🇨🇦
polycoda
2026-09-08 09:49:19
(11 hours ago)
🔑 Wordpress login brute force attempt
Hacking
Web App Attack
🇬🇧
Steve
2026-09-08 09:34:55
(11 hours ago)
Repeated attempts against wordpress site
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:04:14
(11 hours ago)
(mod_security) mod_security (id:217210) triggered by 109.111.36.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 109.111.36.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:04:09.840580 2026] [security2:error] [pid 20863:tid 20863] [client 109.111.36.57:31957] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||themediaplanet.com|F|4"] [data "GET http://themediaplanet.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "themediaplanet.com"] [uri "/"] [unique_id "ap_Pie44ZOQYwtTu6tUqUwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 07:42:16
(13 hours ago)
(mod_security) mod_security (id:217210) triggered by 109.111.36.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 109.111.36.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:42:09.339024 2026] [security2:error] [pid 12531:tid 12606] [client 109.111.36.57:48017] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||meeker.us|F|4"] [data "GET http://meeker.us HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "meeker.us"] [uri "/"] [unique_id "ap-8Uc4OKonD9cWfTFTMxQAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 07:29:10
(13 hours ago)
Web application attack detected.
Web App Attack
🇮🇹
VHosting
2026-09-08 05:10:03
(15 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇧🇪
voormedia
2026-09-08 04:53:19
(16 hours ago)
Accessed trap at '/wp-login.php'
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:44:35
(17 hours ago)
(mod_security) mod_security (id:217210) triggered by 109.111.36.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 109.111.36.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:44:32.425800 2026] [security2:error] [pid 27508:tid 27508] [client 109.111.36.57:59956] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||dietzengineers.com|F|4"] [data "GET http://dietzengineers.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dietzengineers.com"] [uri "/"] [unique_id "ap-EoA_L53REWH_sYPBUTQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-08 02:05:17
(18 hours ago)
Xmlrpc Caught (10)
Brute-Force
Web App Attack
🇨🇦
DRI
2026-09-07 19:31:55
(1 day ago)
Web attack/Malicious activity detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:33:53
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 109.111.36.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 109.111.36.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:33:48.043038 2026] [security2:error] [pid 612047:tid 612070] [client 109.111.36.57:52657] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gryphix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gryphix.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ap7nbATxzc63XGIzqud2uAAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:51:02
(1 day ago)
(mod_security) mod_security (id:217210) triggered by 109.111.36.57 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217210) triggered by 109.111.36.57 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:50:58.505018 2026] [security2:error] [pid 9343:tid 9343] [client 109.111.36.57:37799] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||wallpaperpro.com|F|4"] [data "ET http://wallpaperpro.com/robots.txt HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wallpaperpro.com"] [uri "/robots.txt"] [unique_id "ap6zMjXxLe9vEy3vAAjjFQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack