🇺🇸
TPI-Abuse
2026-09-09 02:26:38
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 158.173.244.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 158.173.244.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:26:30.794752 2026] [security2:error] [pid 16652:tid 16699] [client 158.173.244.136:37071] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.gipsongrocerystore.digital4z.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.gipsongrocerystore.digital4z.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDD1laWDkabBNFRAt0yzwAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 02:08:18
(5 hours ago)
Web application attack detected.
Web App Attack
🇫🇷
ELYAZ
2026-09-09 02:07:25
(5 hours ago)
(wordpress) Failed wordpress login from 158.173.244.136 (PT/Portugal/-): (CF_ENABLE)
Brute-Force
🇺🇸
TPI-Abuse
2026-09-09 01:56:57
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 158.173.244.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 158.173.244.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:56:51.405102 2026] [security2:error] [pid 4972:tid 4972] [client 158.173.244.136:30697] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||glendaleheritage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "glendaleheritage.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC84wTjk50RELiwf2sShQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nyt
2026-09-09 01:52:21
(6 hours ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
Anonymous
2026-09-09 01:48:36
(6 hours ago)
WordPress Brute Force
Brute-Force
🇩🇪
Lino Project
2026-09-09 01:29:06
(6 hours ago)
158.173.244.136 - - [09/Sep/2026:03:29:03 +0200] "GET /wp-login.php HTTP/2.0" 403 405 "-" "Mozilla/5 ...
show more
158.173.244.136 - - [09/Sep/2026:03:29:03 +0200] "GET /wp-login.php HTTP/2.0" 403 405 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
KIsmay
2026-09-09 01:22:36
(6 hours ago)
Sep 8 17:30:07 www4 WPAudit[3418838]: 158.173.244.136 imaginesalmon.com "Mozilla/5.0 (Windows NT 10 ...
show more
Sep 8 17:30:07 www4 WPAudit[3418838]: 158.173.244.136 imaginesalmon.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" imagine:[email protected] FAIL
Sep 8 19:39:16 www4 WPAudit[3444705]: 158.173.244.136 imaginesalmon.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" se7enoaks:se7enoaks_2026 FAIL
Sep 8 19:45:36 www4 WPAudit[3445499]: 158.173.244.136 bestnelson.org "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" katietabor-developer:katietabor-developer2026 FAIL
Sep 8 20:42:00 www4 WPAudit[3449481]: 158.173.244.136 lemoncreekcampground.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" sbd-admin:sbd-admin@2026 FAIL
Sep 8 21:22:34 www4 WPAudit[3452661]: 158.173.244.136 www.trilloperelloyates.com "Mozilla/5.0 (Windows NT
...
show less
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-09 01:19:22
(6 hours ago)
(wordpress) Apache: Failed WordPress login from 158.173.244.136 (PT/Portugal/-): 10 in the last 3600 ...
show more
(wordpress) Apache: Failed WordPress login from 158.173.244.136 (PT/Portugal/-): 10 in the last 3600 secs (0-193)
show less
Hacking
Anonymous
2026-09-09 01:15:10
(6 hours ago)
Web attack blocked by Wordfence on limburgsekunstkring.nl (1 hit). Reported by CRMON.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:10:39
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 158.173.244.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 158.173.244.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:10:34.067282 2026] [security2:error] [pid 24623:tid 24623] [client 158.173.244.136:52631] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||altoshp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "altoshp.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCyClka6sfJagNbd1t8NgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇹🇷
oalver
2026-09-09 00:56:25
(7 hours ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-09-08. Risk score: 30/100.
show less
Web App Attack
Anonymous
2026-09-09 00:50:35
(7 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇮🇹
CoreTech srl
2026-09-09 00:48:56
(7 hours ago)
cloudlinux2 fail2ban: 2026-09-09 02:44:13,591 fail2ban.actions [1794]: NOTICE [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-09 02:44:13,591 fail2ban.actions [1794]: NOTICE [plesk-wordpress] Unban 63.135.161.156cloudlinux2 fail2ban: 2026-09-09 02:44:28,459 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 185.218.86.24 - 2026-09-09 02:44:28cloudlinux2 fail2ban: 2026-09-09 02:44:48,135 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 173.239.240.123 - 2026-09-09 02:44:47cloudlinux2 fail2ban: 2026-09-09 02:44:52,580 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 173.239.240.123 - 2026-09-09 02:44:52cloudlinux2 fail2ban: 2026-09-09 02:44:58,175 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 136.70.138.21cloudlinux2 fail2ban: 2026-09-09 02:44:50,631 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 158.173.244.136 - 2026-09-09 02:44:50cloudlinux2 fail2ban: 2026-09-09 02:45:04,268 fail2ban.actions [1794]: NOTICE [plesk-wordpress] Unban 173.239.211.68cloudlinux2 fail2ban: 2026-09-09 02:45:57,189 fail2ban.filter
show less
Web App Attack
🇫🇷
Tilellit.PRO
2026-09-09 00:43:54
(7 hours ago)
WP Armour Plugin detection
Web Spam
Brute-Force