๐ฆ๐ท
Kreature
2026-08-25 13:22:00
(3 weeks ago)
Intento de loggin por brute-force
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-10-13 20:11:46
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 95.38.94.97 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 95.38.94.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 13 16:11:38.351533 2025] [security2:error] [pid 1658:tid 1658] [client 95.38.94.97:43956] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||futurbike.it|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "futurbike.it"] [uri "/wp-json/wp/v2/users/"] [unique_id "aO1c-o6YTlaT28FkFCnkRgAAAAA"], referer: https://futurbike.it/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-09-02 05:30:58
(1 year ago)
Spamming registration page
Web Spam
๐ณ๐ฑ
antikirra
2025-08-30 09:04:30
(1 year ago)
Proxy Port Scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2025-08-30 06:57:00
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 95.38.94.97 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 95.38.94.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 30 02:56:54.590405 2025] [security2:error] [pid 27549:tid 27549] [client 95.38.94.97:53547] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||staben.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "staben.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aLKgtj-hxoNjdcpar5XtoAAAAAk"], referer: https://staben.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-29 16:35:03
(1 year ago)
Failed login attempt detected by Fail2Ban in plesk-wordpress jail
Exploited Host
๐บ๐ธ
nowyouknow
2025-08-29 13:52:11
(1 year ago)
Phishing
Web Spam
Anonymous
2025-08-23 23:44:23
(1 year ago)
ALTB WEBFORM SPAM 95.38.94.97 (95.38.94.97)
Web Spam
๐ฉ๐ช
rh24
2025-07-10 16:40:15
(1 year ago)
(contact-forms) Failed contact-forms trigger with match [redacted] from 95.38.94.97 (IR/Iran/-): (C ...
show more
(contact-forms) Failed contact-forms trigger with match [redacted] from 95.38.94.97 (IR/Iran/-): (CF_ENABLE)
show less
Hacking
๐ฌ๐ง
Globe2
2025-07-10 13:56:37
(1 year ago)
[10/Jul/2025:14:55:53 +0100] FWedVuqAFI0ZNSem9EOBqMYS 95.38.94.97 10136 91.212.212.13 443
[10/Jul/20 ...
show more
[10/Jul/2025:14:55:53 +0100] FWedVuqAFI0ZNSem9EOBqMYS 95.38.94.97 10136 91.212.212.13 443
[10/Jul/2025:14:56:35 +0100] jWufc5rSOZqGETeZd6fXGI0I 95.38.94.97 15598 91.212.212.13 443
[10/Jul/2025:14:56:36 +0100] Y82PvyNfLZHBLQbUaYNu6iAG 95.38.94.97 47584 91.212.212.13 443
...
show less
Web App Attack
๐ฒ๐พ
Rizzy
2025-07-03 22:43:44
(1 year ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-24 21:02:56
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 95.38.94.97 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 95.38.94.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 24 17:02:49.811838 2025] [security2:error] [pid 51407:tid 51407] [client 95.38.94.97:57883] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barigby.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barigby.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aFsSeXLZeGTcPOwDxhdi1QAAABM"], referer: https://barigby.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-30 21:06:22
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 95.38.94.97 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 95.38.94.97 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 30 17:06:16.131531 2025] [security2:error] [pid 857725:tid 857725] [client 95.38.94.97:40726] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jolankagroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jolankagroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aDodyEyzgCMQCXIuoHTD0QAAABo"], referer: https://jolankagroup.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-05-29 00:42:44
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐จ๐ฟ
unhfree.net
2025-04-25 14:54:02
(1 year ago)
Apr 25 16:53:55 canopus postfix/smtpd[1529354]: 46D1CDC0BE8: reject: RCPT from unknown[95.38.94.97]: ...
show more
Apr 25 16:53:55 canopus postfix/smtpd[1529354]: 46D1CDC0BE8: reject: RCPT from unknown[95.38.94.97]: 554 5.7.1 <[email protected] >: Recipient address rejected: Maximum 20 messages per 60 minutes limit reached; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<localhost>
Apr 25 16:53:55 canopus postfix/smtpd[1529354]: 46D1CDC0BE8: reject: RCPT from unknown[95.38.94.97]: 554 5.7.1 <[email protected] >: Recipient address rejected: Maximum 20 messages per 60 minutes limit reached; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<localhost>
Apr 25 16:53:55 canopus postfix/smtpd[1529354]: 46D1CDC0BE8: reject: RCPT from unknown[95.38.94.97]: 554 5.7.1 <[email protected] >: Recipient address rejected: Maximum 20 messages per 60 minutes limit reached; from=<[email protected] > to=<[email protected] > proto=ESMTP helo=<localhost>
Apr 25 16:54:02 canopus postfix/smtpd[1529354]: NOQUEUE: reject: RCPT from unknown[95.38.94.97]: 554 5.7.
...
show less
Brute-Force
Exploited Host