🇧🇪
cmbplf
2026-09-07 05:47:26
(41 minutes ago)
1.814 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
🇸🇪
OnTheEdge
2026-09-03 17:56:40
(3 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇮🇹
CoreTech srl
2026-08-16 15:48:56
(3 weeks ago)
cloudlinux2 fail2ban: 2026-08-16 17:45:18,069 fail2ban.filter [1791]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-16 17:45:18,069 fail2ban.filter [1791]: INFO [plesk-modsecurity] Found 182.8.161.15 - 2026-08-16 17:45:18cloudlinux2 fail2ban: 2026-08-16 17:47:12,996 fail2ban.filter [1791]: INFO [plesk-wordpress] Found 65.111.23.68 - 2026-08-16 17:47:12cloudlinux2 fail2ban: 2026-08-16 17:47:15,029 fail2ban.filter [1791]: INFO [plesk-modsecurity] Found 182.8.161.15 - 2026-08-16 17:47:14cloudlinux2 fail2ban: 2026-08-16 17:47:16,547 fail2ban.filter [1791]: INFO [plesk-wordpress] Found 65.111.23.78 - 2026-08-16 17:47:16cloudlinux2 fail2ban: 2026-08-16 17:47:17,722 fail2ban.filter [1791]: INFO [plesk-wordpress] Found 45.3.42.39 - 2026-08-16 17:47:17cloudlinux2 fail2ban: 2026-08-16 17:47:14,114 fail2ban.filter [1791]: INFO [plesk-wordpress] Found 65.111.22.97 - 2026-08-16 17:47:13cloudlinux2 fail2ban: 2026-08-16 17:47:15,293 fail2ban.filter [1791]: INFO [plesk-wordpress] Found 65.111.22.33 - 2026-08-16 17:47:15cloudlinux2 fa
show less
Web App Attack
🇦🇹
neo72
2026-08-06 15:57:40
(1 month ago)
Detected malicious activity - bulk block
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-08-06 01:40:03
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-08-03 07:10:02
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇩🇪
Packets-Decreaser.NET
2025-12-31 00:58:26
(8 months ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam
🇺🇸
TPI-Abuse
2025-11-24 08:47:47
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.42.39 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.42.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 03:47:43.101188 2025] [security2:error] [pid 12864:tid 12864] [client 45.3.42.39:24601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.riser-astrology.com"] [uri "/.env"] [unique_id "aSQbrzw3v7lnlNuNfRzxNwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 06:02:10
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.42.39 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.42.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 24 01:02:00.231854 2025] [security2:error] [pid 27797:tid 27797] [client 45.3.42.39:46601] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.intermixx.com"] [uri "/.env"] [unique_id "aSP02OEXASYaBRwS-3hfYwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-11-24 04:58:31
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 45.3.42.39 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210492) triggered by 45.3.42.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Nov 23 23:58:14.920306 2025] [security2:error] [pid 3965259:tid 3965339] [client 45.3.42.39:9113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aapm.eu"] [uri "/.env"] [unique_id "aSPl5sHsvdKIeQe-cM8YKgAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-30 14:35:35
(10 months ago)
WordPress Brute Force
Brute-Force
🇩🇪
Marc
2025-10-29 19:06:01
(10 months ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2025-10-28 11:18:36
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 45.3.42.39 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.42.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 28 07:18:29.332629 2025] [security2:error] [pid 22514:tid 22514] [client 45.3.42.39:42101] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||atame.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "atame.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQCmhd9sh8D7O4QivWklbgAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
F242
2025-03-20 10:39:14
(1 year ago)
Wordpress Login or XMLRPC abuse
Web App Attack
🇺🇸
TPI-Abuse
2025-03-01 05:00:42
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.3.42.39 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 45.3.42.39 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 01 00:00:35.505672 2025] [security2:error] [pid 5692:tid 5692] [client 45.3.42.39:37961] [client 45.3.42.39] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ficciones.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ficciones.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z8KUc2tKIQSwOCFC9h7_1QAAAAE"], referer: https://ficciones.com
show less
Brute-Force
Bad Web Bot
Web App Attack