Anonymous
2026-09-09 08:50:35
(2 hours ago)
denied SSH access attempt. destination port 22.
Port Scan
Brute-Force
SSH
🇪🇸
masterguru
2026-09-09 08:12:50
(2 hours ago)
*Port Scan* detected from 94.250.22.33 (BA/Bosnia and Herzegovina/-). 11 hits in the last 65 seconds ...
show more
*Port Scan* detected from 94.250.22.33 (BA/Bosnia and Herzegovina/-). 11 hits in the last 65 seconds (0-122)
show less
Port Scan
🇳🇱
EGP Abuse Dept
2026-09-09 07:25:05
(3 hours ago)
Unauthorized connection to SSH port 22
Port Scan
Hacking
SSH
🇫🇮
stinpriza
2026-09-09 05:45:15
(5 hours ago)
Web App Attack
Web App Attack
🇺🇸
lostswordfish.com
2026-09-09 05:04:04
(6 hours ago)
Wordfence waf block on madesimpleskincare
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:54:45
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 94.250.22.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 94.250.22.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:54:36.621321 2026] [security2:error] [pid 32589:tid 32589] [client 94.250.22.33:59026] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pleaseaddbacon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pleaseaddbacon.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDmjPFqgqjPZwwHXnRfFQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 04:10:29
(6 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-json/wp/v2/users/me | 2026- ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-json/wp/v2/users/me | 2026-09-09 04:10 UTC
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:34:54
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 94.250.22.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 94.250.22.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:34:41.858878 2026] [security2:error] [pid 21337:tid 21337] [client 94.250.22.33:35128] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vespaitaliancafe.matteozacchino.dev|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vespaitaliancafe.matteozacchino.dev"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDT0RVmLLC2xzaXlMs-3gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 02:48:13
(8 hours ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 94.250.22.33 (BA/Bosnia and Herzegovina/-): 1 ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 94.250.22.33 (BA/Bosnia and Herzegovina/-): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-09 02:38:26
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 94.250.22.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 94.250.22.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:38:16.949844 2026] [security2:error] [pid 13026:tid 13026] [client 94.250.22.33:52514] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cassimandabdallah.williamgilcher.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cassimandabdallah.williamgilcher.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDGmLWL9tCJWqPYmnQryAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
ELYAZ
2026-09-09 01:28:08
(9 hours ago)
(wordpress) Failed wordpress login from 94.250.22.33 (BA/Bosnia and Herzegovina/-): (CF_ENABLE)
Brute-Force
🇺🇸
TPI-Abuse
2026-09-09 00:12:39
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 94.250.22.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 94.250.22.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:12:30.726112 2026] [security2:error] [pid 12472:tid 12472] [client 94.250.22.33:49478] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cmcnow.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cmcnow.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCkbiJyYlAH8BaXvWurmwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 23:58:51
(11 hours ago)
cloudlinux2 fail2ban: 2026-09-09 01:53:52,808 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-09 01:53:52,808 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 94.250.22.33 - 2026-09-09 01:53:52cloudlinux2 fail2ban: 2026-09-09 01:53:49,087 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 63.135.161.154 - 2026-09-09 01:53:48cloudlinux2 fail2ban: 2026-09-09 01:53:58,471 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 63.135.161.154 - 2026-09-09 01:53:58cloudlinux2 fail2ban: 2026-09-09 01:54:11,318 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 63.135.161.154 - 2026-09-09 01:54:10cloudlinux2 fail2ban: 2026-09-09 01:54:12,100 fail2ban.actions [1794]: NOTICE [plesk-wordpress] Ban 63.135.161.154cloudlinux2 fail2ban: 2026-09-09 01:54:12,107 fail2ban.filter [1794]: INFO [recidive] Found 63.135.161.154 - 2026-09-09 01:54:12cloudlinux2 fail2ban: 2026-09-09 01:54:35,971 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 173.239.211.73 - 2026-09-09 01:54:35cloudlinux2 fail2ban: 2026-09-09 01
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:14:21
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 94.250.22.33 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 94.250.22.33 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:14:09.706481 2026] [security2:error] [pid 31083:tid 31083] [client 94.250.22.33:36034] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||schlegelcreative.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "schlegelcreative.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCWwVDBGPDR8MLIheT6LgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack