๐ฉ๐ช
FeG Deutschland
2026-07-22 17:16:58
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐จ๐ฟ
ptlab
2026-07-22 14:45:36
(5 hours ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 06:12:00
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.228 (srv156.hostserv.co.za): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.228 (srv156.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 02:11:55.538293 2026] [security2:error] [pid 507429:tid 507508] [client 41.185.8.228:45562] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||datuinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "datuinc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amBfK8mG5bySG7-WVPVe6gAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-22 04:13:27
(15 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 04:03:33
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.228 (srv156.hostserv.co.za): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.228 (srv156.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 22 00:03:26.868879 2026] [security2:error] [pid 762465:tid 762465] [client 41.185.8.228:34538] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hsoftwaresystems.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hsoftwaresystems.net"] [uri "/wp-json/wp/v2/users"] [unique_id "amBBDrKm9Nk9AQWeMQxk7QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-22 01:05:31
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 41.185.8.228 (srv156.hostserv.co.za): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 41.185.8.228 (srv156.hostserv.co.za): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 21:05:24.447383 2026] [security2:error] [pid 639660:tid 639660] [client 41.185.8.228:38914] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||eduempowermentsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "eduempowermentsolutions.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "amAXVCKW24R51awgCc6EygAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
nomzamo
2026-07-21 22:52:32
(21 hours ago)
Fail2Ban reported: nginx-noscript
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-07-21 15:32:15
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
๐ง๐ฌ
HighWay
2026-07-21 00:07:08
(1 day ago)
41.185.8.228 - - [21/Jul/2026:00:04:27 +0000] "GET /wp-login.php HTTP/1.1" 200 6991 "-" "Mozilla/5.0 ...
show more
41.185.8.228 - - [21/Jul/2026:00:04:27 +0000] "GET /wp-login.php HTTP/1.1" 200 6991 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
41.185.8.228 - - [21/Jul/2026:00:04:29 +0000] "POST /wp-login.php HTTP/1.1" 200 7069 "https://www.jobseu.org/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36"
41.185.8.228 - - [21/Jul/2026:00:07:07 +0000] "POST /xmlrpc.php HTTP/1.1" 200 4663 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_6_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/147.0.7871.34 Mobile/15E148 Safari/604.1"
...
show less
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2025-11-01 23:09:00
(8 months ago)
Unauthorized connection attempt
Brute-Force
Anonymous
2025-08-30 02:20:08
(10 months ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
R.G.
2025-08-29 07:43:15
(10 months ago)
(XMLRPCorWHATEVER) Get lost please 41.185.8.228 (ZA/South Africa/srv156.hostserv.co.za): 3 in the la ...
show more
(XMLRPCorWHATEVER) Get lost please 41.185.8.228 (ZA/South Africa/srv156.hostserv.co.za): 3 in the last 900 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ซ๐ท
Kenshin869
2025-08-29 01:11:39
(10 months ago)
Wordpress unauthorized access attempt
Brute-Force
๐ฉ๐ช
LRob
2025-08-28 08:18:58
(10 months ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐ฉ๐ช
Hazzard
2025-08-27 14:26:34
(10 months ago)
(wordpress) Failed wordpress login from 41.185.8.228 (ZA/South Africa/-/-/srv156.hostserv.co.za/[red ...
show more
(wordpress) Failed wordpress login from 41.185.8.228 (ZA/South Africa/-/-/srv156.hostserv.co.za/[redacted])
show less
Brute-Force