๐ฎ๐น
CoreTech srl
2026-09-21 11:59:21
(1 day ago)
cloudlinux2 fail2ban: 2026-09-21 12:54:55,210 fail2ban.filter [1598]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-21 12:54:55,210 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 49.36.17.51 - 2026-09-21 12:54:55cloudlinux2 fail2ban: 2026-09-21 12:55:01,129 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 223.181.21.234 - 2026-09-21 12:55:00cloudlinux2 fail2ban: 2026-09-21 12:55:16,990 fail2ban.filter [1598]: INFO [recidive] Found 49.36.17.51 - 2026-09-21 12:55:16cloudlinux2 fail2ban: 2026-09-21 12:55:16,985 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Ban 49.36.17.51cloudlinux2 fail2ban: 2026-09-21 12:55:16,658 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 49.36.17.51 - 2026-09-21 12:55:16cloudlinux2 fail2ban: 2026-09-21 12:55:31,401 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 42.116.101.166 - 2026-09-21 12:55:31cloudlinux2 fail2ban: 2026-09-21 12:55:34,116 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 223.181.21.234 - 2026-09-21 12:55:33cloudlinux2 fail2ban: 2026-09-21
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-20 17:08:22
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 13:08:17.362249 2026] [security2:error] [pid 13002:tid 13002] [client 89.110.89.15:51904] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nnrentacar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nnrentacar.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arATAWfhFzvlVmQ9FmkNdwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 05:27:37
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 01:27:31.183093 2026] [security2:error] [pid 3000:tid 3000] [client 89.110.89.15:60420] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||justiart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "justiart.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq9uw5do-jeljht7UPv1SQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 17:54:42
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 13:54:38.996918 2026] [security2:error] [pid 29100:tid 29100] [client 89.110.89.15:31790] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||guarinofurnituredesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "guarinofurnituredesigns.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7MXoEgq3hiqu4nfA0ZHQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 08:37:18
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 04:37:14.281969 2026] [security2:error] [pid 1650:tid 1650] [client 89.110.89.15:34429] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sooperare.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sooperare.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5JutY90yW0tgudVaU1zQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 20:22:03
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 16:21:59.651133 2026] [security2:error] [pid 31260:tid 31260] [client 89.110.89.15:10293] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||owldreamllc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "owldreamllc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqr6Z3Y9jOY6UFWXuAr9kAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 08:13:18
(6 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-09-16 08:13 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 08:30:28
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:30:22.725879 2026] [security2:error] [pid 24118:tid 24118] [client 89.110.89.15:19986] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||honigcpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "honigcpa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqkCHk3pMb2IH4ku5A1ODAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-14 09:17:57
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 05:17:49.816526 2026] [security2:error] [pid 22588:tid 22588] [client 89.110.89.15:30090] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||darrenj.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "darrenj.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqe7vcwqymrGGrbnM8TwHAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 05:15:54
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 01:15:47.024362 2026] [security2:error] [pid 16430:tid 16445] [client 89.110.89.15:53995] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||culturallyyours.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "culturallyyours.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aqYxgy0JqDFU_kWaaUrAMgAAAQk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-12 07:18:40
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 03:25:46
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 23:25:42.941834 2026] [security2:error] [pid 8398:tid 8398] [client 89.110.89.15:46076] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||chickiesbeef.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "chickiesbeef.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqTGNvVjaEROOgs7Xh6HcAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 06:13:52
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 02:13:47.965062 2026] [security2:error] [pid 32071:tid 32071] [client 89.110.89.15:47687] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fletcherdouglas.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fletcherdouglas.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqOcG_xbifkRLGKxV7dMSgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 20:56:19
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 16:56:14.060026 2026] [security2:error] [pid 21198:tid 21198] [client 89.110.89.15:8512] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jillbauman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jillbauman.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqMZblU4LWJbN3KDMNbuoAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 00:54:54
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsin ...
show more
(mod_security) mod_security (id:225170) triggered by 89.110.89.15 (host-89-110-89-15.hosted-by-vdsina.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 20:54:50.453165 2026] [security2:error] [pid 2053:tid 2053] [client 89.110.89.15:8766] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||modestosoftwater.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "modestosoftwater.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqH_2lXT-yDkxGYeq98UUwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack