Anonymous
2026-09-27 22:00:45
(9 hours ago)
Network service scanning detected by FortiGate; source quarantined.
Port Scan
๐ฉ๐ช
big-cloud.nl
2026-09-25 12:10:08
(2 days ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:30:55
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 78.97.151.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 78.97.151.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:30:45.535494 2026] [security2:error] [pid 28317:tid 28317] [client 78.97.151.198:34694] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||talentstar2025.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "talentstar2025.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arFbtXu5bbcMZqI95KYL4QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 13:47:30
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 78.97.151.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 78.97.151.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:47:22.564755 2026] [security2:error] [pid 211106:tid 211106] [client 78.97.151.198:49676] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||walkercline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "walkercline.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arE1aq80bPIMft7xgGG_hgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-09-18 21:37:55
(1 week ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-17 14:39:52
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 78.97.151.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 78.97.151.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 10:39:49.039656 2026] [security2:error] [pid 9976:tid 9976] [client 78.97.151.198:51510] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bronislawsuchanek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bronislawsuchanek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqv7tR-QgJFpsOeeKfaQjwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:54:35
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 78.97.151.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 78.97.151.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:54:31.348654 2026] [security2:error] [pid 17650:tid 17650] [client 78.97.151.198:35398] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doreenkimura.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doreenkimura.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqvjB1-ICZTL7WLkGO60kwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-15 04:09:24
(1 week ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-14 12:13:57
(1 week ago)
cloudlinux2 fail2ban: 2026-09-14 14:09:17,713 fail2ban.filter [1908]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-14 14:09:17,713 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 49.43.128.98 - 2026-09-14 14:09:17cloudlinux2 fail2ban: 2026-09-14 14:09:58,468 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 78.97.151.198 - 2026-09-14 14:09:57cloudlinux2 fail2ban: 2026-09-14 14:10:09,458 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 151.158.235.25 - 2026-09-14 14:10:09cloudlinux2 fail2ban: 2026-09-14 14:10:24,502 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 103.171.117.48 - 2026-09-14 14:10:24cloudlinux2 fail2ban: 2026-09-14 14:10:18,583 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 154.241.9.90 - 2026-09-14 14:10:18cloudlinux2 fail2ban: 2026-09-14 14:10:41,320 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Ban 151.158.235.25cloudlinux2 fail2ban: 2026-09-14 14:10:41,288 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 151.158.235.25 - 2026-09-14 14:10:41cloudlinux2 fail2ba
show less
Web App Attack
๐ฉ๐ช
AlexEventfahrtenIPDB
2026-09-14 09:04:23
(1 week ago)
[Mon Sep 14 11:04:22.495441 2026] [authz_core:error] [pid 2516374:tid 2516391] [remote 78.97.151.198 ...
show more
[Mon Sep 14 11:04:22.495441 2026] [authz_core:error] [pid 2516374:tid 2516391] [remote 78.97.151.198:33160] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://alex-eventfahrten.spdns.de/
[Mon Sep 14 11:04:22.628720 2026] [authz_core:error] [pid 2516374:tid 2516394] [remote 78.97.151.198:33160] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://alex-eventfahrten.de/wp-login.php
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-14 06:59:22
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
Anonymous
2026-09-13 08:45:14
(2 weeks ago)
Web attack blocked by Wordfence on vestingstadvalkenburg.nl (3 hits). Reported by CRMON.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 20:50:38
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 78.97.151.198 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 78.97.151.198 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:50:33.016560 2026] [security2:error] [pid 20903:tid 20903] [client 78.97.151.198:51782] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nwtree.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nwtree.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqB1GatrUYLH9ZIVGzzi_wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack