Anonymous
2026-08-31 17:37:03
(4 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-login.php HTTP/2.0, [2/2] done, POST /wp-login.php H ...
show more
Bot / scanning and/or hacking attempts: GET /wp-login.php HTTP/2.0, [2/2] done, POST /wp-login.php HTTP/2.0
show less
Hacking
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-31 04:34:02
(17 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ซ๐ท
tecnicorioja
2026-08-30 22:00:24
(1 day ago)
wp-login attack [30/Aug/2026:17:30:51
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-08-30 16:35:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-30 13:12:41
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
LRob
2026-08-30 12:30:55
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-30 12:30 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
omc
2026-08-30 03:07:14
(1 day ago)
GET /wp-json/buddypress/v1/members [Q4].
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-08-30 02:47:25
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-29 21:28:57
(2 days ago)
cloudlinux2 fail2ban: 2026-08-29 23:24:15,553 fail2ban.filter [1478]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-29 23:24:15,553 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 193.36.224.114 - 2026-08-29 23:24:15cloudlinux2 fail2ban: 2026-08-29 23:24:20,461 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 193.36.224.114 - 2026-08-29 23:24:19cloudlinux2 fail2ban: 2026-08-29 23:24:18,846 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 14.160.25.150 - 2026-08-29 23:24:18cloudlinux2 fail2ban: 2026-08-29 23:24:35,879 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 14.128.14.2 - 2026-08-29 23:24:35cloudlinux2 fail2ban: 2026-08-29 23:24:53,025 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 136.144.19.241 - 2026-08-29 23:24:52cloudlinux2 fail2ban: 2026-08-29 23:24:58,752 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 136.144.43.8 - 2026-08-29 23:24:58cloudlinux2 fail2ban: 2026-08-29 23:26:25,325 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 136.144.42.39 - 2026-08-29 23:26:24cloud
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 10:34:45
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 14.128.14.2 (bdserver1.instrawebs.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 14.128.14.2 (bdserver1.instrawebs.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 06:34:39.981593 2026] [security2:error] [pid 30566:tid 30566] [client 14.128.14.2:59508] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||doctorbalog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "doctorbalog.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apK1v4c52I8bns3bTJ__2gAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-29 06:26:23
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 02:32:22
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 14.128.14.2 (bdserver1.instrawebs.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 14.128.14.2 (bdserver1.instrawebs.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 22:32:14.215129 2026] [security2:error] [pid 7584:tid 7584] [client 14.128.14.2:59556] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pastorjohndunning.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pastorjohndunning.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apJErlS5X53BetjtqMRREQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-29 00:36:24
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
๐ฒ๐น
Malta
2026-08-28 22:49:07
(2 days ago)
14.128.14.2 - - [29/Aug/2026:00:49:06 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
14.128.14.2 - - [29/Aug/2026:00:49:06 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-28 20:28:21
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 14.128.14.2 (bdserver1.instrawebs.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 14.128.14.2 (bdserver1.instrawebs.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:28:16.496045 2026] [security2:error] [pid 16146:tid 16146] [client 14.128.14.2:50452] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stonehill.myomni.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stonehill.myomni.us"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apHvYHHNAopRea35CouSzQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack