Anonymous
2026-10-08 10:10:25
(3 days ago)
fail2ban: brute-force/credential spraying against mail (IMAP/POP/webmail) โ rmnet.it
Brute-Force
๐จ๐ฆ
Anytech
2026-10-08 04:38:20
(3 days ago)
Blocked by Conn-Monitor: Contradicting Fingerprint
Bad Web Bot
Web App Attack
Hacking
Spoofing
๐ณ๐ฑ
GES
2026-10-08 03:59:42
(3 days ago)
Brute force login detected (10 failed attempts in 300s). Auto-blocked by XUI Shield.
DDoS Attack
Port Scan
๐ง๐ช
cmbplf
2026-10-08 02:04:20
(3 days ago)
3.658 requests from abuseipdb.com blacklisted IP (1w6d23h)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-08 00:27:38
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 207.180.254.56 (56.254.180.207.in-addr.arpa): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 207.180.254.56 (56.254.180.207.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:27:34.667331 2026] [security2:error] [pid 10148:tid 10148] [client 207.180.254.56:42484] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.garantaconsulting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.garantaconsulting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asbjdoUiW2TK2gx8LpHF4wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
GES
2026-10-08 00:19:28
(3 days ago)
Credential scanning on player_api.php (5 distinct logins in 120s). Auto-blocked by XUI Shield.
DDoS Attack
Port Scan
๐ต๐ฑ
Budyn
2026-10-07 22:17:07
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: goblinpot.online | URI: /.env.prod | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/125.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 21:51:04
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 207.180.254.56 (56.254.180.207.in-addr.arpa): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 207.180.254.56 (56.254.180.207.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:51:00.584197 2026] [security2:error] [pid 22380:tid 22380] [client 207.180.254.56:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||package.cloudex.click|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "package.cloudex.click"] [uri "/wp-json/wp/v2/users"] [unique_id "asa-xIig5UMlzUtp8v2t_QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 17:30:11
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 207.180.254.56 (56.254.180.207.in-addr.arpa): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 207.180.254.56 (56.254.180.207.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 13:30:06.065258 2026] [security2:error] [pid 28894:tid 28894] [client 207.180.254.56:32836] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||makaihe.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "makaihe.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asaBnocQfaFd8Ct38QjVvgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRob
2026-10-07 11:24:09
(3 days ago)
Web exploit attempt | method: GET | path: /wp-json/wp/v2/users | ua: Mozilla/5.0 (Windows NT 10.0; W ...
show more
Web exploit attempt | method: GET | path: /wp-json/wp/v2/users | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
๐บ๐ธ
Jason Howell
2026-10-07 09:53:42
(4 days ago)
207.180.254.56 - - [07/Oct/2026:04:53:36 -0500] "GET /wp-login.php HTTP/1.1" 200 5531 "https://www.d ...
show more
207.180.254.56 - - [07/Oct/2026:04:53:36 -0500] "GET /wp-login.php HTTP/1.1" 200 5531 "https://www.devilsglenstorage.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
207.180.254.56 - - [07/Oct/2026:04:53:37 -0500] "POST /wp-login.php HTTP/1.1" 200 1950 "https://www.devilsglenstorage.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
207.180.254.56 - - [07/Oct/2026:04:53:39 -0500] "GET /wp-login.php HTTP/1.1" 200 1568 "https://www.devilsglenstorage.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
207.180.254.56 - - [07/Oct/2026:04:53:41 -0500] "POST /wp-login.php HTTP/1.1" 200 1950 "https://www.devilsglenstorage.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
207.180.254.56 - - [07/Oct/2026:04:53:41 -0500] "GET /wp-login.php HTTP/1.1" 200 1568 "https://www.devilsglenstorage.com/wp-lo
...
show less
Web App Attack
Anonymous
2026-10-07 09:50:04
(4 days ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-07 08:02:07
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 207.180.254.56 (56.254.180.207.in-addr.arpa): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 207.180.254.56 (56.254.180.207.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 04:02:01.324837 2026] [security2:error] [pid 31719:tid 31719] [client 207.180.254.56:57900] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marv.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marv.us"] [uri "/wp-json/wp/v2/users"] [unique_id "asX8eTNXd1a-7OF_TJtwoQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-10-07 07:58:36
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 01:00:33
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 207.180.254.56 (56.254.180.207.in-addr.arpa): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 207.180.254.56 (56.254.180.207.in-addr.arpa): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 21:00:29.535126 2026] [security2:error] [pid 14710:tid 14710] [client 207.180.254.56:55318] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nekstlevel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nekstlevel.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asWZrfDX7lVW-O2ZtA0AnwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack