Anonymous
2026-09-21 03:50:03
(3 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐น๐ท
ycoskun41
2026-09-19 11:59:29
(1 day ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-18 06:00:02
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฒ๐ฝ
octageeks.com
2026-09-18 04:06:19
(3 days ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
๐ฉ๐ช
todix
2026-09-17 23:36:15
(3 days ago)
WebAttack or semilar from 64.227.172.95
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:58:18
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 64.227.172.95 (digiof.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:225170) triggered by 64.227.172.95 (digiof.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:58:12.360725 2026] [security2:error] [pid 5612:tid 5612] [client 64.227.172.95:45752] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lyldevelopers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lyldevelopers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqvj5DdrLzOlUPmPlwhVNwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-17 11:09:45
(3 days ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking
๐ซ๐ฎ
stinpriza
2026-09-17 09:52:55
(3 days ago)
WP Authentication attempt for unknown user
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 09:37:38
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 64.227.172.95 (digiof.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:225170) triggered by 64.227.172.95 (digiof.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:37:35.855659 2026] [security2:error] [pid 6858:tid 6858] [client 64.227.172.95:59106] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||the-it-man.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "the-it-man.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqu03_cSpo-RRSKKHUwbbgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 08:24:12
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 64.227.172.95 (digiof.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:225170) triggered by 64.227.172.95 (digiof.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 04:24:08.123368 2026] [security2:error] [pid 18518:tid 18612] [client 64.227.172.95:46052] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||41bravo.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "41bravo.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqujqKh_p-AxsrBG0vAheQAAAko"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-17 07:42:45
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 07:38:25
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 64.227.172.95 (digiof.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:225170) triggered by 64.227.172.95 (digiof.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 03:38:17.770602 2026] [security2:error] [pid 1121:tid 1121] [client 64.227.172.95:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||upskirtcrazy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "upskirtcrazy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aquY6Yg82GdrddmUzbkrVwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 07:20:49
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 64.227.172.95 (digiof.com): 1 in the last 300 s ...
show more
(mod_security) mod_security (id:225170) triggered by 64.227.172.95 (digiof.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 03:20:45.280901 2026] [security2:error] [pid 18941:tid 18941] [client 64.227.172.95:58772] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bervick.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bervick.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aquUzUZ7WqP7QrFfIHYlgAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-17 05:55:45
(4 days ago)
64.227.172.95 - - [17/Sep/2026:05:53:29 +0000] "GET /login?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/ ...
show more
64.227.172.95 - - [17/Sep/2026:05:53:29 +0000] "GET /login?author=2 HTTP/1.1" 403 1165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" "-" edge="64.227.172.95"
64.227.172.95 - - [17/Sep/2026:05:54:04 +0000] "GET /login?author=3 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:97.0) Gecko/20100101 Firefox/97.0" "-" edge="64.227.172.95"
64.227.172.95 - - [17/Sep/2026:05:54:17 +0000] "GET /login?author=4 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:62.0) Gecko/20100101 Firefox/62.0" "-" edge="64.227.172.95"
64.227.172.95 - - [17/Sep/2026:05:54:20 +0000] "GET /login?author=5 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:77.0) Gecko/20100101 Firefox/77.0" "-" edge="64.227.172.95"
64.227.172.95 - - [17/Sep/2026:05:54:43 +0000] "GET /login?author=6 HTTP/1.1" 403 1166 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:57.0) Gecko/20100101 Firefox/57.0" "-" edge="64.227.172.95"
...
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-17 04:56:59
(4 days ago)
Probing websites for vulnerabilities
Web App Attack