Anonymous
2026-09-10 21:57:46
(11 minutes ago)
(wordpress) Failed wordpress login from 146.70.10.7 (CR/Costa Rica/Provincia de San José/San José/-/ ...
show more
(wordpress) Failed wordpress login from 146.70.10.7 (CR/Costa Rica/Provincia de San José/San José/-/[redacted])
show less
Brute-Force
🇩🇪
voemedia
2026-09-10 21:29:48
(39 minutes ago)
(wordpress) Failed wordpress login from 146.70.10.7 (CR/Costa Rica/-)
Brute-Force
🇮🇹
CoreTech srl
2026-09-10 21:28:57
(40 minutes ago)
cloudlinux2 fail2ban: 2026-09-10 23:23:56,814 fail2ban.actions [1892]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-10 23:23:56,814 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Ban 35.228.25.104cloudlinux2 fail2ban: 2026-09-10 23:23:56,754 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 35.228.25.104 - 2026-09-10 23:23:56cloudlinux2 fail2ban: 2026-09-10 23:23:56,822 fail2ban.filter [1892]: INFO [recidive] Found 35.228.25.104 - 2026-09-10 23:23:56cloudlinux2 fail2ban: 2026-09-10 23:23:56,764 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 35.228.25.104 - 2026-09-10 23:23:56cloudlinux2 fail2ban: 2026-09-10 23:23:55,922 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 146.70.10.7 - 2026-09-10 23:23:55cloudlinux2 fail2ban: 2026-09-10 23:23:56,788 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 35.228.25.104 - 2026-09-10 23:23:56cloudlinux2 fail2ban: 2026-09-10 23:24:19,047 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 34.118.175.50 - 2026-09-10 23:24:19cloudlinux2 fail2ban: 2026-09-
show less
Brute-Force
🇦🇺
A.i.D.A.N.N
2026-09-10 21:23:10
(46 minutes ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
🇩🇪
4server
2026-09-10 20:57:25
(1 hour ago)
[ThuSep1022:57:23.0670132026][security2:error][pid789951:tid789981][client146.70.10.7:0]ModSecurity: ...
show more
[ThuSep1022:57:23.0670132026][security2:error][pid789951:tid789981][client146.70.10.7:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"studio-portale.ch\"][uri\"/xmlrpc.php\"][unique_id\"aqMZs5zA_Spjmmhjr4oOngAAANM\"]
show less
Port Scan
Brute-Force
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-10 20:40:36
(1 hour ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
GB/United Kingdom/-
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 20:30:39
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 146.70.10.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.10.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 16:30:31.747555 2026] [security2:error] [pid 29573:tid 29573] [client 146.70.10.7:22050] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||activethinkers.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "activethinkers.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqMTZ3DRKvCBYvFTFUDsQgAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 20:12:08
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 146.70.10.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.10.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 16:12:03.449842 2026] [security2:error] [pid 5599:tid 5599] [client 146.70.10.7:32470] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.michelehoop.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqMPExAW8P88GuMhfIFGsAAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-10 20:08:53
(2 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-10 19:52:22
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 146.70.10.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.10.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 15:52:16.339268 2026] [security2:error] [pid 19569:tid 19569] [client 146.70.10.7:22127] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.doctorbalog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.doctorbalog.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqMKcPde7lPPRU78qi8ADQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
maxxsense
2026-09-10 19:49:21
(2 hours ago)
(wordpress) Failed wordpress login from 146.70.10.7 (CR/Costa Rica/-)
Brute-Force
🇩🇪
palla89
2026-09-10 19:47:12
(2 hours ago)
(wordpress) Failed wordpress login from 146.70.10.7 (CR/Costa Rica/-)
Brute-Force
🇺🇸
TPI-Abuse
2026-09-10 19:32:54
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 146.70.10.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.10.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 15:32:47.178558 2026] [security2:error] [pid 10860:tid 10860] [client 146.70.10.7:6887] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fusionrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fusionrep.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqMF35xEi_6I99JIQbW61gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
BRHosting
2026-09-10 19:16:06
(2 hours ago)
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 19:10:53
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 146.70.10.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.10.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 15:10:47.761781 2026] [security2:error] [pid 26977:tid 26977] [client 146.70.10.7:19318] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.konahawaiirealty.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.konahawaiirealty.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqMAt6k4vj-NZ7SuT8w5qAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack