🇩🇪
Vegascosmetics
2026-09-10 10:56:22
(20 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nest ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after deep/obfuscated attack (encoding nesting / CPU-drain risk). Evidence: High Priority: %25252F
show less
Hacking
Exploited Host
Web App Attack
🇺🇸
abuse-opdc
2026-09-04 20:07:46
(6 days ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
🇲🇽
octageeks.com
2026-09-01 04:20:15
(1 week ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇫🇷
tecnicorioja
2026-08-31 22:01:32
(1 week ago)
wp-login attack [31/Aug/2026:19:31:43
Brute-Force
Web App Attack
🇩🇪
DocNetzwerk
2026-08-31 19:38:11
(1 week ago)
(wordpress) Failed wordpress login from 103.190.47.11 (ID/Indonesia/-)
Brute-Force
Anonymous
2026-08-31 19:30:07
(1 week ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-31 19:16:07
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.190.47.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 103.190.47.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 15:16:00.905175 2026] [security2:error] [pid 30653:tid 30653] [client 103.190.47.11:48462] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cnphilos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cnphilos.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apXS8NN6wmNO8jFk7nurPQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
nyt
2026-08-31 19:02:16
(1 week ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
🇩🇪
karger
2026-08-31 18:55:27
(1 week ago)
Wordpress attack - soft filter
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 18:53:20
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.190.47.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 103.190.47.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 14:53:16.434186 2026] [security2:error] [pid 24687:tid 24687] [client 103.190.47.11:45634] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lambert-heating-and-air.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lambert-heating-and-air.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apXNnHv0zG5rsQhVsT3gJQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 18:37:22
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.190.47.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 103.190.47.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 14:37:14.754210 2026] [security2:error] [pid 10203:tid 10203] [client 103.190.47.11:58178] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newhopepetgrooming.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newhopepetgrooming.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apXJ2mi_rKD78mrTjT_wIQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 18:28:03
(1 week ago)
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/2.0
Hacking
Web App Attack
🇫🇷
Yepngo
2026-08-31 18:24:35
(1 week ago)
103.190.47.11 - - [31/Aug/2026:20:16:24 +0200] "POST /wp-login.php HTTP/2.0" 200 12507 "https://yepn ...
show more
103.190.47.11 - - [31/Aug/2026:20:16:24 +0200] "POST /wp-login.php HTTP/2.0" 200 12507 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
103.190.47.11 - - [31/Aug/2026:20:24:35 +0200] "POST /wp-login.php HTTP/2.0" 200 12500 "https://dev.yepngo.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 18:11:40
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 103.190.47.11 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 103.190.47.11 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 14:11:32.982954 2026] [security2:error] [pid 17849:tid 17849] [client 103.190.47.11:46812] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rimaine.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rimaine.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apXD1IzhmXf_WawCVrn4pQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 18:07:55
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack