🇩🇪
Hazzard
2026-09-09 05:30:35
(7 hours ago)
(wordpress) Failed wordpress login from 103.252.201.35 (SG/Singapore/-/Singapore/35-201-252-103.myre ...
show more
(wordpress) Failed wordpress login from 103.252.201.35 (SG/Singapore/-/Singapore/35-201-252-103.myrepublic.com.sg/[redacted]): (CF_ENABLE)
show less
Brute-Force
🇩🇪
ger-stg-sifi1
2026-09-09 04:18:33
(8 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇲🇽
octageeks.com
2026-09-09 04:14:22
(8 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇫🇮
stinpriza
2026-09-09 02:16:03
(10 hours ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:11:33
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.s ...
show more
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:11:27.736004 2026] [security2:error] [pid 19630:tid 19630] [client 103.252.201.35:19236] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lgbtqhistoryinaustin.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lgbtqhistoryinaustin.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCyP21gr8Yd2wQiQgE4gwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:48:50
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.s ...
show more
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:48:44.135250 2026] [security2:error] [pid 10868:tid 10868] [client 103.252.201.35:19340] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.joelyaucom.studioyau.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.joelyaucom.studioyau.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCs7KssGGo7YYTYwJ3pwwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-09 00:37:09
(12 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:23:27
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.s ...
show more
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:23:23.075045 2026] [security2:error] [pid 2513:tid 2513] [client 103.252.201.35:19304] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mavikalem.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mavikalem.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCK28rJn9r-qLSdgzJV7AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 21:22:53
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.s ...
show more
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:22:47.084327 2026] [security2:error] [pid 5825:tid 5825] [client 103.252.201.35:56273] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blog.l3l4.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blog.l3l4.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqB8p4keayUQXekgTYbfNgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
spamverify.com
2026-09-08 20:57:53
(16 hours ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 19:43:55
(17 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-json/wp/v2/users/me | 2026- ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-json/wp/v2/users/me | 2026-09-08 19:43 UTC
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:50:20
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.s ...
show more
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:50:14.408587 2026] [security2:error] [pid 22829:tid 22829] [client 103.252.201.35:19632] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||clcmillvale.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "clcmillvale.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBY5uOW9aKoP5Tdo-6_yQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 17:42:16
(19 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /wp-json/wp/v2/users/me | 2026-09-08 17:42 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 16:41:18
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.s ...
show more
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:41:13.841477 2026] [security2:error] [pid 1728:tid 1728] [client 103.252.201.35:19403] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stacyfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stacyfarm.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqA6qU3CEA0bvBDyaez2cwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:08:12
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.s ...
show more
(mod_security) mod_security (id:225170) triggered by 103.252.201.35 (35-201-252-103.myrepublic.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:08:05.657393 2026] [security2:error] [pid 20652:tid 20678] [client 103.252.201.35:56433] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||scottspencergfx.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "scottspencergfx.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAWxSJrt-w5IaZiWyqvzwAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack