๐ฎ๐น
CoreTech srl
2026-09-11 11:58:56
(3 hours ago)
cloudlinux2 fail2ban: 2026-09-11 13:54:15,549 fail2ban.actions [1606]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-11 13:54:15,549 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Unban 152.58.131.75cloudlinux2 fail2ban: 2026-09-11 13:54:17,934 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 152.58.131.16 - 2026-09-11 13:54:17cloudlinux2 fail2ban: 2026-09-11 13:54:18,165 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Ban 152.58.131.16cloudlinux2 fail2ban: 2026-09-11 13:54:18,259 fail2ban.filter [1606]: INFO [recidive] Found 152.58.131.16 - 2026-09-11 13:54:18cloudlinux2 fail2ban: 2026-09-11 13:56:14,403 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 192.140.151.77 - 2026-09-11 13:56:14cloudlinux2 fail2ban: 2026-09-11 13:56:11,690 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 93.177.95.66 - 2026-09-11 13:56:11cloudlinux2 fail2ban: 2026-09-11 13:56:59,281 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 192.140.151.77 - 2026-09-11 13:56:59cloudlinux2 fail2ban: 2026-09-11 13:57:18,409 fai
show less
FTP Brute-Force
๐ฑ๐ป
garmtech.com
2026-07-13 16:04:22
(1 month ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 19-04.93.177.95.66.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 19-04.93.177.95.66.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 05:33:27
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 93.177.95.66 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 93.177.95.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 01:33:21.643942 2026] [security2:error] [pid 23695:tid 23695] [client 93.177.95.66:16399] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pathpa.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pathpa.org"] [uri "/wp-json/wp/v2/users"] [unique_id "akdJofMk0dlQXcDY39oCTwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 03:12:23
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 93.177.95.66 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 93.177.95.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 23:12:20.622194 2026] [security2:error] [pid 6900:tid 6904] [client 93.177.95.66:60585] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lapulperiagirona.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lapulperiagirona.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akcolP0EvVLrON-A1zPYzgAAAII"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-07-02 06:45:31
(2 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐ฉ๐ช
YF
2026-06-30 22:10:10
(2 months ago)
WordPress content enumeration
Web App Attack
๐ซ๐ฎ
JimArchon72
2026-06-23 20:35:04
(2 months ago)
2026/06/23 20:34:38 "GET /wp-login.php?action=register HTTP/1.1"
Web App Attack
๐ฑ๐ป
garmtech.com
2026-06-17 22:23:09
(2 months ago)
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 01-23.93.177.95.66.web-spammer ...
show more
IM360 WAF: Block IP which is in the web-spammers RBL MV:RBL lookup of 01-23.93.177.95.66.web-spammers.v2.rbl.imunify.com._v4 succeeded.
show less
Web App Attack
๐ช๐ธ
Mugen
2026-02-17 19:31:31
(6 months ago)
Unauthorized VPN login attempts
Brute-Force
Anonymous
2026-01-05 01:01:41
(8 months ago)
This IP was involved in a brute force and password spray attack.
Brute-Force
Web App Attack
๐จ๐ฆ
wil.com
2025-12-02 19:46:55
(9 months ago)
GlobalProtect login attempts with user 0021421.
VPN IP
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-10-12 22:38:30
(10 months ago)
(mod_security) mod_security (id:210350) triggered by 93.177.95.66 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210350) triggered by 93.177.95.66 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 12 18:38:27.361087 2025] [security2:error] [pid 2424:tid 2424] [client 93.177.95.66:21365] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||sahinozalit.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "sahinozalit.com"] [uri "/admin"] [unique_id "aOwt47hyy-1hMhdAtePjAwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-10-06 21:30:11
(11 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐จ๐ญ
backslash
2025-09-02 17:55:05
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot