🇩🇪
neckaralb-admin.de
2026-09-09 01:05:37
(8 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:42:20
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 125.163.153.251 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.153.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:42:11.535339 2026] [security2:error] [pid 11054:tid 11054] [client 125.163.153.251:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||southernbroadcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "southernbroadcast.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCdU52AaKxFy-DDuzaz3QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-08 22:20:24
(2 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:20:19
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 125.163.153.251 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.153.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:20:12.351454 2026] [security2:error] [pid 29408:tid 29408] [client 125.163.153.251:40622] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||puckerbuttbikinis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "puckerbuttbikinis.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCKHNq8p3Dr9Yzg4wJ2IAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
cwytech
2026-09-08 22:17:13
(2 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
🇺🇸
etu brutus
2026-09-08 21:12:34
(4 hours ago)
125.163.153.251 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:03:42
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 125.163.153.251 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.153.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:03:37.865952 2026] [security2:error] [pid 22223:tid 22223] [client 125.163.153.251:60342] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thorndikestudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thorndikestudio.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBcCddzqy5iFrXZk0HN2gAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
JRID
2026-09-08 17:46:04
(7 hours ago)
Detected by CrowdSec + Suricata IDS: automated attack/scan against web servers.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:06:39
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 125.163.153.251 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.153.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:06:34.120709 2026] [security2:error] [pid 22778:tid 22778] [client 125.163.153.251:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ipv6.rodrigoaldecoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ipv6.rodrigoaldecoa.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAyiha6JpgdHnOGUn5UbAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
spamverify.com
2026-09-08 15:46:41
(9 hours ago)
Honeypot Hit: WordPress Users
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
🇩🇪
thesimonmanuel
2026-09-08 15:07:55
(10 hours ago)
125.163.153.251 - [redacted] [08/Sep/2026:20:37:55 +0530] "GET /wp-json/wp/v2/users/me HTTP/2.0" 401 ...
show more
125.163.153.251 - [redacted] [08/Sep/2026:20:37:55 +0530] "GET /wp-json/wp/v2/users/me HTTP/2.0" 401 96 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:40:51
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 125.163.153.251 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 125.163.153.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:40:44.199960 2026] [security2:error] [pid 2340:tid 2340] [client 125.163.153.251:52442] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tasteshop.l3l4.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tasteshop.l3l4.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAebHB5fQi5DMgebDx-PwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
stinpriza
2026-09-08 14:17:53
(10 hours ago)
Web App Attack
Web App Attack
🇩🇪
LRob
2026-09-08 13:45:33
(11 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | 2026-09-08 13:45 UTC
show less
Hacking
Web App Attack
🇺🇸
www.winos.me
2026-09-08 13:44:07
(11 hours ago)
Scanning for sensitive files/paths: /wp-login.php
Hacking
Web App Attack