Anonymous
2026-09-10 10:21:47
(1 hour ago)
133.209.13.3 - - [10/Sep/2026:12:21:39 +0200] "GET /wp-login.php HTTP/2.0" 200 4318 "-" "Mozilla/5.0 ...
show more
133.209.13.3 - - [10/Sep/2026:12:21:39 +0200] "GET /wp-login.php HTTP/2.0" 200 4318 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-10 03:45:11
(7 hours ago)
Web attack blocked by Wordfence on limburgsekunstkring.nl (3 hits). Reported by CRMON.
Web App Attack
🇩🇪
FeG Deutschland
2026-09-10 02:56:13
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇩🇪
netclix.gr
2026-09-09 17:59:14
(17 hours ago)
(wordpress) Failed wordpress login from 133.209.13.3 (JP/Japan/flh2-133-209-13-3.tky.mesh.ad.jp): ( ...
show more
(wordpress) Failed wordpress login from 133.209.13.3 (JP/Japan/flh2-133-209-13-3.tky.mesh.ad.jp): (CF_ENABLE)
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-09 06:34:51
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp) ...
show more
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:34:43.727462 2026] [security2:error] [pid 7529:tid 7529] [client 133.209.13.3:24404] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jacquelineperriam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jacquelineperriam.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqD-Awfuggdhg0oOCN7pgwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
SpamStopper
2026-09-09 06:29:19
(1 day ago)
Fail2Ban - WP Spoofing
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:19:49
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp) ...
show more
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:19:43.850958 2026] [security2:error] [pid 30659:tid 30659] [client 133.209.13.3:20316] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||travelwithjenniferb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "travelwithjenniferb.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDsb_oxVLGw-7QvK15eoQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-09 04:44:35
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:01:30
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp) ...
show more
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:01:23.884637 2026] [security2:error] [pid 15329:tid 15329] [client 133.209.13.3:8017] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||instalatoribucuresti.com.apexhumanoidrobots.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "instalatoribucuresti.com.apexhumanoidrobots.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDaE8QRxCZZQatR4keyswAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:32:38
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp) ...
show more
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:32:32.976218 2026] [security2:error] [pid 13174:tid 13174] [client 133.209.13.3:8024] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||xyncom.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "xyncom.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDFQFxQn2dh9WbM5EO8cAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:07:34
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp) ...
show more
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:07:29.537526 2026] [security2:error] [pid 12443:tid 12443] [client 133.209.13.3:28511] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geckoturner.chezlubacov.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geckoturner.chezlubacov.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC_YdlCVc0uCVhYgJCLOQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 21:59:37
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp) ...
show more
(mod_security) mod_security (id:225170) triggered by 133.209.13.3 (flh2-133-209-13-3.tky.mesh.ad.jp): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:59:32.632637 2026] [security2:error] [pid 16651:tid 16684] [client 133.209.13.3:32595] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.gipsongrocerystore.digital4z.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.gipsongrocerystore.digital4z.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCFRHIWtk-iI_fSdec_WQAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 21:44:22
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇩🇪
LRob
2026-09-08 19:47:13
(1 day ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-08 19:47 UTC
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 14:58:51
(1 day ago)
cloudlinux2 fail2ban: 2026-09-08 16:54:15,371 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-08 16:54:15,371 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 173.239.213.53 - 2026-09-08 16:54:14cloudlinux2 fail2ban: 2026-09-08 16:54:32,268 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 185.251.19.168 - 2026-09-08 16:54:30cloudlinux2 fail2ban: 2026-09-08 16:54:43,694 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.148.11.4 - 2026-09-08 16:54:43cloudlinux2 fail2ban: 2026-09-08 16:54:50,776 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 34.148.11.4 - 2026-09-08 16:54:50cloudlinux2 fail2ban: 2026-09-08 16:54:46,410 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 133.209.13.3 - 2026-09-08 16:54:46cloudlinux2 fail2ban: 2026-09-08 16:55:01,659 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 45.146.55.104 - 2026-09-08 16:55:01cloudlinux2 fail2ban: 2026-09-08 16:55:14,942 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 142.111.152.181 - 2026-09-08 16:55:14clou
show less
Web App Attack