๐ฉ๐ช
dbmwebdesign
2026-09-11 04:35:35
(14 hours ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐ฉ๐ช
dbmwebdesign
2026-09-08 07:05:14
(3 days ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐ฉ๐ช
neckaralb-admin.de
2026-09-08 04:44:39
(3 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
4server
2026-09-08 02:40:55
(3 days ago)
[TueSep0804:40:51.6805052026][security2:error][pid968183:tid968290][client2606:2040:3800:e0::2:0]Mod ...
show more
[TueSep0804:40:51.6805052026][security2:error][pid968183:tid968290][client2606:2040:3800:e0::2:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"gmint.ch\"][uri\"/wp-login.php\"][unique_id\"ap91s24fMJPbosQ-HznfIgAAAUQ\"]\,referer:http://gmint.ch/wp-login.php
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 00:47:36
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 20:47:33.124548 2026] [security2:error] [pid 2270:tid 2270] [client 2606:2040:3800:e0::2:58193] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.247.fishing|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.247.fishing"] [uri "/wp-json/wp/v2/users"] [unique_id "ap9bJRb1uIOknkT90Uw4MAAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 00:16:37
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 20:16:29.840567 2026] [security2:error] [pid 20649:tid 20649] [client 2606:2040:3800:e0::2:58039] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pathpa.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pathpa.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ap9T3UWFThCE8rFSaXyiJQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 23:42:52
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:42:46.642060 2026] [security2:error] [pid 10927:tid 10927] [client 2606:2040:3800:e0::2:53625] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arapi.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arapi.org"] [uri "/"] [unique_id "ap9L9menkJKmN1ShRuekIAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 23:08:56
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:08:52.093338 2026] [security2:error] [pid 5901:tid 5901] [client 2606:2040:3800:e0::2:50119] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jazziiafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jazziiafoundation.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ap9EBNb_R0KIRT9sLXf8qAAAACs"], referer: https://duckduckgo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 22:50:25
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 18:50:19.625142 2026] [security2:error] [pid 9617:tid 9617] [client 2606:2040:3800:e0::2:50926] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aithearchitect.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aithearchitect.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ap8_qxUWnqAlBf8bPjHJigAAAAs"], referer: https://www.google.com/search?q=wordpress
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 18:22:39
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:22:36.668687 2026] [security2:error] [pid 20290:tid 20290] [client 2606:2040:3800:e0::2:50321] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.exhaustthelimits.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.exhaustthelimits.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ap8A7ApJMyb76Hir6CbpvwAAAAw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 18:07:30
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:07:22.190996 2026] [security2:error] [pid 16544:tid 16544] [client 2606:2040:3800:e0::2:65229] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mjkhan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mjkhan.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ap79WgqYsmAN9AXtcjUo6gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 17:03:54
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:03:45.465970 2026] [security2:error] [pid 22174:tid 22174] [client 2606:2040:3800:e0::2:56471] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.theseventhcongregationofladderdayvixens.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.theseventhcongregationofladderdayvixens.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ap7ucfSLzzuuBwy-w2WLRwAAAAE"], referer: https://www.bing.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-07 17:02:43
(4 days ago)
2.908 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
๐ฉ๐ช
LRob
2026-09-07 17:00:42
(4 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /le-groupe/nos-filiales/dg-consultants/wp-login.php | 2026-09-07 17:00 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 15:39:11
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 2606:2040:3800:e0::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 11:39:05.294770 2026] [security2:error] [pid 25583:tid 25583] [client 2606:2040:3800:e0::2:62702] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thebrotherhoodlounge.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thebrotherhoodlounge.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ap7ama_zj8wfvbIhGerIqAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack