🇧🇪
taivas.nl
2026-09-05 01:32:14
(10 minutes ago)
Bad_requests
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-05 01:31:58
(10 minutes ago)
(mod_security) mod_security (id:225170) triggered by 85.215.130.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 85.215.130.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:31:50.028088 2026] [security2:error] [pid 10223:tid 10223] [client 85.215.130.58:40968] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kadinisi.org.mavikalem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kadinisi.org.mavikalem.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aptxBpSttyAdzgD-rvh2-gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-05 01:28:57
(13 minutes ago)
cloudlinux2 fail2ban: 2026-09-05 03:24:10,168 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-05 03:24:10,168 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 175.44.80.163 - 2026-09-05 03:24:10cloudlinux2 fail2ban: 2026-09-05 03:25:11,177 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.56.116.74 - 2026-09-05 03:25:10cloudlinux2 fail2ban: 2026-09-05 03:25:03,647 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 85.215.130.58 - 2026-09-05 03:25:03cloudlinux2 fail2ban: 2026-09-05 03:25:06,540 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.56.116.74 - 2026-09-05 03:25:06cloudlinux2 fail2ban: 2026-09-05 03:25:18,419 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.56.116.16 - 2026-09-05 03:25:17cloudlinux2 fail2ban: 2026-09-05 03:25:40,530 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 142.111.152.111 - 2026-09-05 03:25:40cloudlinux2 fail2ban: 2026-09-05 03:25:40,896 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 155.2.215.32 - 2026-09-05 03:25:40clou
show less
Web App Attack
🇺🇸
mnogoweb
2026-09-05 01:21:22
(21 minutes ago)
(smtpauth) Failed SMTP AUTH login from 85.215.130.58 (DE/Germany/-): 5 in the last 3600 secs; Ports: ...
show more
(smtpauth) Failed SMTP AUTH login from 85.215.130.58 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-04 18:31:52 login authenticator failed for (45.74.31.30) [85.215.130.58]: 535 Incorrect authentication data ([email protected] )
2026-09-04 18:45:07 login authenticator failed for (45.74.31.30) [85.215.130.58]: 535 Incorrect authentication data ([email protected] )
2026-09-04 18:49:39 login authenticator failed for (45.74.31.30) [85.215.130.58]: 535 Incorrect authentication data ([email protected] )
2026-09-04 19:12:02 login authenticator failed for (45.74.31.30) [85.215.130.58]: 535 Incorrect authentication data ([email protected] )
2026-09-04 19:21:18 login authenticator failed for (45.74.31.30) [85.215.130.58]: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇬🇧
andypiper
2026-09-05 01:00:45
(41 minutes ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 00:40:34
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 85.215.130.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 85.215.130.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 20:40:29.618599 2026] [security2:error] [pid 20203:tid 20203] [client 85.215.130.58:50708] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||skintormint.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "skintormint.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aptk_eE-1q4BkFNAsmtdlQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
antlac1
2026-09-05 00:35:51
(1 hour ago)
crowdsecurity/http-cve-probing
Brute-Force
Web App Attack
Anonymous
2026-09-05 00:23:38
(1 hour ago)
2026-09-05T00:23:37.214880+00:00 instance-20260804-1025 wordpress(trademarks4all.com)[1625091]: Imme ...
show more
2026-09-05T00:23:37.214880+00:00 instance-20260804-1025 wordpress(trademarks4all.com)[1625091]: Immediately block connections from 85.215.130.58
...
show less
Web App Attack
🇺🇸
mnogoweb
2026-09-05 00:15:32
(1 hour ago)
(smtpauth) Failed SMTP AUTH login from 85.215.130.58 (DE/Germany/-): 5 in the last 3600 secs; Ports: ...
show more
(smtpauth) Failed SMTP AUTH login from 85.215.130.58 (DE/Germany/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_SMTPAUTH; Logs: 2026-09-04 17:57:34 login authenticator failed for (45.74.31.30) [85.215.130.58]: 535 Incorrect authentication data ([email protected] )
2026-09-04 18:04:58 login authenticator failed for (45.74.31.30) [85.215.130.58]: 535 Incorrect authentication data ([email protected] )
2026-09-04 18:07:43 login authenticator failed for (45.74.31.30) [85.215.130.58]: 535 Incorrect authentication data ([email protected] )
2026-09-04 18:07:54 login authenticator failed for (45.74.31.30) [85.215.130.58]: 535 Incorrect authentication data ([email protected] )
2026-09-04 18:15:27 login authenticator failed for (45.74.31.30) [85.215.130.58]: 535 Incorrect authentication data ([email protected] )
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-05 00:14:55
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 85.215.130.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 85.215.130.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 20:14:50.565197 2026] [security2:error] [pid 31134:tid 31134] [client 85.215.130.58:50834] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lasertherapyoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lasertherapyoc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apte-sQf9BTlZm_v4JZkqwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 23:56:41
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 85.215.130.58 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 85.215.130.58 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 19:56:33.096873 2026] [security2:error] [pid 26565:tid 26565] [client 85.215.130.58:54928] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||astglobaltech.com.greenlight.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "astglobaltech.com.greenlight.us"] [uri "/wp-json/wp/v2/users"] [unique_id "aptasacAiWmtjRcjVUcaTwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 23:06:11
(2 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-09-04 23:06 UTC
show less
Hacking
Web App Attack
🇸🇮
administrator
2026-09-04 22:34:49
(3 hours ago)
2026-09-04 17:26:45,727 fail2ban.actions [1191]: NOTICE [webadmin-badips] Ban 85.215.130.58
...
show more
2026-09-04 17:26:45,727 fail2ban.actions [1191]: NOTICE [webadmin-badips] Ban 85.215.130.58
2026-09-04 17:35:06,905 fail2ban.actions [1191]: NOTICE [webadmin-nfw] Ban 85.215.130.58
2026-09-04 17:26:45,727 fail2ban.actions [1191]: NOTICE [webadmin-badips] Ban 85.215.130.58
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
🇺🇸
xxkodedxx
2026-09-04 22:12:56
(3 hours ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get in 10m window.
Active: 22:12:04 UTC
Volume: 1 honeypot probe(s)
Bait taken: /wp-sitemap-users-1.xml
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-09-04 22:11:28
(3 hours ago)
85.215.130.58 - - [05/Sep/2026:00:11:15 +0200] "GET /readme.html HTTP/2.0" 404 483 "-" "Mozilla/5.0 ...
show more
85.215.130.58 - - [05/Sep/2026:00:11:15 +0200] "GET /readme.html HTTP/2.0" 404 483 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 85.215.130.58 - - [05/Sep/2026:00:11:19 +0200] "POST /api/graphql HTTP/2.0" 404 483 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 85.215.130.58 - - [05/Sep/2026:00:11:28 +0200] "GET /wp-json/wp/v2/users?per_page=50&_embed&_fields=id,slug,name HTTP/2.0" 404 483 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Brute-Force