "Primary script unknown" ...
show more
2026/07/13 19:58:24 [error] 279309#279309: *1667106 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 213.47.19.10, server: kocerroxy.com, request: "GET /administrator/index.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com", referrer: "https://kocerroxy.com/administrator/"
213.47.19.10 - - [13/Jul/2026:19:58:24 +0000] "GET /administrator/index.php HTTP/1.1" 404 47 "https://kocerroxy.com/administrator/" "Mozilla/5.0 (Linux; Android 13; INKOSI_PRO_4G Build/TP1A.220624.014) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.6834.123 Mobile Safari/537.36"
2026/07/13 19:58:25 [error] 279309#279309: *1667103 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 213.47.19.10, server: kocerroxy.com, request: "GET /wp-login.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
...
show less
Web App Attack
🇭🇺
kranem
2026-06-09 21:00:03
(2 months ago)
Triggered Cloudflare WAF from AT.
Action taken: BLOCK
ASN: 8412 (T-Mobile Austria GmbH)
Protocol: HT ...
show more
Triggered Cloudflare WAF from AT.
Action taken: BLOCK
ASN: 8412 (T-Mobile Austria GmbH)
Protocol: HTTP/1.1 (GET method)
Endpoint: /admin/
Timestamp: 2026-06-09T20:49:53Z
User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) HeadlessChrome/78.0.3904.70 Safari/537.36
show less
Bad Web Bot
🇫🇷
Lunix
2026-06-04 03:05:18
(3 months ago)
Brute-Force
Web App Attack