Anonymous
2026-08-23 11:20:32
(5 days ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-23 10:07:00
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 95.216.170.157 (static.157.170.216.95.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 95.216.170.157 (static.157.170.216.95.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 06:06:51.865570 2026] [security2:error] [pid 21683:tid 21683] [client 95.216.170.157:36182] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||honigcpa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "honigcpa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aorGO7pn1aN9uS0bODFc3QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-23 06:08:29
(5 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 95.216.170.157 (FI/Finland/static.157.170.216. ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 95.216.170.157 (FI/Finland/static.157.170.216.95.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 95.216.170.157 - - [23/Aug/2026:08:08:27 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 1854 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=studioegizi.it
show less
Port Scan
๐ฉ๐ช
maxpower
2026-08-23 05:42:54
(5 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 95.216.170.157 (FI/Finland/static.157.170.216. ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 95.216.170.157 (FI/Finland/static.157.170.216.95.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 95.216.170.157 - - [23/Aug/2026:07:42:52 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 2134 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=britishlanguagecentre.it
show less
Port Scan
๐ฆ๐บ
FireGuard Server
2026-08-23 01:15:04
(5 days ago)
Blocked by os-abuseipdb; 14 hits, proto=tcp, ports=443
Port Scan
Hacking
Anonymous
2026-08-23 01:10:56
(5 days ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: FI, Attack patterns: Auto ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: FI, Attack patterns: Automated scanning
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-22 21:38:34
(5 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 18:09:08
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 95.216.170.157 (static.157.170.216.95.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 95.216.170.157 (static.157.170.216.95.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 14:09:02.061701 2026] [security2:error] [pid 30166:tid 30166] [client 95.216.170.157:35384] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||feministvoice.blog|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "feministvoice.blog"] [uri "/wp-json/wp/v2/users"] [unique_id "aonlvgqWYj9Tda8JIZFavwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-22 15:59:42
(6 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after locale-probe / error-handler fuzzing ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after locale-probe / error-handler fuzzing against ASP.NET shop. Evidence: LOCALE-PROBE: MissingSlash (/be10559Content/images/site/31aec856a9184cb7816cba0bfd7982a7.png)
show less
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-22 15:13:57
(6 days ago)
cloudlinux2 fail2ban: 2026-08-22 17:11:15,445 fail2ban.filter [1480]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-22 17:11:15,445 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 172.98.33.80 - 2026-08-22 17:11:15cloudlinux2 fail2ban: 2026-08-22 17:11:15,475 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 45.132.115.109 - 2026-08-22 17:11:15cloudlinux2 fail2ban: 2026-08-22 17:11:15,439 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 172.98.33.83 - 2026-08-22 17:11:15cloudlinux2 fail2ban: 2026-08-22 17:12:00,367 fail2ban.actions [1480]: NOTICE [plesk-modsecurity] Unban 188.64.173.63cloudlinux2 fail2ban: 2026-08-22 17:12:24,699 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 95.216.170.157 - 2026-08-22 17:12:24cloudlinux2 fail2ban: 2026-08-22 17:12:56,371 fail2ban.filter [1480]: INFO [plesk-wordpress] Found 45.132.115.133 - 2026-08-22 17:12:55cloudlinux2 fail2ban: 2026-08-22 17:13:06,793 fail2ban.filter [1480]: INFO [plesk-modsecurity] Found 136.67.78.172 - 2026-08-22 17:13:06cloudlinux2 fail2ban: 20
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-08-22 14:20:55
(6 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
maxpower
2026-08-22 12:48:50
(6 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 95.216.170.157 (FI/Finland/static.157.170.216. ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 95.216.170.157 (FI/Finland/static.157.170.216.95.clients.your-server.de): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 95.216.170.157 - - [22/Aug/2026:14:48:45 +0200] "GET /wp-json/wp/v2/users?per_page=100 HTTP/1.1" 200 1763 "-" "Mozilla/5.0 (compatible; osentix-crawler/1.0; +https://osentix.com/bot)" "-" host=centromedicodiianni.it
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-22 12:46:26
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 95.216.170.157 (static.157.170.216.95.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 95.216.170.157 (static.157.170.216.95.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 08:46:20.228343 2026] [security2:error] [pid 20397:tid 20397] [client 95.216.170.157:28356] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||noviasaltovacio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "noviasaltovacio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aomaHA6bsAQ0WMUNC8zJKgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 11:51:27
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 95.216.170.157 (static.157.170.216.95.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 95.216.170.157 (static.157.170.216.95.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 07:51:23.913970 2026] [security2:error] [pid 27371:tid 27371] [client 95.216.170.157:45034] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||twogocamping.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "twogocamping.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aomNO2y9IaZ2SaLyvAZCiAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 10:51:35
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 95.216.170.157 (static.157.170.216.95.clients.y ...
show more
(mod_security) mod_security (id:225170) triggered by 95.216.170.157 (static.157.170.216.95.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 06:51:30.531957 2026] [security2:error] [pid 24980:tid 24980] [client 95.216.170.157:15292] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bethanpearce.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bethanpearce.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aol_Mv01qmWULbIp6aklzwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack