🇺🇸
TPI-Abuse
2026-09-08 23:09:08
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 62.4.45.14 (cable-cgn.45.14.mtel.me): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 62.4.45.14 (cable-cgn.45.14.mtel.me): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:09:01.340506 2026] [security2:error] [pid 7987:tid 7987] [client 62.4.45.14:35156] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wallawallafirearmstraining.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wallawallafirearmstraining.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCVjVVvkQOs-MZVzbCQVAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:36:29
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.4.45.14 (cable-cgn.45.14.mtel.me): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 62.4.45.14 (cable-cgn.45.14.mtel.me): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:36:24.293661 2026] [security2:error] [pid 24489:tid 24489] [client 62.4.45.14:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "avaliantlife.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCN6AJtgNOE1-Pa0uGNPgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
london2038.com
2026-09-08 22:27:52
(2 hours ago)
Probing for exploits
62.4.45.14 - - [09/Sep/2026:00:27:43 +0200] "GET /wp-login.php HTTP/2.0" 301 0 ...
show more
Probing for exploits
62.4.45.14 - - [09/Sep/2026:00:27:43 +0200] "GET /wp-login.php HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
62.4.45.14 - - [09/Sep/2026:00:27:49 +0200] "POST /wp-login.php HTTP/2.0" 301 0 "https://v97746.<REDACTED>/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
Anonymous
2026-09-08 22:15:29
(2 hours ago)
Web attack blocked by Wordfence on www.museumvalkenburg.nl (1 hit). Reported by CRMON.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:05:51
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.4.45.14 (cable-cgn.45.14.mtel.me): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 62.4.45.14 (cable-cgn.45.14.mtel.me): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:05:44.464085 2026] [security2:error] [pid 21311:tid 21311] [client 62.4.45.14:5704] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bostonlog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bostonlog.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCGuAx_iod2-GCV0d9LhQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 21:51:15
(3 hours ago)
WordPress Brute Force
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 21:45:14
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.4.45.14 (cable-cgn.45.14.mtel.me): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 62.4.45.14 (cable-cgn.45.14.mtel.me): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:45:10.424132 2026] [security2:error] [pid 1346:tid 1346] [client 62.4.45.14:52156] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||garantaconsulting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "garantaconsulting.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCB5jNRib3CRsNAmxSpOwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 21:33:25
(3 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | 2026-09-08 21:33 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 21:20:15
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 62.4.45.14 (cable-cgn.45.14.mtel.me): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 62.4.45.14 (cable-cgn.45.14.mtel.me): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:20:10.066802 2026] [security2:error] [pid 10488:tid 10488] [client 62.4.45.14:24399] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wealthsec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wealthsec.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqB8CmQ4PxHT2ZB3HXTxVgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lostswordfish.com
2026-09-08 20:56:03
(3 hours ago)
Wordfence waf block on pameganslaw
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 20:13:57
(4 hours ago)
cloudlinux2 fail2ban: 2026-09-08 22:09:21,085 fail2ban.actions [1794]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-08 22:09:21,085 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 34.146.108.178cloudlinux2 fail2ban: 2026-09-08 22:09:20,888 fail2ban.filter [1794]: INFO [plesk-proftpd] Found 46.62.209.187 - 2026-09-08 22:09:20cloudlinux2 fail2ban: 2026-09-08 22:09:48,585 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 62.4.45.14 - 2026-09-08 22:09:48cloudlinux2 fail2ban: 2026-09-08 22:10:34,795 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 23.94.155.21 - 2026-09-08 22:10:33cloudlinux2 fail2ban: 2026-09-08 22:10:34,802 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 23.94.155.35 - 2026-09-08 22:10:33cloudlinux2 fail2ban: 2026-09-08 22:10:37,257 fail2ban.actions [1794]: NOTICE [plesk-proftpd] Unban 125.111.47.184cloudlinux2 fail2ban: 2026-09-08 22:11:00,035 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 91.176.62.188 - 2026-09-08 22:11:00cloudlinux2 fail2ban: 2026-09-08 22:11:15,246 fail2ban
show less
FTP Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 19:01:32
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇫🇷
Zkillu
2026-08-19 21:57:55
(2 weeks ago)
UDP flood (DDoS) vs AS215599: 155 pkts / 0.22 MB to UDP 80/8443 across 102 dst IP(s), 2026-08-19 21: ...
show more
UDP flood (DDoS) vs AS215599: 155 pkts / 0.22 MB to UDP 80/8443 across 102 dst IP(s), 2026-08-19 21:46 to 2026-08-20 00:36 CEST. No legitimate service on these UDP ports (7-day baseline 0 GB/day). Carpet-bombing of a /24, likely botnet-compromised host. Evidence: sFlow + hardware ACL counters.
show less
DDoS Attack
Exploited Host
🇩🇪
HandyTreff.de
2025-12-27 07:18:36
(8 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -21.99 (Bad < -10 / Very Bad < -20 / ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -21.99 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/55.0.2883.87 UBro
show less
Bad Web Bot
Web App Attack
🇩🇪
SMARTNET
2025-11-30 18:38:00
(9 months ago)
Aisuru(Mirai variant) DDoS
DDoS Attack