๐ท๐บ
Agrohim
2026-10-07 17:32:41
(1 hour ago)
Gate I blocked for categories:
DDoS Attack
Ping of Death
Port Scan
Hacking
Brute-Force
๐ท๐บ
akokarev
2026-10-03 08:00:01
(4 days ago)
MikroTik autoban
Port Scan
๐บ๐ธ
TPI-Abuse
2026-01-19 17:32:23
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 19 12:32:16.420859 2026] [security2:error] [pid 26354:tid 26354] [client 5.253.206.40:46586] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chapa.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chapa.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aW5qoFUbc5JVViQmoeKKeAAAAAs"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-14 18:52:30
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 14 13:52:23.195356 2026] [security2:error] [pid 396805:tid 396805] [client 5.253.206.40:36612] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hartflicker.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hartflicker.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWfl59jTbpoqvCqZirF2nQAAACA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-11 10:43:04
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 11 05:42:57.044494 2026] [security2:error] [pid 16834:tid 16834] [client 5.253.206.40:46486] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||baker15.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "baker15.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aWN-sdrjC0KgdyUKlN6_bwAAAAE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-10 17:27:56
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 10 12:27:49.657577 2026] [security2:error] [pid 20791:tid 20791] [client 5.253.206.40:58728] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bofill.name|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bofill.name"] [uri "/wp-json/wp/v2/users"] [unique_id "aWKMFc22PFk488DmOpgzswAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-01-08 01:10:05
(8 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-04 21:21:55
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 04 16:21:51.991925 2026] [security2:error] [pid 16841:tid 16841] [client 5.253.206.40:48776] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||towardthesky.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "towardthesky.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aVrZ70WSZfJp7IKrdv3NgwAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
abuse_IP_reporter
2025-04-25 15:45:20
(1 year ago)
Apr 25 18:12:53 server UFW BLOCK SRC=5.253.206.40 DF PROTO=TCP SPT=51694
Port Scan
๐ฏ๐ต
www.winos.me
2025-04-25 11:03:52
(1 year ago)
Default ban by fail2ban
Brute-Force
Web App Attack
SSH
๐ท๐บ
nyuuzyou
2025-04-25 06:34:21
(1 year ago)
{"action": "connection", "dest_ip": "0.0.0.0", "dest_port": "21", "server": "ftp_server", "src_ip": ...
show more
{"action": "connection", "dest_ip": "0.0.0.0", "dest_port": "21", "server": "ftp_server", "src_ip": "5.253.206.40", "src_port": "50809", "timestamp": "2025-04-25T06:34:03.846804"}
show less
FTP Brute-Force
Port Scan
Anonymous
2025-04-24 00:08:03
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
mnsf
2025-04-23 23:05:34
(1 year ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2025-04-23 22:32:29
(1 year ago)
197 requests with url.path *.env
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-04-23 22:15:56
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 5.253.206.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 23 18:15:52.379744 2025] [security2:error] [pid 3118737:tid 3118737] [client 5.253.206.40:61089] [client 5.253.206.40] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greed.ee"] [uri "/.env"] [unique_id "aAlmmACQnKI7FyQMBwahMQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack