🇮🇹
VHosting
2026-08-29 00:20:03
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
oralunal
2026-08-27 23:11:01
(1 week ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
🇺🇸
TRoden
2026-08-26 05:45:34
(1 week ago)
Geo Block Plugin: Escalation flag(s): rce_attempt
Hacking
🇦🇺
oncord
2026-04-17 12:14:27
(4 months ago)
Form spam
Web Spam
🇺🇸
TPI-Abuse
2026-03-16 07:19:20
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 03:19:14.838648 2026] [security2:error] [pid 16326:tid 16326] [client 88.218.45.177:28931] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "abeu8gg5rlfjax3Mzk3w0QAAAAw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
oncord
2026-03-09 02:48:30
(5 months ago)
Form spam
Web Spam
🇺🇸
TPI-Abuse
2026-01-22 20:09:34
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 15:09:30.825199 2026] [security2:error] [pid 23590:tid 23590] [client 88.218.45.177:47593] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||casapapayasanmiguel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "casapapayasanmiguel.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aXKD-upuWHAvbuRiXMaA1wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-10 10:33:30
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 05:33:25.009438 2025] [security2:error] [pid 25399:tid 25399] [client 88.218.45.177:52737] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||itre.org|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "itre.org"] [uri "/"] [unique_id "aTlMdNjyIZw-FHFr9Kg30QAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-10 09:09:12
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 04:09:05.564289 2025] [security2:error] [pid 11164:tid 11164] [client 88.218.45.177:13043] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||mosherpit.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "mosherpit.com"] [uri "/"] [unique_id "aTk4sf1GCCv2CQTwgDD5bwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-10 07:05:32
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 02:05:27.201422 2025] [security2:error] [pid 27109:tid 27123] [client 88.218.45.177:52651] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||pref-realestate.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "pref-realestate.com"] [uri "/"] [unique_id "aTkbtyS0Bgb-EQW_BcGbzwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-12-10 06:43:55
(8 months ago)
(mod_security) mod_security (id:210350) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 01:43:50.678460 2025] [security2:error] [pid 15005:tid 15014] [client 88.218.45.177:25893] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||rmgmediagroup.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "rmgmediagroup.com"] [uri "/"] [unique_id "aTkWplVLsVfkwxfIewMugQAAAUA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ne1for23
2025-10-07 14:45:32
(10 months ago)
88.218.45.177 - - [07/Oct/2025:14:45:32 +0000] "GET /wp-login.php HTTP/1.1" 403 555 "-" "Mozilla/5.0 ...
show more
88.218.45.177 - - [07/Oct/2025:14:45:32 +0000] "GET /wp-login.php HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203"
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-10-04 22:12:24
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 18:12:16.957488 2025] [security2:error] [pid 11399:tid 11399] [client 88.218.45.177:42751] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||justinpenney.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "justinpenney.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aOGbwEqDX9YtocVn1C9huQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-04 17:01:30
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 13:01:27.929582 2025] [security2:error] [pid 26817:tid 26817] [client 88.218.45.177:19791] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||accommodation-perthairport.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "accommodation-perthairport.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aOFS53lCvf4naRlmyM5XIAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-03 06:20:16
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 88.218.45.177 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 03 02:20:07.549016 2025] [security2:error] [pid 3391:tid 3391] [client 88.218.45.177:45953] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geckoturner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geckoturner.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aN9rF--ZnwBIODSGWqcAOAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack