🇮🇹
CoreTech srl
2026-08-25 23:23:57
(1 week ago)
cloudlinux2 fail2ban: 2026-08-26 01:19:44,142 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-26 01:19:44,142 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 104.23.225.51 - 2026-08-26 01:19:43cloudlinux2 fail2ban: 2026-08-26 01:19:44,154 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 104.23.225.50 - 2026-08-26 01:19:43cloudlinux2 fail2ban: 2026-08-26 01:20:17,389 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.86.28 - 2026-08-26 01:20:16cloudlinux2 fail2ban: 2026-08-26 01:20:14,660 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 217.181.73.183 - 2026-08-26 01:20:14cloudlinux2 fail2ban: 2026-08-26 01:20:19,605 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.86.22 - 2026-08-26 01:20:19cloudlinux2 fail2ban: 2026-08-26 01:20:18,760 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.83.58 - 2026-08-26 01:20:18cloudlinux2 fail2ban: 2026-08-26 01:20:16,771 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.64.231 - 2026-08-26 01:20:16c
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-12 11:06:26
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 217.181.83.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 217.181.83.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 07:06:19.574382 2026] [security2:error] [pid 1963358:tid 1963358] [client 217.181.83.58:56980] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||salernospizza.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "salernospizza.com"] [uri "/wp-login.php"] [unique_id "anxTq-DMj1-yfzvB2A9KxwAAAAA"], referer: https://salernospizza.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-08-12 10:33:46
(3 weeks ago)
Web password guessing
Brute-Force
🇷🇴
gtheo99
2026-07-20 12:42:03
(1 month ago)
Unauthorized authenticated cPanel access (port 2083) as part of a rotating proxy pool; credential ab ...
show more
Unauthorized authenticated cPanel access (port 2083) as part of a rotating proxy pool; credential abuse across 19 hosting accounts, phishing page deployment and mail-sending capability probing. 1 requests logged.
show less
Brute-Force
Web App Attack
Hacking
🇮🇩
bps-statistics
2026-06-17 07:28:17
(2 months ago)
WP Login Scan Activities: "2026-06-17T14:28:17.052+07:00" "/wp-login.php" "217.181.83.58" "Mozilla/5 ...
show more
WP Login Scan Activities: "2026-06-17T14:28:17.052+07:00" "/wp-login.php" "217.181.83.58" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:138.0) Gecko/20100101 Firefox/138.0"
show less
Web App Attack
🇦🇹
neo72
2026-05-29 07:03:31
(3 months ago)
Detected malicious activity - bulk block
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-03-13 07:26:09
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 217.181.83.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 217.181.83.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 13 03:26:01.604053 2026] [security2:error] [pid 20812:tid 20812] [client 217.181.83.58:29164] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.blacksheepoffroad.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.blacksheepoffroad.com"] [uri "/wp-login.php"] [unique_id "abO8CfXI-BZHZB8nCds3_AAAABU"], referer: http://blacksheepoffroad.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-09 21:04:43
(5 months ago)
(mod_security) mod_security (id:210350) triggered by 217.181.83.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 217.181.83.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 09 17:04:35.501318 2026] [security2:error] [pid 3108:tid 3108] [client 217.181.83.58:14170] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.fiasdesigns.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.fiasdesigns.com"] [uri "/wp-login.php"] [unique_id "aa814_AtLfBm2P47pM3khQAAAAI"], referer: http://fiasdesigns.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack