🇩🇪
LRob
2026-09-09 16:10:22
(18 hours ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-09 16:10 UTC
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-09-09 05:46:15
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇧🇪
brechtr
2026-09-09 05:41:53
(1 day ago)
[Press84-BanHammer] bad username — Sourced from: brechtryckaert.com — Request: POST /wp-login.php
Brute-Force
🇮🇹
CoreTech srl
2026-09-09 05:23:57
(1 day ago)
cloudlinux2 fail2ban: 2026-09-09 07:19:06,276 fail2ban.filter [1892]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-09 07:19:06,276 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 150.107.173.185 - 2026-09-09 07:19:06cloudlinux2 fail2ban: 2026-09-09 07:19:45,255 fail2ban.filter [1892]: INFO [plesk-proftpd] Found 138.197.194.83 - 2026-09-09 07:19:45cloudlinux2 fail2ban: 2026-09-09 07:20:34,901 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 193.36.225.175 - 2026-09-09 07:20:34cloudlinux2 fail2ban: 2026-09-09 07:21:03,532 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 45.92.229.75 - 2026-09-09 07:21:02cloudlinux2 fail2ban: 2026-09-09 07:21:09,631 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 62.250.124.10 - 2026-09-09 07:21:09cloudlinux2 fail2ban: 2026-09-09 07:21:54,251 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 142.111.152.49 - 2026-09-09 07:21:53cloudlinux2 fail2ban: 2026-09-09 07:22:10,699 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Unban 9.246.91.150cloudlinux2 fail2ban: 20
show less
FTP Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:11:20
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 115.66.183.149 (bb115-66-183-149.singnet.com.sg ...
show more
(mod_security) mod_security (id:225170) triggered by 115.66.183.149 (bb115-66-183-149.singnet.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:11:15.873074 2026] [security2:error] [pid 14993:tid 14993] [client 115.66.183.149:37848] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bikiniadvice.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bikiniadvice.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCyMzcwp8r6yCxPsDk9DQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
spamverify.com
2026-09-09 00:17:11
(1 day ago)
Honeypot Hit: WordPress Users
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
🇩🇪
F242
2026-09-08 22:09:59
(1 day ago)
Wordpress Login or XMLRPC abuse
Web App Attack
🇩🇪
london2038.com
2026-09-08 22:00:07
(1 day ago)
Probing for exploits
115.66.183.149 - - [09/Sep/2026:00:00:02 +0200] "GET /wp-login.php HTTP/2.0" 30 ...
show more
Probing for exploits
115.66.183.149 - - [09/Sep/2026:00:00:02 +0200] "GET /wp-login.php HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
115.66.183.149 - - [09/Sep/2026:00:00:05 +0200] "POST /wp-login.php HTTP/2.0" 301 0 "https://v97746.<REDACTED>/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:55:30
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 115.66.183.149 (bb115-66-183-149.singnet.com.sg ...
show more
(mod_security) mod_security (id:225170) triggered by 115.66.183.149 (bb115-66-183-149.singnet.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:55:24.074133 2026] [security2:error] [pid 10505:tid 10505] [client 115.66.183.149:36638] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||coyotebytes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "coyotebytes.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBoLMRJUuKWlmCh_QTLYgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:05:42
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 115.66.183.149 (bb115-66-183-149.singnet.com.sg ...
show more
(mod_security) mod_security (id:225170) triggered by 115.66.183.149 (bb115-66-183-149.singnet.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:05:36.731138 2026] [security2:error] [pid 32447:tid 32447] [client 115.66.183.149:43522] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mccompu.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mccompu.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAWMEoz9w7bu2dIid_-gwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
stinpriza
2026-09-08 13:58:07
(1 day ago)
Web App Attack
Web App Attack
🇩🇪
LRob
2026-09-08 06:03:27
(2 days ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-08 06:03 UTC
Brute-Force
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-08 04:19:45
(2 days ago)
WordPress login attempt
Brute-Force
🇩🇪
georgengelmann
2026-09-07 20:57:01
(2 days ago)
Failed login attempt for bchpls
Brute-Force
Web App Attack
🇺🇸
lostswordfish.com
2026-09-07 18:20:05
(2 days ago)
Wordfence waf block on secure2024 libjusco
Web App Attack