Anonymous
2026-08-25 06:46:21
(6 hours ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2026-08-24 14:15:23
(23 hours ago)
Web attack blocked by Wordfence on www.historischarchiefvalkenburg.nl (2 hits). Reported by CRMON.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 12:34:31
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2304:3071::1 (vmi3043071.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2304:3071::1 (vmi3043071.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 08:34:27.741727 2026] [security2:error] [pid 4375:tid 4375] [client 2a02:c207:2304:3071::1:57090] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||naturalacu.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "naturalacu.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aow6U_GlmWHj7teykKFkZgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
ljo
2026-08-24 12:16:52
(1 day ago)
2a02:c207:2304:3071::1 - - [24/Aug/2026:14:16:39 +0200] "GET / HTTP/1.1" 200 15103 "https://rfhl.nu/ ...
show more
2a02:c207:2304:3071::1 - - [24/Aug/2026:14:16:39 +0200] "GET / HTTP/1.1" 200 15103 "https://rfhl.nu/blog/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
2a02:c207:2304:3071::1 - - [24/Aug/2026:14:16:39 +0200] "GET / HTTP/1.1" 200 15103 "https://rfhl.nu/wp/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
2a02:c207:2304:3071::1 - - [24/Aug/2026:14:16:40 +0200] "GET / HTTP/1.1" 200 15103 "https://rfhl.nu/wp/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
2a02:c207:2304:3071::1 - - [24/Aug/2026:14:16:43 +0200] "GET /feed/ HTTP/1.1" 200 909 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
2a02:c207:2304:3071::1 - - [24/Aug/2026:14:16:43 +0200] "GET /feed/ HTTP/1.1" 200 909 "https://rfhl.n
...
show less
DDoS Attack
๐ง๐ช
cmbplf
2026-08-24 12:08:05
(1 day ago)
38.428 requests in 1 hour (3mos1w6d)
Brute-Force
Bad Web Bot
Anonymous
2026-08-24 11:57:29
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-24 11:54:29
(1 day ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 2a02:c207:2304:3071::1 (FR/France/-): 3 in the ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 2a02:c207:2304:3071::1 (FR/France/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/24 13:54:26 [error] 2400077#2400077: *3124486 access forbidden by rule, client: 2a02:c207:2304:3071::1, server: digiampaolosrl.it, request: "GET /?author=2 HTTP/2.0", host: "digiampaolo.it"
2026/08/24 13:54:26 [error] 2400081#2400081: *3124487 access forbidden by rule, client: 2a02:c207:2304:3071::1, server: digiampaolosrl.it, request: "GET /?author=9 HTTP/2.0", host: "digiampaolo.it"
2026/08/24 13:54:26 [error] 2400081#2400081: *3124487 access forbidden by rule, client: 2a02:c207:2304:3071::1, server: digiampaolosrl.it, request: "GET /?author=13 HTTP/2.0", host: "digiampaolo.it"
show less
Port Scan
๐ณ๐ฑ
Site.eu
2026-08-24 11:54:25
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ช๐ธ
alferez
2026-08-24 11:49:45
(1 day ago)
Multiple WP Login Attack
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 11:44:28
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2304:3071::1 (vmi3043071.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2304:3071::1 (vmi3043071.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 07:44:19.591377 2026] [security2:error] [pid 3581987:tid 3582065] [client 2a02:c207:2304:3071::1:44748] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.kettlehill.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aowuk_PbM9m9EnUWc3MxRwAAAdU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-08-24 11:30:39
(1 day ago)
WordPress author enumeration
Web App Attack
๐ฉ๐ช
LRob
2026-08-24 11:28:56
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-24 11:28 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 11:24:44
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2304:3071::1 (vmi3043071.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2304:3071::1 (vmi3043071.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 07:24:35.510993 2026] [security2:error] [pid 13429:tid 13429] [client 2a02:c207:2304:3071::1:52882] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abilityengraving.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abilityengraving.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aowp89Kpx8tZ9WFfAPleXwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-24 01:16:12
(1 day ago)
WordPress login brute-force | path: /wp-login.php | 2026-08-24 01:16 UTC
Brute-Force
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-24 00:58:11
(1 day ago)
(wordpress) Failed wordpress login from 2a02:c207:2304:3071::1 (FR/France/Bas-Rhin/Lauterbourg/vmi30 ...
show more
(wordpress) Failed wordpress login from 2a02:c207:2304:3071::1 (FR/France/Bas-Rhin/Lauterbourg/vmi3043071.contaboserver.net/[redacted]): (CF_ENABLE)
show less
Brute-Force