๐บ๐ธ
TPI-Abuse
2026-08-24 17:07:19
(8 minutes ago)
(mod_security) mod_security (id:225170) triggered by 3.135.219.169 (ec2-3-135-219-169.us-east-2.comp ...
show more
(mod_security) mod_security (id:225170) triggered by 3.135.219.169 (ec2-3-135-219-169.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 13:07:15.542333 2026] [security2:error] [pid 14468:tid 14468] [client 3.135.219.169:58039] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dvdmasters.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dvdmasters.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aox6Q5Uv18Y2_kdSmVoUfAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-24 17:03:56
(11 minutes ago)
cloudlinux2 fail2ban: 2026-08-24 19:00:12,852 fail2ban.filter [1464]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-24 19:00:12,852 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.24.161 - 2026-08-24 19:00:12cloudlinux2 fail2ban: 2026-08-24 19:00:12,789 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 217.181.80.5 - 2026-08-24 19:00:12cloudlinux2 fail2ban: 2026-08-24 19:00:18,406 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.87.47 - 2026-08-24 19:00:18cloudlinux2 fail2ban: 2026-08-24 19:00:24,680 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.16.129 - 2026-08-24 19:00:24cloudlinux2 fail2ban: 2026-08-24 19:00:32,100 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 217.181.66.166 - 2026-08-24 19:00:31cloudlinux2 fail2ban: 2026-08-24 19:00:30,823 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 195.63.30.212 - 2026-08-24 19:00:29cloudlinux2 fail2ban: 2026-08-24 19:00:34,895 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 3.135.219.169 - 2026-08-24 19:00:34cloud
show less
Web App Attack
Anonymous
2026-08-24 16:55:05
(20 minutes ago)
Web scanner: GET //wp-includes/wlwmanifest.xml
Web App Attack
Hacking
Anonymous
2026-08-24 16:45:28
(30 minutes ago)
Blocked by ModSec and CSF
Port Scan
๐ณ๐ฑ
BlueWire Hosting
2026-08-24 16:43:25
(32 minutes ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 16:41:49
(34 minutes ago)
(mod_security) mod_security (id:225170) triggered by 3.135.219.169 (ec2-3-135-219-169.us-east-2.comp ...
show more
(mod_security) mod_security (id:225170) triggered by 3.135.219.169 (ec2-3-135-219-169.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 12:41:43.120317 2026] [security2:error] [pid 29012:tid 29012] [client 3.135.219.169:56366] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.trinitydent.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.trinitydent.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aox0R6Vwq4uTN-TRa3VY6QAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
mgarofano80
2026-08-24 16:02:21
(1 hour ago)
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-08-24 15:52:44
(1 hour ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 3.135.219.169 (US/United States/ec2-3-135-219- ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 3.135.219.169 (US/United States/ec2-3-135-219-169.us-east-2.compute.amazonaws.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/24 17:52:38 [error] 2696101#2696101: *3171914 access forbidden by rule, client: 3.135.219.169, server: villapardi.it, request: "GET //xmlrpc.php?rsd HTTP/2.0", host: "villapardi.it"
2026/08/24 17:52:39 [error] 2696102#2696102: *3171908 access forbidden by rule, client: 3.135.219.169, server: villapardi.it, request: "GET //?author=1 HTTP/2.0", host: "villapardi.it"
2026/08/24 17:52:39 [error] 2696101#2696101: *3171914 access forbidden by rule, client: 3.135.219.169, server: villapardi.it, request: "GET //?author=2 HTTP/2.0", host: "villapardi.it"
show less
Port Scan
Anonymous
2026-08-24 15:35:11
(1 hour ago)
(wordpress) Failed wordpress login from 3.135.219.169 (US/United States/Ohio/Columbus/ec2-3-135-219- ...
show more
(wordpress) Failed wordpress login from 3.135.219.169 (US/United States/Ohio/Columbus/ec2-3-135-219-169.us-east-2.compute.amazonaws.com/[redacted])
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-24 15:34:54
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 3.135.219.169 (ec2-3-135-219-169.us-east-2.comp ...
show more
(mod_security) mod_security (id:225170) triggered by 3.135.219.169 (ec2-3-135-219-169.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 11:34:48.873477 2026] [security2:error] [pid 12938:tid 12938] [client 3.135.219.169:63675] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||meganmurph.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "meganmurph.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aoxkmITn-vWEbPctypPoAwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-08-24 15:32:14
(1 hour ago)
Bad_requests
Bad Web Bot
๐ธ๐ฌ
Cloudkul Cloudkul
2026-08-24 15:18:26
(1 hour ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
Anonymous
2026-08-24 15:10:13
(2 hours ago)
Automatically blocked after 3 security events. Observed repeated web application attack probes. Sour ...
show more
Automatically blocked after 3 security events. Observed repeated web application attack probes. Source: Cloudflare security controls.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 15:04:52
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 3.135.219.169 (ec2-3-135-219-169.us-east-2.comp ...
show more
(mod_security) mod_security (id:225170) triggered by 3.135.219.169 (ec2-3-135-219-169.us-east-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 11:04:45.899256 2026] [security2:error] [pid 10899:tid 10899] [client 3.135.219.169:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||local639.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "local639.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aoxdje_1hA50ulbYvdDIigAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WeekendWeb
2026-08-24 14:34:21
(2 hours ago)
Wordpress Vunerability attack
Web App Attack