๐บ๐ธ
TPI-Abuse
2026-08-31 22:16:41
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a0b:4140:a574::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0b:4140:a574::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:16:37.379231 2026] [security2:error] [pid 8697:tid 8697] [client 2a0b:4140:a574::2:35546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "howwegothere.info"] [uri "/.env.local"] [unique_id "apX9RZISkrKTllB3IUSsTAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MAM
2026-07-26 06:54:34
(1 month ago)
IMAP/Submission attempt
Hacking
๐ฉ๐ช
ksol-hostmaster
2026-07-24 20:56:10
(1 month ago)
Jul 24 22:56:10 ksol dovecot[2253]: auth-worker(54595): conn unix:auth-worker (uid=143): auth-worker ...
show more
Jul 24 22:56:10 ksol dovecot[2253]: auth-worker(54595): conn unix:auth-worker (uid=143): auth-worker<4>: sql(anonymized@email,2a0b:4140:a574::2,<hQ8zmmFX4uIqC0FApXQAAAAAAAAAAAAC>): unknown user (given password: I-AM-A-SUCKER-USING-A-WRONG-PASSWORD)
...
show less
Brute-Force
๐ฉ๐ช
ksol-hostmaster
2026-07-16 09:24:41
(1 month ago)
Jul 16 11:24:41 ksol dovecot[78357]: auth-worker(34691): conn unix:auth-worker (uid=143): auth-worke ...
show more
Jul 16 11:24:41 ksol dovecot[78357]: auth-worker(34691): conn unix:auth-worker (uid=143): auth-worker<2>: sql(anonymized@email,2a0b:4140:a574::2,<lKKCArdWAI0qC0FApXQAAAAAAAAAAAAC>): unknown user (given password: I-AM-A-SUCKER-USING-A-WRONG-PASSWORD)
...
show less
Brute-Force
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-16 05:02:46
(1 month ago)
HTTP flood against /retreat-corp on Apache webserver
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-07-02 21:36:49
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 2a0b:4140:a574::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0b:4140:a574::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 17:36:43.995254 2026] [security2:error] [pid 13274:tid 13274] [client 2a0b:4140:a574::2:47884] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ecodesarrollourbano.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ecodesarrollourbano.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "akbZ67arJjRdYwCOPiVyOAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-07-02 20:09:41
(1 month ago)
(wordpress) Failed wordpress login from 2a0b:4140:a574::2 (GB/United Kingdom/England/London/-/[redac ...
show more
(wordpress) Failed wordpress login from 2a0b:4140:a574::2 (GB/United Kingdom/England/London/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-24 13:45:15
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0b:4140:a574::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0b:4140:a574::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 09:45:08.696659 2026] [security2:error] [pid 22326:tid 22326] [client 2a0b:4140:a574::2:38288] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||toybud.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "toybud.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajvfZMtRInKBPLBVOM5aNgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 12:25:17
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0b:4140:a574::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0b:4140:a574::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 08:25:09.147039 2026] [security2:error] [pid 1381:tid 1381] [client 2a0b:4140:a574::2:52972] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||haroparquet.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "haroparquet.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajvMpXCP2ugd682mrSYI7AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-24 11:12:41
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 2a0b:4140:a574::2 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0b:4140:a574::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 07:12:36.845924 2026] [security2:error] [pid 32565:tid 32565] [client 2a0b:4140:a574::2:33540] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flymarlin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flymarlin.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aju7pPDYBmapejIg_V2lYQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-06-20 04:33:02
(2 months ago)
Brute-force/Enumeration: Multiple login attempts for non-existent mail accounts (Honeytrap).
Email Spam
Brute-Force
๐บ๐ธ
Vano Ganzzz
2026-06-17 18:36:41
(2 months ago)
Triggered Cloudflare WAF (l7ddos) from GB.
Action taken: BLOCK
ASN: 210644 (AEZA GROUP LLC)
Protocol ...
show more
Triggered Cloudflare WAF (l7ddos) from GB.
Action taken: BLOCK
ASN: 210644 (AEZA GROUP LLC)
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /
Timestamp: 2026-06-17T18:36:41Z
Ray ID: a0d42944cada366c
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36
show less
DDoS Attack
Bad Web Bot