๐ฉ๐ช
ger-stg-sifi1
2026-08-16 06:09:08
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฌ๐ง
ebandwagon
2026-08-16 01:20:04
(1 week ago)
Wordpress brute force. Multiple attemps
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-15 05:51:22
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฌ๐ง
foxxelabs
2026-08-14 18:08:16
(1 week ago)
Automated report from FoxxeLabs Sentinel. Path probed: /wp-login.php | Project: anseo | Reason(s): K ...
show more
Automated report from FoxxeLabs Sentinel. Path probed: /wp-login.php | Project: anseo | Reason(s): Known exploit path: /wp-login.php | User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.5 S
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-07 22:00:16
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-06.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-07 14:49:13
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 10:49:06.504876 2026] [security2:error] [pid 18317:tid 18317] [client 2a02:4780:12:bc9e::1:48092] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gemco-mfg.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gemco-mfg.com"] [uri "/"] [unique_id "anXwYjgbMTq_liGiRnJG4gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 13:41:54
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 09:41:45.356619 2026] [security2:error] [pid 11015:tid 11015] [client 2a02:4780:12:bc9e::1:36320] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||garantaconsulting.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "garantaconsulting.com"] [uri "/"] [unique_id "anXgme3VmGKyVXwxbsJpDQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 12:54:28
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 08:54:24.157564 2026] [security2:error] [pid 1758237:tid 1758237] [client 2a02:4780:12:bc9e::1:44798] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gdpeters.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gdpeters.com"] [uri "/"] [unique_id "anXVgGaw-zd07Gs8ODv8sQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 11:22:29
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 07:22:24.009853 2026] [security2:error] [pid 11406:tid 11406] [client 2a02:4780:12:bc9e::1:41654] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gbaker.us|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gbaker.us"] [uri "/"] [unique_id "anW_8GJ50rko_8vriwVtGgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Viveronese
2026-08-07 10:04:39
(2 weeks ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 08:40:46
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:40:42.139181 2026] [security2:error] [pid 3732458:tid 3732458] [client 2a02:4780:12:bc9e::1:56368] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||geauxcowboys.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "geauxcowboys.com"] [uri "/"] [unique_id "anWaCoKJwEs2bQOZd9lCpQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 08:00:15
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 04:00:08.989161 2026] [security2:error] [pid 156041:tid 156041] [client 2a02:4780:12:bc9e::1:42944] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||garon.us|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "garon.us"] [uri "/"] [unique_id "anWQiFCoxbt8t60DQzytngAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 07:22:51
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 03:22:44.854823 2026] [security2:error] [pid 1707421:tid 1707421] [client 2a02:4780:12:bc9e::1:40400] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||georgelaceysales.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "georgelaceysales.com"] [uri "/"] [unique_id "anWHxCBtAtGPor9mRvVpnAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 05:42:20
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 01:42:12.926023 2026] [security2:error] [pid 3791007:tid 3791007] [client 2a02:4780:12:bc9e::1:32918] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||gdrankin.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gdrankin.com"] [uri "/"] [unique_id "anVwNPoAfH16joOQvz8WXwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-07 03:54:18
(3 weeks ago)
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.ne ...
show more
(mod_security) mod_security (id:210350) triggered by 2a02:4780:12:bc9e::1 (mail.marutienterprises.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 23:54:11.348101 2026] [security2:error] [pid 1001925:tid 1001928] [client 2a02:4780:12:bc9e::1:59166] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||visionforandfromchildren.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "visionforandfromchildren.org"] [uri "/"] [unique_id "anVW4yR3pXflugjlBWo_VQAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack