🇧🇪
taivas.nl
2026-09-05 04:33:15
(9 hours ago)
Many_bad_calls
Web App Attack
🇩🇪
london2038.com
2026-09-05 03:43:10
(10 hours ago)
Attacking WordPress
34.93.229.10 - - [05/Sep/2026:05:43:07 +0200] "POST /wp-login.php HTTP/2.0" 503 ...
show more
Attacking WordPress
34.93.229.10 - - [05/Sep/2026:05:43:07 +0200] "POST /wp-login.php HTTP/2.0" 503 19287 "https://<REDACTED>/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
Anonymous
2026-09-05 03:40:13
(10 hours ago)
WordPress Brute Force
Brute-Force
Anonymous
2026-09-05 03:33:24
(10 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇫🇷
masterguru
2026-09-05 03:30:05
(10 hours ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 34.93.229.10 (10.229.93.34.bc.googleuserconte ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 34.93.229.10 (10.229.93.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-196)
show less
Hacking
🇬🇷
setupgr
2026-09-05 03:11:13
(10 hours ago)
(mod_security) mod_security (id:11000011) triggered by 34.93.229.10 (IN/India/Maharashtra/Mumbai/-/[ ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.93.229.10 (IN/India/Maharashtra/Mumbai/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sat Sep 05 06:11:10.141168 2026] [security2:error] [pid 2981:tid 3047] [remote 34.93.229.10:55596] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 10.229.93.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "babis.photo"] [uri "/graphql"] [unique_id "apuITiQOwjsfTOcOLgeb5wABVg8"]
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-05 01:56:50
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.93.229.10 (10.229.93.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.93.229.10 (10.229.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:56:45.033064 2026] [security2:error] [pid 15832:tid 15832] [client 34.93.229.10:43718] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.joelyaucom.studioyau.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.joelyaucom.studioyau.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apt23QgYg-Co47hW3KrkhAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
FireGuard Server
2026-09-05 01:50:05
(11 hours ago)
Blocked by os-abuseipdb; 7 hits, proto=tcp, ports=443
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-05 01:35:44
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.93.229.10 (10.229.93.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.93.229.10 (10.229.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:35:38.473947 2026] [security2:error] [pid 23779:tid 23779] [client 34.93.229.10:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.southernbroadcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.southernbroadcast.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aptx6ku-io8cxKflqO2IzQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-05 01:26:59
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-05 01:20:08
(12 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-05 01:04:30
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.93.229.10 (10.229.93.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.93.229.10 (10.229.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:04:22.156419 2026] [security2:error] [pid 3631:tid 3631] [client 34.93.229.10:48698] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||leolion.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "leolion.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aptqloQGY3HQCsRJ_lU93QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇷
setupgr
2026-09-05 00:49:34
(12 hours ago)
(mod_security) mod_security (id:11000011) triggered by 34.93.229.10 (IN/India/Maharashtra/Mumbai/-/[ ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.93.229.10 (IN/India/Maharashtra/Mumbai/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sat Sep 05 03:49:29.808841 2026] [security2:error] [pid 3681:tid 3715] [remote 34.93.229.10:44984] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 10.229.93.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "tavernadimitris.com"] [uri "/wp-json/oembed/1.0/embed"] [unique_id "aptnGWBlMaSljN9C3CJAQQAEjwM"]
show less
Port Scan
🇮🇹
CoreTech srl
2026-09-05 00:38:56
(13 hours ago)
cloudlinux2 fail2ban: 2026-09-05 02:33:52,170 fail2ban.filter [1594]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-05 02:33:52,170 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 45.146.55.203 - 2026-09-05 02:33:51cloudlinux2 fail2ban: 2026-09-05 02:34:58,528 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 136.144.43.119 - 2026-09-05 02:34:58cloudlinux2 fail2ban: 2026-09-05 02:35:22,557 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.93.229.10 - 2026-09-05 02:35:22cloudlinux2 fail2ban: 2026-09-05 02:35:33,789 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 164.68.100.166 - 2026-09-05 02:35:33cloudlinux2 fail2ban: 2026-09-05 02:36:11,033 fail2ban.actions [1594]: NOTICE [plesk-wordpress] Unban 141.255.164.71cloudlinux2 fail2ban: 2026-09-05 02:36:16,452 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 155.2.215.17 - 2026-09-05 02:36:16cloudlinux2 fail2ban: 2026-09-05 02:36:28,720 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 131.226.2.227 - 2026-09-05 02:36:28cloudlinux2 fail2ban: 2026
show less
Web App Attack
🇪🇸
arturotrenard
2026-09-05 00:28:10
(13 hours ago)
WordPress attack blocked (wp-defender): exploit-probe: https://hubsmesaclick.com/graphql
Web App Attack