๐ฌ๐ง
gigatech
2026-07-20 06:55:03
(7 hours ago)
Webserver Probing
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-19 19:35:35
(18 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-19 16:43:57
(21 hours ago)
cloudlinux2 fail2ban: 2026-07-19 18:38:50,237 fail2ban.filter [1918]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-19 18:38:50,237 fail2ban.filter [1918]: INFO [plesk-modsecurity] Found 196.74.175.225 - 2026-07-19 18:38:50cloudlinux2 fail2ban: 2026-07-19 18:38:49,141 fail2ban.filter [1918]: INFO [plesk-modsecurity] Found 34.182.174.30 - 2026-07-19 18:38:48cloudlinux2 fail2ban: 2026-07-19 18:39:19,507 fail2ban.filter [1918]: INFO [plesk-wordpress] Found 144.76.97.62 - 2026-07-19 18:39:19cloudlinux2 fail2ban: 2026-07-19 18:39:41,963 fail2ban.filter [1918]: INFO [plesk-wordpress] Found 75.119.132.40 - 2026-07-19 18:39:41cloudlinux2 fail2ban: 2026-07-19 18:39:45,451 fail2ban.filter [1918]: INFO [plesk-apache] Found 34.73.28.200 - 2026-07-19 18:39:45cloudlinux2 fail2ban: 2026-07-19 18:39:49,066 fail2ban.filter [1918]: INFO [plesk-modsecurity] Found 34.73.28.200 - 2026-07-19 18:39:49cloudlinux2 fail2ban: 2026-07-19 18:39:49,186 fail2ban.filter [1918]: INFO [plesk-apache] Found 34.73.28.200 - 2026-07-19 18:39:49cloudlinux2
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-13 03:24:05
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-07-09 15:06:47
(1 week ago)
angleseaarthouse.com.au:443 75.119.132.40 - - [10/Jul/2026:01:06:44 +1000] "GET /?author=2 HTTP/1.1" ...
show more
angleseaarthouse.com.au:443 75.119.132.40 - - [10/Jul/2026:01:06:44 +1000] "GET /?author=2 HTTP/1.1" 404 188817 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-09 14:52:12
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 75.119.132.40 (server170.serverinternal.site): ...
show more
(mod_security) mod_security (id:210350) triggered by 75.119.132.40 (server170.serverinternal.site): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 09 10:52:06.254500 2026] [security2:error] [pid 32198:tid 32198] [client 75.119.132.40:55494] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||belgiophar.com|F|4"] [data "keep-alive, keep-alive"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "belgiophar.com"] [uri "/graphql"] [unique_id "ak-1lqo5xxVpXAMmNjjiwQAAAAQ"], referer: https://belgiophar.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-09 13:44:14
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 75.119.132.40 (server170.serverinternal.site): ...
show more
(mod_security) mod_security (id:210350) triggered by 75.119.132.40 (server170.serverinternal.site): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 09 09:44:09.814788 2026] [security2:error] [pid 15292:tid 15292] [client 75.119.132.40:48032] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||visionremota.info|F|4"] [data "keep-alive, keep-alive"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "visionremota.info"] [uri "/"] [unique_id "ak-lqZv6vfPRK8R0jgPcJAAAAAE"], referer: https://visionremota.info/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-09 12:04:30
(1 week ago)
(mod_security) mod_security (id:210350) triggered by 75.119.132.40 (server170.serverinternal.site): ...
show more
(mod_security) mod_security (id:210350) triggered by 75.119.132.40 (server170.serverinternal.site): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 09 08:04:22.896083 2026] [security2:error] [pid 13709:tid 13709] [client 75.119.132.40:44218] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||newcitypark.com|F|4"] [data "keep-alive, keep-alive"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "newcitypark.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ak-ORtY4LdgDkucUBzy8FAAAAAE"], referer: https://newcitypark.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-09 09:21:35
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-08 08:40:14
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 75.119.132.40 (server170.serverinternal.site): ...
show more
(mod_security) mod_security (id:225170) triggered by 75.119.132.40 (server170.serverinternal.site): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 08 04:40:09.049855 2026] [security2:error] [pid 1739:tid 1739] [client 75.119.132.40:58018] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||odysseydogasporlari.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "odysseydogasporlari.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ak4M6X3gBsI560rqruHrqgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-07 22:48:59
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 75.119.132.40 (server170.serverinternal.site): ...
show more
(mod_security) mod_security (id:225170) triggered by 75.119.132.40 (server170.serverinternal.site): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 07 18:48:52.166292 2026] [security2:error] [pid 24537:tid 24537] [client 75.119.132.40:57334] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nwtree.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nwtree.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ak2CVEPs7Bn38eHmbVNkHgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 08:21:27
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 75.119.132.40 (server170.serverinternal.site): ...
show more
(mod_security) mod_security (id:225170) triggered by 75.119.132.40 (server170.serverinternal.site): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 04:21:23.548973 2026] [security2:error] [pid 5289:tid 5289] [client 75.119.132.40:46996] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||taekwondoit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "taekwondoit.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "akjCg-okfL80_rnaisKtJwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-03 04:25:00
(2 weeks ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-02 17:28:15
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 75.119.132.40 (server170.serverinternal.site): ...
show more
(mod_security) mod_security (id:225170) triggered by 75.119.132.40 (server170.serverinternal.site): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 13:28:09.884251 2026] [security2:error] [pid 4804:tid 4804] [client 75.119.132.40:38360] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||oruhu.org.circulodesonido.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "oruhu.org.circulodesonido.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "akafqbtNi82Y41emxjiE-QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-02 04:15:15
(2 weeks ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 75.119.132.40 (US/United States/server170.ser ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 75.119.132.40 (US/United States/server170.serverinternal.site): 1 in the last 3600 secs (0-195)
show less
Hacking