๐บ๐ธ
TPI-Abuse
2026-06-15 22:35:47
(6 minutes ago)
(mod_security) mod_security (id:225170) triggered by 91.146.99.41 (serv2.natural.es): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.146.99.41 (serv2.natural.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 18:35:43.658153 2026] [security2:error] [pid 1285:tid 1285] [client 91.146.99.41:52492] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||parastesh.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "parastesh.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajB-P8f94YeZb2IXcAh06gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
noise.agency
2026-06-15 22:35:08
(7 minutes ago)
(wordpress) Failed wordpress login from 91.146.99.41 (ES/Spain/serv2.natural.es)
Brute-Force
๐ซ๐ท
SpaceHost-Server
2026-06-15 22:33:17
(8 minutes ago)
Brute-Force
Web App Attack
๐ญ๐บ
szasa
2026-06-15 22:25:05
(17 minutes ago)
2026/06/16 00:25:04 [error] 707102#707102: *3828562 access forbidden by rule, client: 91.146.99.41, ...
show more
2026/06/16 00:25:04 [error] 707102#707102: *3828562 access forbidden by rule, client: 91.146.99.41, server: datamentor.hu, request: "GET /wp-login.php HTTP/2.0", host: "datamentor.hu"
2026/06/16 00:25:04 [error] 707102#707102: *3828562 access forbidden by rule, client: 91.146.99.41, server: datamentor.hu, request: "POST /wp-login.php HTTP/2.0", host: "datamentor.hu", referrer: "https://datamentor.hu/wp-login.php"
2026/06/16 00:25:04 [error] 707102#707102: *3828562 access forbidden by rule, client: 91.146.99.41, server: datamentor.hu, request: "POST /wp-login.php HTTP/2.0", host: "datamentor.hu", referrer: "https://datamentor.hu/wp-login.php"
...
show less
Web App Attack
๐ฉ๐ช
netclix.gr
2026-06-15 22:21:35
(20 minutes ago)
(PERMBLOCK) 91.146.99.41 (ES/Spain/serv2.natural.es) has had more than 4 temp blocks
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-15 22:16:05
(26 minutes ago)
(mod_security) mod_security (id:225170) triggered by 91.146.99.41 (serv2.natural.es): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.146.99.41 (serv2.natural.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 18:15:58.370674 2026] [security2:error] [pid 28382:tid 28382] [client 91.146.99.41:50736] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||budgetbyron.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "budgetbyron.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajB5nnrurD-pecDNHsm8_QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-15 22:12:41
(29 minutes ago)
Unauthorized access to webpage admin
Web App Attack
๐จ๐ฆ
KIsmay
2026-06-15 22:12:38
(29 minutes ago)
Jun 15 17:54:01 www4 WPAudit[2051662]: 91.146.99.41 vhsport.ca "Mozilla/5.0 (X11; CrOS x86_64 14541. ...
show more
Jun 15 17:54:01 www4 WPAudit[2051662]: 91.146.99.41 vhsport.ca "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:r007p455w0rd FAIL
Jun 15 17:57:14 www4 WPAudit[2052181]: 91.146.99.41 www.katharinedickerson.com "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0" katharinedickerson:katharinedickerson18 FAIL
Jun 15 17:59:34 www4 WPAudit[2052620]: 91.146.99.41 imaginesalmon.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:sbd-admin2022 FAIL
Jun 15 18:05:45 www4 WPAudit[2053693]: 91.146.99.41 ouchiaccounting.ca "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" bwouchi:bwouchi@321 FAIL
Jun 15 18:12:37 www4 WPAudit[2054857]: 91.146.99.41 www.imaginesalmon.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safa
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
relianoid.com
2026-06-15 22:08:45
(33 minutes ago)
404 Errors Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web App Attack
๐บ๐ธ
Ghost Rider
2026-06-15 22:05:50
(36 minutes ago)
RdpGuard detected brute-force attempt on RDP
Brute-Force
๐ซ๐ท
tecnicorioja
2026-06-15 22:01:41
(40 minutes ago)
wp-login attack [15/Jun/2026:16:26:00
Brute-Force
Web App Attack
๐ซ๐ฎ
KnightIndustries
2026-06-15 21:59:06
(43 minutes ago)
2026-06-15T22:51:21.828250+02:00 milkyway wordpress(fawcettcomputerservices.com)[3909912]: Authentic ...
show more
2026-06-15T22:51:21.828250+02:00 milkyway wordpress(fawcettcomputerservices.com)[3909912]: Authentication failure for joshua from 91.146.99.41
2026-06-15T23:42:36.141150+02:00 milkyway wordpress(learncryptography.pw)[3921178]: Authentication failure for mystic from 91.146.99.41
2026-06-15T23:59:05.540374+02:00 milkyway wordpress(butlinsbadges.fawcett.ovh)[3921168]: Authentication failure for joshua from 91.146.99.41
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 21:56:20
(45 minutes ago)
(mod_security) mod_security (id:225170) triggered by 91.146.99.41 (serv2.natural.es): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 91.146.99.41 (serv2.natural.es): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 17:56:16.113145 2026] [security2:error] [pid 25923:tid 25923] [client 91.146.99.41:54040] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||verdeprofundo.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "verdeprofundo.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajB1AN7g5kDtBKhTdvRk8AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
www.fransveldman.world
2026-06-15 21:49:15
(52 minutes ago)
Fetched browser challenge page 13 times in <2h without solving. Likely bad bot.
Bad Web Bot
๐ญ๐บ
szasa
2026-06-15 21:32:04
(1 hour ago)
2026/06/15 23:12:30 [error] 707102#707102: *3827268 access forbidden by rule, client: 91.146.99.41, ...
show more
2026/06/15 23:12:30 [error] 707102#707102: *3827268 access forbidden by rule, client: 91.146.99.41, server: datamentor.hu, request: "GET /wp-login.php HTTP/2.0", host: "beszerzokozpont.hu"
2026/06/15 23:12:30 [error] 707102#707102: *3827268 access forbidden by rule, client: 91.146.99.41, server: datamentor.hu, request: "POST /wp-login.php HTTP/2.0", host: "beszerzokozpont.hu", referrer: "https://beszerzokozpont.hu/wp-login.php"
2026/06/15 23:32:03 [error] 707102#707102: *3827683 access forbidden by rule, client: 91.146.99.41, server: datamentor.hu, request: "GET /wp-login.php HTTP/2.0", host: "datamentor.hu"
2026/06/15 23:32:03 [error] 707102#707102: *3827683 access forbidden by rule, client: 91.146.99.41, server: datamentor.hu, request: "POST /wp-login.php HTTP/2.0", host: "datamentor.hu", referrer: "https://datamentor.hu/wp-login.php"
...
show less
Web App Attack