🇩🇪
FeG Deutschland
2026-09-14 16:11:54
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇫🇷
Tilellit.PRO
2026-09-14 03:34:48
(23 hours ago)
WP Armour Plugin detection
Web Spam
Brute-Force
🇲🇽
octageeks.com
2026-09-13 04:23:23
(1 day ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇩🇪
netclix.gr
2026-09-13 01:25:31
(2 days ago)
(wordpress) Failed wordpress login from 112.145.202.119 (KR/South Korea/-): (CF_ENABLE)
Brute-Force
🇫🇷
✨
2026-09-13 01:15:12
(2 days ago)
Domain : ability6.com
Rule : wp-login
2026-09-13 01:13:33 ***hidden-privacy*** GET /wp-login.php - 4 ...
show more
Domain : ability6.com
Rule : wp-login
2026-09-13 01:13:33 ***hidden-privacy*** GET /wp-login.php - 443 - 112.145.202.119 HTTP/2 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36 - ability6.com 404 0 0 104603 694 1985 - -
show less
Web App Attack
🇩🇪
FeG Deutschland
2026-09-12 22:31:23
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
Anonymous
2026-09-12 16:02:45
(2 days ago)
(wordpress) Failed wordpress login from 112.145.202.119 (KR/South Korea/-)
Brute-Force
🇺🇸
nyt
2026-09-12 15:56:39
(2 days ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
🇩🇪
LRob
2026-09-11 18:41:55
(3 days ago)
WordPress login brute-force | path: /wp-fi/wp-login.php (+1 more) | 2026-09-11 18:41 UTC
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:50:45
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 112.145.202.119 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 112.145.202.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:50:36.178081 2026] [security2:error] [pid 23625:tid 23625] [client 112.145.202.119:45052] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||become-a-medicalsalesrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "become-a-medicalsalesrep.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqQxXIFmhu57cETBIUzC5AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-11 15:31:54
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 19:35:48
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 112.145.202.119 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 112.145.202.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 15:35:41.263529 2026] [security2:error] [pid 14138:tid 14157] [client 112.145.202.119:50526] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||inal.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "inal.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aqMGjefchYIXkapTqOnOfgAAAVE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
AlexEventfahrtenIPDB
2026-09-10 01:55:11
(5 days ago)
[Thu Sep 10 03:55:07.439214 2026] [authz_core:error] [pid 900397:tid 900426] [remote 112.145.202.119 ...
show more
[Thu Sep 10 03:55:07.439214 2026] [authz_core:error] [pid 900397:tid 900426] [remote 112.145.202.119:45128] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php
[Thu Sep 10 03:55:11.647011 2026] [authz_core:error] [pid 900397:tid 900428] [remote 112.145.202.119:45276] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/
...
show less
Brute-Force
Web App Attack
🇩🇪
LRob
2026-09-09 14:01:06
(5 days ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /wp-login.php | 2026-09-09 14:01 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 05:16:39
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 112.145.202.119 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 112.145.202.119 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:16:36.145386 2026] [security2:error] [pid 24129:tid 24129] [client 112.145.202.119:59794] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||robinsnestingplace.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "robinsnestingplace.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDrtB_gPzQvT0IBFKPWmgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack