๐ฆ๐น
joe-abuse
2026-09-01 01:40:31
(2 days ago)
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-30 2 ...
show more
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-30 23:00:50. Events: 1. Reported by ipdb-security/fitzgerald.eu
show less
Web App Attack
๐น๐ท
eryilmaz
2026-08-31 02:00:27
(3 days ago)
Automated attack blocked by eryilmaz WAF/fail2ban: 2 event(s) [waf.block] in the last 1 days, e.g. / ...
show more
Automated attack blocked by eryilmaz WAF/fail2ban: 2 event(s) [waf.block] in the last 1 days, e.g. /wp-login.php
show less
Web App Attack
Hacking
๐ฆ๐น
joe-abuse
2026-08-31 01:36:03
(3 days ago)
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-30 2 ...
show more
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-30 23:00:50. Events: 1. Reported by ipdb-security/fitzgerald.eu
show less
Web App Attack
๐ซ๐ฎ
JimArchon72
2026-08-30 23:05:01
(3 days ago)
2026/08/30 23:03:00 "GET /wp-login.php HTTP/2.0"
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-30 23:03:41
(3 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 22:31:49
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 85.214.143.195 (h2988937.stratoserver.net): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 85.214.143.195 (h2988937.stratoserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 18:31:44.671944 2026] [security2:error] [pid 15014:tid 15014] [client 85.214.143.195:36680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||firebelly.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "firebelly.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apSvUOBsDztCEN66oxc1kwAAAAE"], referer: http://www.firebelly.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
GEDAL
2026-08-30 21:54:50
(4 days ago)
Fail2ban webexploits @ <hostname> : 85.214.143.195 - - [30/Aug/2026:23:54:49 +0200] "GET /wp-login.p ...
show more
Fail2ban webexploits @ <hostname> : 85.214.143.195 - - [30/Aug/2026:23:54:49 +0200] "GET /wp-login.php HTTP/1.1" 301 162 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
show less
Brute-Force
SSH
๐ฉ๐ช
DocNetzwerk
2026-08-30 21:53:06
(4 days ago)
(wordpress) Failed wordpress login from 85.214.143.195 (DE/Germany/h2988937.stratoserver.net)
Brute-Force
๐ฆ๐บ
FireGuard Server
2026-08-30 21:25:03
(4 days ago)
Blocked by os-abuseipdb; 12 hits, proto=tcp, ports=443
Port Scan
Hacking
๐ฌ๐ง
gigatech
2026-08-30 21:15:05
(4 days ago)
Webserver Probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 21:10:02
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 85.214.143.195 (h2988937.stratoserver.net): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 85.214.143.195 (h2988937.stratoserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 17:09:57.581034 2026] [security2:error] [pid 19935:tid 19935] [client 85.214.143.195:52196] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||darkalleyproductions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "darkalleyproductions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apScJSCUukabuuqlRb7wLQAAAAs"], referer: http://darkalleyproductions.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-08-30 20:52:01
(4 days ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 20:16:37
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 85.214.143.195 (h2988937.stratoserver.net): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 85.214.143.195 (h2988937.stratoserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:16:30.039206 2026] [security2:error] [pid 9492:tid 9492] [client 85.214.143.195:34606] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lovebuilds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lovebuilds.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apSPntxboGNcQ1YsAbop5AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-08-30 19:26:10
(4 days ago)
WP User Enumeration, WP login POST blocked by WAF
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-08-30 19:25:03
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack