๐ฎ๐น
CoreTech srl
2026-08-21 21:39:01
(2 hours ago)
cloudlinux2 fail2ban: 2026-08-21 23:35:40,806 fail2ban.filter [1480]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-21 23:35:40,806 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 147.90.209.12 - 2026-08-21 23:35:40cloudlinux2 fail2ban: 2026-08-21 23:35:38,816 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 147.90.209.12 - 2026-08-21 23:35:38cloudlinux2 fail2ban: 2026-08-21 23:36:29,872 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 62.238.125.138 - 2026-08-21 23:36:29cloudlinux2 fail2ban: 2026-08-21 23:37:07,840 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.216.252.8 - 2026-08-21 23:37:07cloudlinux2 fail2ban: 2026-08-21 23:37:07,853 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.216.252.8 - 2026-08-21 23:37:07cloudlinux2 fail2ban: 2026-08-21 23:37:07,891 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 172.216.252.8 - 2026-08-21 23:37:07cloudlinux2 fail2ban: 2026-08-21 23:37:07,942 fail2ban.actions [1480]: NOTICE [plesk-modsecurity] Ban 172.216.252.8cloudlinux2 fail2b
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-21 21:32:00
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.125.138 (static.138.125.238.62.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.125.138 (static.138.125.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 17:31:52.093425 2026] [security2:error] [pid 26254:tid 26254] [client 62.238.125.138:17038] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||major33.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "major33.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aojDyElxOeYoXpN5tkLLlAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-21 20:35:06
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 20:23:06
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.125.138 (static.138.125.238.62.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.125.138 (static.138.125.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 16:22:57.380469 2026] [security2:error] [pid 31963:tid 31963] [client 62.238.125.138:20466] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dandksupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dandksupply.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoizoVHcdPOdD1z8oUYIngAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 19:33:25
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.125.138 (static.138.125.238.62.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.125.138 (static.138.125.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 15:33:18.066000 2026] [security2:error] [pid 19343:tid 19343] [client 62.238.125.138:55246] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pschitchat.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pschitchat.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoin_maVcq6GHcxfYh8ALQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-21 16:38:28
(7 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 15:19:16
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.125.138 (static.138.125.238.62.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.125.138 (static.138.125.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 11:19:07.530873 2026] [security2:error] [pid 12670:tid 12699] [client 62.238.125.138:36784] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lapulperiagirona.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lapulperiagirona.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aohsa2yJ1myLuKa37m88aQAAAVg"]
show less
Brute-Force
Bad Web Bot
Web App Attack