Anonymous
2026-09-23 08:15:31
(1 hour ago)
Web attack blocked by Wordfence on limburgsekunstkring.nl (3 hits). Reported by CRMON.
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-23 04:08:46
(6 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
Anonymous
2026-09-22 20:10:13
(14 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฉ๐ช
ger-stg-sifi1
2026-09-22 18:51:18
(15 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-22 13:14:05
(20 hours ago)
WordPress Brute Force
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-09-22 10:16:44
(23 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-22 09:22:24
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-22 07:15:26
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:14:06
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 149.19.27.153 (cgn-poy-149-19-27-153.as55850.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 149.19.27.153 (cgn-poy-149-19-27-153.as55850.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:13:59.269796 2026] [security2:error] [pid 28833:tid 28863] [client 149.19.27.153:1815] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nicholsinvest.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nicholsinvest.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arHWV-hhvAGbQcBowgnaZwAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:42:05
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 149.19.27.153 (cgn-poy-149-19-27-153.as55850.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 149.19.27.153 (cgn-poy-149-19-27-153.as55850.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:41:58.959891 2026] [security2:error] [pid 11443:tid 11443] [client 149.19.27.153:24395] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jeanniemorrislaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jeanniemorrislaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arGkpjoPBzUL2g7uB9EgxQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:00:55
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 149.19.27.153 (cgn-poy-149-19-27-153.as55850.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 149.19.27.153 (cgn-poy-149-19-27-153.as55850.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:00:48.806765 2026] [security2:error] [pid 13118:tid 13118] [client 149.19.27.153:36588] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||canebrakes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "canebrakes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arGbAHZZMKKm4uqSvKvX_AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:48:48
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 149.19.27.153 (cgn-poy-149-19-27-153.as55850.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 149.19.27.153 (cgn-poy-149-19-27-153.as55850.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:48:42.821061 2026] [security2:error] [pid 7052:tid 7052] [client 149.19.27.153:23723] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rambleandprose.cyberclay.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rambleandprose.cyberclay.net"] [uri "/wp-json/wp/v2/users"] [unique_id "arFt-pJCZCp2y7y-8OVGmQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 11:05:55
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 149.19.27.153 (cgn-poy-149-19-27-153.as55850.ne ...
show more
(mod_security) mod_security (id:225170) triggered by 149.19.27.153 (cgn-poy-149-19-27-153.as55850.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 07:05:47.170401 2026] [security2:error] [pid 29822:tid 29822] [client 149.19.27.153:3990] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||plazahacienda.imerka.com.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "plazahacienda.imerka.com.mx"] [uri "/wp-json/wp/v2/users"] [unique_id "arEPi5KTA1pZXzXhAlWi3gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-09-20 20:36:02
(2 days ago)
Wordfence waf block on wp20190711M4
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-20 18:15:53
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack