๐จ๐ฆ
Anymous
2026-08-23 07:17:05
(1 hour ago)
SYN Flood
DDoS Attack
๐ฉ๐ช
maxpower
2026-08-23 06:29:57
(2 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.49.99 (FI/Finland/static.99.49.238.62.c ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.49.99 (FI/Finland/static.99.49.238.62.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 62.238.49.99 - - [23/Aug/2026:08:29:54 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 6470 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=anvcgabruzzo.it
show less
Port Scan
๐บ๐ธ
NXTwoThou
2026-08-23 05:06:27
(3 hours ago)
get /
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-08-23 03:05:54
(5 hours ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /wp-json/wp/v2/users | Pays: FI | UA: Mozilla/5.0 (compa ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /wp-json/wp/v2/users | Pays: FI | UA: Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)
show less
Hacking
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-23 02:03:17
(7 hours ago)
*Port Scan* detected from 62.238.49.99 (FI/Finland/Uusimaa/Helsinki/static.99.49.238.62.clients.your ...
show more
*Port Scan* detected from 62.238.49.99 (FI/Finland/Uusimaa/Helsinki/static.99.49.238.62.clients.your-server.de).
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-22 22:50:28
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.49.99 (static.99.49.238.62.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.49.99 (static.99.49.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 18:50:23.281276 2026] [security2:error] [pid 3968:tid 3968] [client 62.238.49.99:43178] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gisur.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gisur.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoonr9U1RT1qppvfkzZNuAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-22 21:03:57
(12 hours ago)
cloudlinux2 fail2ban: 2026-08-22 22:59:00,958 fail2ban.filter [1480]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-22 22:59:00,958 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 104.234.19.77 - 2026-08-22 22:59:00cloudlinux2 fail2ban: 2026-08-22 22:59:52,661 fail2ban.actions [1480]: NOTICE [plesk-wordpress] Unban 104.28.208.86cloudlinux2 fail2ban: 2026-08-22 23:00:09,252 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 45.132.115.106 - 2026-08-22 23:00:09cloudlinux2 fail2ban: 2026-08-22 23:00:09,253 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 45.132.115.106 - 2026-08-22 23:00:09cloudlinux2 fail2ban: 2026-08-22 23:00:15,478 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 185.223.152.32 - 2026-08-22 23:00:15cloudlinux2 fail2ban: 2026-08-22 23:00:09,381 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 45.132.115.104 - 2026-08-22 23:00:09cloudlinux2 fail2ban: 2026-08-22 23:00:19,803 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 185.223.152.32 - 2026-08-22 23:00:19cloudlinux2 fail2ban: 2026
show less
Web App Attack
๐จ๐ฆ
Anymous
2026-08-22 20:56:27
(12 hours ago)
GET /data:. HTTP/1.1 404 5262 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.co ...
show more
GET /data:. HTTP/1.1 404 5262 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)"
show less
Port Scan
Web App Attack
Anonymous
2026-08-22 18:25:11
(14 hours ago)
Bot / seems abusive / Apache connections: 45
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ฌ๐ง
ISPLtd
2026-08-22 17:48:25
(15 hours ago)
62.238.49.99 - - [22/Aug/2026:14:48:24 -0300] "GET /wp-content/plugins/woocommerce/assets/css/woocom ...
show more
62.238.49.99 - - [22/Aug/2026:14:48:24 -0300] "GET /wp-content/plugins/woocommerce/assets/css/woocommerce-smallscreen.css
62.238.49.99 - - [22/Aug/2026:14:48:24 -0300] "GET /wp-content/themes/superb-ecommerce/style.css
...
show less
Hacking
Web App Attack
๐ฌ๐ง
consul.to
2026-08-22 14:53:01
(18 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 14:35:09
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.49.99 (static.99.49.238.62.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.49.99 (static.99.49.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 10:35:03.666045 2026] [security2:error] [pid 13472:tid 13472] [client 62.238.49.99:64820] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||genevainvestors.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "genevainvestors.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aomzl08aAlKb5a8vuoJMjwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-22 14:34:39
(18 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.49.99 (FI/Finland/static.99.49.238.62.c ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 62.238.49.99 (FI/Finland/static.99.49.238.62.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 62.238.49.99 - - [22/Aug/2026:16:34:33 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 951 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=matteodinicola.it
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-22 13:57:01
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.238.49.99 (static.99.49.238.62.clients.your- ...
show more
(mod_security) mod_security (id:225170) triggered by 62.238.49.99 (static.99.49.238.62.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 09:56:55.240358 2026] [security2:error] [pid 24036:tid 24036] [client 62.238.49.99:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||upskirtcrazy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "upskirtcrazy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aomqp9nHRs6VcD7xh9OcNwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
YF
2026-08-22 11:31:03
(21 hours ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack