Anonymous
2026-09-09 00:40:04
(44 minutes ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇩🇪
neckaralb-admin.de
2026-09-09 00:37:34
(46 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇮🇳
evicky2002
2026-09-09 00:01:20
(1 hour ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇩🇪
LRob
2026-09-08 20:45:25
(4 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-json/wp/v2/users/me | 2026- ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-json/wp/v2/users/me | 2026-09-08 20:45 UTC
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:32:51
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): ...
show more
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:32:46.841791 2026] [security2:error] [pid 10236:tid 10236] [client 83.215.102.82:47358] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||celebritybikinigossip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "celebritybikinigossip.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAcjt8bfL_-IpiJ-whWhwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:13:26
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): ...
show more
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:13:22.329653 2026] [security2:error] [pid 10443:tid 10443] [client 83.215.102.82:58482] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fusteriafontane.casademunt.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fusteriafontane.casademunt.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAYAiEYdSbevM4Tijf90AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:33:32
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): ...
show more
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:33:25.984369 2026] [security2:error] [pid 11228:tid 11228] [client 83.215.102.82:51970] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||learnserve.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "learnserve.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAOpdnciOV1D8WulT9n6QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:16:46
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): ...
show more
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:16:38.750419 2026] [security2:error] [pid 24039:tid 24039] [client 83.215.102.82:41676] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sneedvillefarmersmarket.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sneedvillefarmersmarket.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAKts9gxIw2oSAxF6B1owAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:50:58
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): ...
show more
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:50:54.705997 2026] [security2:error] [pid 31476:tid 31476] [client 83.215.102.82:55146] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||riedmannfamily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "riedmannfamily.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAErnNSoZXetC06K6LBIAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 12:13:57
(13 hours ago)
cloudlinux2 fail2ban: 2026-09-08 14:08:50,032 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-08 14:08:50,032 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 45.131.193.224 - 2026-09-08 14:08:49cloudlinux2 fail2ban: 2026-09-08 14:08:50,821 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 45.131.193.221 - 2026-09-08 14:08:50cloudlinux2 fail2ban: 2026-09-08 14:09:28,147 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 136.144.43.136 - 2026-09-08 14:09:26cloudlinux2 fail2ban: 2026-09-08 14:09:28,134 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 136.144.43.146 - 2026-09-08 14:09:26cloudlinux2 fail2ban: 2026-09-08 14:09:41,305 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 45.132.115.231 - 2026-09-08 14:09:40cloudlinux2 fail2ban: 2026-09-08 14:09:41,319 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 172.98.33.193 - 2026-09-08 14:09:40cloudlinux2 fail2ban: 2026-09-08 14:09:53,548 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 83.215.102.82 - 2026-09-08 14:09:53clou
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:37:23
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): ...
show more
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:37:17.864379 2026] [security2:error] [pid 4259:tid 4259] [client 83.215.102.82:40962] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||schwanpaint.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "schwanpaint.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_zbYQtzWSx-xgFjHWagwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 11:04:47
(14 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:01:24
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): ...
show more
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:01:20.570674 2026] [security2:error] [pid 3424505:tid 3424505] [client 83.215.102.82:43474] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nuewines.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nuewines.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_rAJMXENra4MnfttcdUgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:33:48
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): ...
show more
(mod_security) mod_security (id:225170) triggered by 83.215.102.82 (83-215-102-82.dyn.cablelink.at): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:33:44.616968 2026] [security2:error] [pid 21917:tid 21917] [client 83.215.102.82:44114] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||techoutletec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "techoutletec.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_kiEBKv1uU7AFRS3dbpgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-08 10:05:25
(15 hours ago)
3.427 requests to many distinct domains in 1 hour (3w1d18h)
Brute-Force
Bad Web Bot