π³π±
Site.eu
2026-10-04 01:03:17
(3 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
π©πͺ
gadix
2026-10-03 15:24:04
(3 days ago)
91.192.224.150 - - [03/Oct/2026:16:41:52 +0200] "POST /wp-login.php HTTP/1.1" 200 3200 "https://prow ...
show more
91.192.224.150 - - [03/Oct/2026:16:41:52 +0200] "POST /wp-login.php HTTP/1.1" 200 3200 "https://proweris.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
91.192.224.150 - - [03/Oct/2026:17:03:01 +0200] "POST /wp-login.php HTTP/1.1" 200 3200 "https://proweris.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
91.192.224.150 - - [03/Oct/2026:17:24:03 +0200] "POST /wp-l
...
show less
Web App Attack
π©πͺ
BlueWire Hosting
2026-10-03 13:36:53
(3 days ago)
Aggressive scanning resulting into 404
Bad Web Bot
π©πͺ
todix
2026-10-03 13:24:00
(3 days ago)
WebAttack or semilar from 91.192.224.150
Web App Attack
π©πͺ
XICTRON
2026-10-03 12:35:03
(3 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-03 12:10:23
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 91.192.224.150 (chat.dc9.dev): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 91.192.224.150 (chat.dc9.dev): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 08:10:19.841321 2026] [security2:error] [pid 11344:tid 11344] [client 91.192.224.150:35294] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abilityengraving.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abilityengraving.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asDwq3-fTmIsbUxLH2T-sQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-10-03 11:57:25
(3 days ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 91.192.224.150 (PL/Poland/chat.dc9.dev): 3 in ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 91.192.224.150 (PL/Poland/chat.dc9.dev): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/10/03 13:57:21 [error] 2082673#2082673: *194385 access forbidden by rule, client: 91.192.224.150, server: avconsulenze.arkon.it, request: "GET /?author=3 HTTP/1.1", host: "avconsulenze.eu"
2026/10/03 13:57:21 [error] 2082665#2082665: *194386 access forbidden by rule, client: 91.192.224.150, server: avconsulenze.arkon.it, request: "GET /?author=4 HTTP/1.1", host: "avconsulenze.eu"
2026/10/03 13:57:21 [error] 2082669#2082669: *194377 access forbidden by rule, client: 91.192.224.150, server: avconsulenze.arkon.it, request: "GET /?author=12 HTTP/1.1", host: "avconsulenze.eu"
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-10-03 11:55:03
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 91.192.224.150 (chat.dc9.dev): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 91.192.224.150 (chat.dc9.dev): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 07:54:57.489745 2026] [security2:error] [pid 9093:tid 9093] [client 91.192.224.150:58206] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||67ronin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "67ronin.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asDtERetabiX62QGGFJvhwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-10-03 11:36:34
(3 days ago)
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail ngin ...
show more
[cb-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail nginx-404. Example: 91.192.224.150 - - [03/Oct/2026:13:36:14 +0200] "GET /?author=14 HTTP/1.1" 404 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36 Edg/127.0.0.0"
91.192.224.150 - - [03/Oct/2026:13:36:14 +0200] "GET /?author=11 HTTP/1.1" 404 31 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
91.192.224.150 - - [03/Oct/2026:13:36:14 +0200] "GET /?author=12 HTTP/1.1" 404 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
91.192.224.150 - - [03/Oct/2026:13:36:14 +0200] "GET /?author=4 HTTP/1.1" 404 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
91.192.224.1
...
show less
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-10-03 11:26:37
(3 days ago)
Web exploit attempt | method: POST | path: /wp-json/wp/v2/users | ua: Mozilla/5.0 (Windows NT 10.0; ...
show more
Web exploit attempt | method: POST | path: /wp-json/wp/v2/users | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
π©πͺ
FeG Deutschland
2026-10-03 11:10:13
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
πΊπΈ
mnsf
2026-10-03 11:05:12
(3 days ago)
Too many Status 40X (13)
Scanning/Probing (12)
Brute-Force
Web App Attack