π«π·
Jean Valjean
2026-09-16 00:36:52
(2 days ago)
Fail2ban Caboom : wp-login.php Bruteforce
Brute-Force
Web App Attack
Anonymous
2026-09-16 00:34:00
(2 days ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=17
Hacking
ππ·
bubausluge
2026-09-16 00:32:11
(2 days ago)
Blocked by https://aegis.hr β WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-09-16 ...
show more
Blocked by https://aegis.hr β WAF: ModSec rule match - (MITRE T1190), 1 attempts, Period: 2026-09-16 00:10:26 to 2026-09-16 00:10:26
show less
Web App Attack
Hacking
π¬π§
Apache
2026-09-16 00:28:56
(2 days ago)
(mod_security) mod_security (id:210410) triggered by 63.180.207.0 (DE/Germany/ec2-63-180-207-0.eu-ce ...
show more
(mod_security) mod_security (id:210410) triggered by 63.180.207.0 (DE/Germany/ec2-63-180-207-0.eu-central-1.compute.amazonaws.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
πΈπͺ
eagle
2026-09-16 00:23:15
(2 days ago)
63.180.207.0 - - [16/Sep/2026:00:23:15 +0000] "" 400 0 "-" "-"
...
Port Scan
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 00:08:36
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 63.180.207.0 (ec2-63-180-207-0.eu-central-1.com ...
show more
(mod_security) mod_security (id:225170) triggered by 63.180.207.0 (ec2-63-180-207-0.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:08:32.324903 2026] [security2:error] [pid 13029:tid 13029] [client 63.180.207.0:50998] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||seagrovesrealty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "seagrovesrealty.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqneACDCxR4UDzU-38sIBQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 23:34:31
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 63.180.207.0 (ec2-63-180-207-0.eu-central-1.com ...
show more
(mod_security) mod_security (id:225170) triggered by 63.180.207.0 (ec2-63-180-207-0.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 19:34:25.603715 2026] [security2:error] [pid 3119:tid 3119] [client 63.180.207.0:60005] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ohwaitiforgot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ohwaitiforgot.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqnWAU0fbcUsUSt-cz8_dgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
tinect
2026-09-15 23:08:56
(2 days ago)
This IP was detected by CrowdSec triggering tinect/http-sensitive-file-probe
Web App Attack
πΊπΈ
agenciahypelab.com.br
2026-09-15 23:01:33
(2 days ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-09-15 22:59:25
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 63.180.207.0 (ec2-63-180-207-0.eu-central-1.com ...
show more
(mod_security) mod_security (id:225170) triggered by 63.180.207.0 (ec2-63-180-207-0.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:59:21.245578 2026] [security2:error] [pid 24188:tid 24318] [client 63.180.207.0:52183] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ward-bergerhouse.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ward-bergerhouse.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqnNyakbounfB1-xo4rs7wAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Stara
2026-09-15 22:55:59
(2 days ago)
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kinesk ...
show more
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kineskinja)
show less
Hacking
Brute-Force
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-15 22:50:05
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π¨π
zynex
2026-09-15 22:32:17
(2 days ago)
URL Probing: /site/wp-includes/wlwmanifest.xml
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 22:29:08
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 63.180.207.0 (ec2-63-180-207-0.eu-central-1.com ...
show more
(mod_security) mod_security (id:225170) triggered by 63.180.207.0 (ec2-63-180-207-0.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:29:01.275681 2026] [security2:error] [pid 30416:tid 30416] [client 63.180.207.0:65233] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mobileonlinecasinos.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mobileonlinecasinos.co"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqnGrVKL6Z9ea26nVyYqIQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 22:10:12
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 63.180.207.0 (ec2-63-180-207-0.eu-central-1.com ...
show more
(mod_security) mod_security (id:225170) triggered by 63.180.207.0 (ec2-63-180-207-0.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:10:05.070442 2026] [security2:error] [pid 11189:tid 11189] [client 63.180.207.0:55845] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bickleton.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bickleton.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqnCPc20gSI64ioxAUSZ5gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack