๐บ๐ธ
entangled_mongoose
2026-10-07 07:18:11
(3 hours ago)
Probed /wp-login.php.
Web App Attack
๐ณ๐ฑ
MacLotsen
2026-10-07 06:09:52
(4 hours ago)
146.70.198.231 - - [07/Oct/2026:08:09:28 +0200] "POST /wp-login.php HTTP/1.1" 200 4410 "https://afke ...
show more
146.70.198.231 - - [07/Oct/2026:08:09:28 +0200] "POST /wp-login.php HTTP/1.1" 200 4410 "https://afkewiersma.nl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15"
146.70.198.231 - - [07/Oct/2026:08:09:35 +0200] "POST /wp-login.php HTTP/1.1" 200 4424 "https://afkewiersma.nl/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36"
146.70.198.231 - - [07/Oct/2026:08:09:37 +0200] "POST /wp-login.php HTTP/1.1" 200 4422 "https://afkewiersma.nl/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
146.70.198.231 - - [07/Oct/2026:08:09:39 +0200] "POST /wp-login.php HTTP/1.1" 200 4424 "https://afkewiersma.nl/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
146.70.198.231 - - [07/Oct/2026:08:09:41 +0200] "POST /wp-lo
...
show less
Web App Attack
Brute-Force
๐ง๐ช
taivas.nl
2026-10-07 04:33:02
(6 hours ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 03:42:42
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 146.70.198.231 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.198.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 23:42:35.021629 2026] [security2:error] [pid 15859:tid 15859] [client 146.70.198.231:62996] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||k2servicesinc.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "k2servicesinc.net"] [uri "/wp-json/wp/v2/users"] [unique_id "asW_q3faOrCdnOfJsbn0-AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 03:24:47
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 146.70.198.231 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.198.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 23:24:42.463924 2026] [security2:error] [pid 3292357:tid 3292383] [client 146.70.198.231:56295] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.gryphix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.gryphix.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asW7etNMsGpZFjO_eWfj8wAAAFc"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 03:00:00
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 146.70.198.231 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.198.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:59:54.674277 2026] [security2:error] [pid 8838:tid 8838] [client 146.70.198.231:58484] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.rootsofwellnessayurveda.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.rootsofwellnessayurveda.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asW1quLOFy2bk9V-qMJQkQAAAAQ"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
lns.bz
2026-10-07 02:41:55
(8 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:33:54
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 146.70.198.231 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.198.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:33:47.594793 2026] [security2:error] [pid 23945:tid 23945] [client 146.70.198.231:59570] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||annropp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "annropp.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asWvi4mtDLp3IHcjx8CwwwAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
tentwentyfour
2026-10-07 02:21:57
(8 hours ago)
Blocked for brute-forcing WordPress log-in
Brute-Force
Web App Attack
๐ฉ๐ช
palzer.IT
2026-10-07 02:19:53
(8 hours ago)
Fail2ban automatic report for plesk-wordpress: 146.70.198.231 - - [07/Oct/2026:04:19:21 +0200] POST ...
show more
Fail2ban automatic report for plesk-wordpress: 146.70.198.231 - - [07/Oct/2026:04:19:21 +0200] POST /wp-login.php [DOMAIN_REMOVED] 200 8954 [DOMAIN_REMOVED] Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:119.0) Gecko/20100101 Firefox/119.0
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-07 02:16:54
(8 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ซ๐ฎ
bittiguru.fi
2026-10-07 02:03:03
(8 hours ago)
146.70.198.231 - [07/Oct/2026:05:02:32 +0300] "POST /wp-login.php HTTP/1.1" 403 3022 "https://www.co ...
show more
146.70.198.231 - [07/Oct/2026:05:02:32 +0300] "POST /wp-login.php HTTP/1.1" 403 3022 "https://www.connectingeuropeans.eu/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15" "3.12"
146.70.198.231 - [07/Oct/2026:05:02:40 +0300] "POST /wp-login.php HTTP/1.1" 404 9215 "https://www.connectingeuropeans.eu/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0" "3.66"
146.70.198.231 - [07/Oct/2026:05:02:47 +0300] "POST /wp-login.php HTTP/1.1" 403 754 "https://www.connectingeuropeans.eu/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36" "2.37"
146.70.198.231 - [07/Oct/2026:05:02:54 +0300] "POST /wp-login.php HTTP/1.1" 403 754 "https://www.connectingeuropeans.eu/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:119.0) Gecko/20100101 Firefox/119.0" "2.37"
146.70.198.231 - [07/Oct/2026:05:03:03
...
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:02:14
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 146.70.198.231 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.198.231 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:02:07.622249 2026] [security2:error] [pid 6584:tid 6610] [client 146.70.198.231:49828] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.fastestcopyright.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.fastestcopyright.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asWoH-YazchBLdtpPNUIAgAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
DRI
2026-10-07 01:36:04
(9 hours ago)
Web attack/Malicious activity detected
Web App Attack
๐ญ๐ท
bubausluge
2026-10-07 01:30:49
(9 hours ago)
Blocked by https://aegis.hr โ WebHost: ModSecurity CRS Alert - (MITRE T1190), 5 attempts, Period: 20 ...
show more
Blocked by https://aegis.hr โ WebHost: ModSecurity CRS Alert - (MITRE T1190), 5 attempts, Period: 2026-10-07 01:14:26 to 2026-10-07 01:14:26
show less
Web App Attack
Bad Web Bot