Anonymous
2026-06-15 04:46:13
(3 days ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2026-06-12 11:46:05
(6 days ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2026-06-11 02:46:11
(1 week ago)
Failed Wordpress Logins
Web App Attack
π§πͺ
Ivo Vynckier
2026-06-10 09:55:00
(1 week ago)
13.223.247.142 - - [09/Jun/2026:11:49:50 +0200] "GET /wp-includes/css/buttons.css HTTP/1.1" 301 313 ...
show more
13.223.247.142 - - [09/Jun/2026:11:49:50 +0200] "GET /wp-includes/css/buttons.css HTTP/1.1" 301 313 "-" "Go-http-client/1.1"
13.223.247.142 - - [09/Jun/2026:11:49:50 +0200] "GET /media/system/js/core.js HTTP/1.1" 301 309 "-" "Go-http-client/1.1"
show less
Web App Attack
π©πͺ
LRob.fr
2026-06-10 06:00:23
(1 week ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
π©πͺ
LRob.fr
2026-06-10 05:45:11
(1 week ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
πͺπΈ
ofm-abuse
2026-06-10 05:20:35
(1 week ago)
Brute-force
...
Brute-Force
Web App Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-09 20:13:43
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 13.223.247.142 (ec2-13-223-247-142.compute-1.am ...
show more
(mod_security) mod_security (id:225170) triggered by 13.223.247.142 (ec2-13-223-247-142.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 16:13:38.227277 2026] [security2:error] [pid 27234:tid 27234] [client 13.223.247.142:64915] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.healthmarkcounseling.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.healthmarkcounseling.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aihz8qQ2VUXL9HpbCXZFhAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
WeekendWeb
2026-06-09 20:13:20
(1 week ago)
Wordpress Vunerability attack
Web App Attack
πΈπͺ
vaia.cloud
2026-06-09 20:13:02
(1 week ago)
trying wp-login.php/xmlrpc.php 36 times in 1 minutes
Brute-Force
Web App Attack
π¨π¦
Dunham Support
2026-06-09 19:38:52
(1 week ago)
(wordpress) Failed wordpress login from 13.223.247.142 (US/United States/ec2-13-223-247-142.compute- ...
show more
(wordpress) Failed wordpress login from 13.223.247.142 (US/United States/ec2-13-223-247-142.compute-1.amazonaws.com)
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-09 19:34:52
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 13.223.247.142 (ec2-13-223-247-142.compute-1.am ...
show more
(mod_security) mod_security (id:225170) triggered by 13.223.247.142 (ec2-13-223-247-142.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 15:34:45.341990 2026] [security2:error] [pid 7289:tid 7289] [client 13.223.247.142:58022] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cathybermanmft.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cathybermanmft.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aihq1dMTGw0b-ffoXtqfJQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
netclix.gr
2026-06-09 19:33:23
(1 week ago)
(wordpress) Failed wordpress login from 13.223.247.142 (US/United States/ec2-13-223-247-142.compute- ...
show more
(wordpress) Failed wordpress login from 13.223.247.142 (US/United States/ec2-13-223-247-142.compute-1.amazonaws.com): (CF_ENABLE)
show less
Brute-Force
π«π·
dynamix
2026-06-09 19:16:48
(1 week ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 19:13:23
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 13.223.247.142 (ec2-13-223-247-142.compute-1.am ...
show more
(mod_security) mod_security (id:225170) triggered by 13.223.247.142 (ec2-13-223-247-142.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 15:13:17.068502 2026] [security2:error] [pid 8696:tid 8696] [client 13.223.247.142:53897] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rwabutazafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rwabutazafoundation.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aihlzdIPkV4cHhEt0kn1VQAAAG0"]
show less
Brute-Force
Bad Web Bot
Web App Attack