๐บ๐ธ
TPI-Abuse
2026-07-25 07:35:31
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 37.215.37.41 (mm-41-37-215-37.mfilial.dynamic.p ...
show more
(mod_security) mod_security (id:225170) triggered by 37.215.37.41 (mm-41-37-215-37.mfilial.dynamic.pppoe.byfly.by): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 25 03:35:25.237367 2026] [security2:error] [pid 3307862:tid 3307862] [client 37.215.37.41:8456] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lexie.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lexie.org"] [uri "/wp-json/wp/v2/users"] [unique_id "amRnPaURgn5ABTRsA9K4QgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 23:49:32
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 37.215.37.41 (mm-41-37-215-37.mfilial.dynamic.p ...
show more
(mod_security) mod_security (id:225170) triggered by 37.215.37.41 (mm-41-37-215-37.mfilial.dynamic.pppoe.byfly.by): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 19:49:24.623671 2026] [security2:error] [pid 966738:tid 966738] [client 37.215.37.41:6131] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||oxygenfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "oxygenfarm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amP6BMgQBHrPZIq1yltQygAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 23:38:01
(9 hours ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Ha1fdan
2026-07-24 22:25:05
(10 hours ago)
37.215.37.41 - - [24/Jul/2026:18:55:09 +0200] "GET /wp-login.php HTTP/2.0" 404 36 "-" "Mozilla/5.0 ( ...
show more
37.215.37.41 - - [24/Jul/2026:18:55:09 +0200] "GET /wp-login.php HTTP/2.0" 404 36 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36"
37.215.37.41 - - [25/Jul/2026:00:24:39 +0200] "GET /wp-login.php HTTP/2.0" 404 36 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
37.215.37.41 - - [25/Jul/2026:00:24:58 +0200] "GET /wp-login.php HTTP/2.0" 404 36 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
37.215.37.41 - - [25/Jul/2026:00:25:01 +0200] "GET /wp-login.php HTTP/2.0" 404 36 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
37.215.37.41 - - [25/Jul/2026:00:25:04 +0200] "POST /wp-login.php HTTP/2.0" 404 36 "https://h6.dk/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 22:10:12
(11 hours ago)
| [Dangerous/Belarus] Aggressive IP 37.215.37.41 (~30 hits). Type: DoS Defender- Web server 400 erro ...
show more
| [Dangerous/Belarus] Aggressive IP 37.215.37.41 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐จ๐ญ
backslash
2026-07-24 18:21:00
(14 hours ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ซ๐ฎ
inlink.ltd
2026-07-24 17:13:30
(16 hours ago)
Known malicious PHP file or CMS probe
Web App Attack
๐ฌ๐ง
consul.to
2026-07-24 16:39:46
(16 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
kosada.com
2026-06-29 11:06:25
(3 weeks ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
๐ณ๐ฑ
exxos
2025-08-28 22:07:15
(10 months ago)
Attacks with Bad user agents
Hacking
๐ง๐พ
sashan
2023-08-17 05:07:37
(2 years ago)
Aug 17 08:07:37 debian kernel: [107935.437190] nftables: JAIL-CIFS IN=wan OUT= MAC= SRC=37.215.37.41 ...
show more
Aug 17 08:07:37 debian kernel: [107935.437190] nftables: JAIL-CIFS IN=wan OUT= MAC= SRC=37.215.37.41 DST=xxx.xxx.xxx.xxx LEN=52 TOS=0x00 PREC=0x00 TTL=121 ID=3813 DF PROTO=TCP SPT=57408 DPT=445 WINDOW=8192 RES=0x00 SYN URGP=0
...
show less
Port Scan