๐ต๐ฑ
Budyn
2026-09-15 23:42:09
(39 minutes ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: ssh.goblinpot.space | URI: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:119.0) Gecko/20100101 Firefox/119.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 23:23:40
(58 minutes ago)
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 19:23:34.793348 2026] [security2:error] [pid 17036:tid 17036] [client 152.42.207.45:64193] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stacyfarm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stacyfarm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqnTdpuq1iVnX3Ll4o5jYQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-09-15 23:06:14
(1 hour ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 23:04:47
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 19:04:39.264068 2026] [security2:error] [pid 30850:tid 30850] [client 152.42.207.45:52565] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nationalenq.internetnameregistration.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nationalenq.internetnameregistration.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqnPBzhxG_U3-Wy625CJHAAAAAc"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-09-15 23:00:23
(1 hour ago)
wp-login.php Brute force
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:45:21
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:45:17.101308 2026] [security2:error] [pid 5565:tid 5565] [client 152.42.207.45:65468] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||slimlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "slimlaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqm8bQiyM4d6vkPqzWpBSgAAABE"], referer: https://www.bing.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:25:29
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:25:24.206053 2026] [security2:error] [pid 29349:tid 29349] [client 152.42.207.45:63820] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stantontownship.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stantontownship.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aqm3xOB5fhy7Qc7K8JAoygAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 21:21:56
(2 hours ago)
(wordpress) Failed wordpress login from 152.42.207.45 (SG/Singapore/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-15 19:59:37
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:59:32.574915 2026] [security2:error] [pid 26421:tid 26421] [client 152.42.207.45:58012] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||solarfarms.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "solarfarms.info"] [uri "/wp-json/wp/v2/users"] [unique_id "aqmjpB2uvki6WXe_edVWhgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-15 19:34:47
(4 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: ssh.dont-eat-the-pudding.xyz | URI: /wp-login.php | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:07:07
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:06:59.890811 2026] [security2:error] [pid 1070:tid 1070] [client 152.42.207.45:50315] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "soundtrax.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aqmJQzZTydPyfWla0vNg3QAAAAo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-15 17:57:00
(6 hours ago)
2026-09-15 19:53:18 WordPress login error from 152.42.207.45: invalid_username && 2026-09-15 19:53:3 ...
show more
2026-09-15 19:53:18 WordPress login error from 152.42.207.45: invalid_username && 2026-09-15 19:53:32 WordPress login error from 152.42.207.45: invalid_username && 2026-09-15 19:53:46 WordPress login error from 152.42.207.45: invalid_username && 14 more within 20 minutes
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-15 16:44:03
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 152.42.207.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:43:57.901421 2026] [security2:error] [pid 6933:tid 6981] [client 152.42.207.45:50670] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.neutrahouse1939.ward-bergerhouse.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.neutrahouse1939.ward-bergerhouse.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aql1zb6ViQaeaxDXAqws9wAAAQA"], referer: https://wordpress.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
๐ท๐ท๐ท
2026-09-15 16:03:34
(8 hours ago)
Multiple WordPress unauthorized access attempts
...
Brute-Force
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-09-15 15:57:24
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack