🇬🇧
SilverZippo
2026-08-30 20:48:23
(3 minutes ago)
Web App Attack
Web App Attack
🇳🇴
jad-abuse
2026-08-30 20:44:38
(7 minutes ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. Observed by 1 sensor(s); 1 hits.
show less
Brute-Force
Web App Attack
🇺🇸
nyt
2026-08-30 20:26:05
(26 minutes ago)
WP User Enumeration, WP login POST blocked by WAF
Brute-Force
Web App Attack
🇺🇸
ambor
2026-08-30 20:23:17
(29 minutes ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 20:17:56
(34 minutes ago)
(mod_security) mod_security (id:225170) triggered by 159.89.149.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.89.149.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:17:48.693591 2026] [security2:error] [pid 28106:tid 28106] [client 159.89.149.162:46362] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bethanpearce.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bethanpearce.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apSP7BXIq3SLs5EwVHWKtAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
JimArchon72
2026-08-30 20:15:02
(37 minutes ago)
2026/08/30 20:13:22 "GET /wp-login.php HTTP/2.0"
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 19:23:20
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 159.89.149.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.89.149.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 15:23:13.659014 2026] [security2:error] [pid 11895:tid 11895] [client 159.89.149.162:41500] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arapi.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arapi.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apSDIXMhd-jXdw49b55sLAAAAA0"], referer: http://arapi.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 19:04:13
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 159.89.149.162 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 159.89.149.162 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 15:04:08.335892 2026] [security2:error] [pid 2986:tid 2986] [client 159.89.149.162:35388] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||scswat.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "scswat.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apR-qDCrCQK5VayX-nyeiwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-08-30 18:45:04
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
Rom74
2026-08-29 07:35:23
(1 day ago)
2026-08-29T09:35:21.108563+02:00 serveur1 sshd[3431572]: pam_unix(sshd:auth): authentication failure ...
show more
2026-08-29T09:35:21.108563+02:00 serveur1 sshd[3431572]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=159.89.149.162
2026-08-29T09:35:23.144957+02:00 serveur1 sshd[3431572]: Failed password for invalid user rom74 from 159.89.149.162 port 57052 ssh2
...
show less
Brute-Force
SSH
🇳🇱
wlt-blocker
2026-08-24 14:22:04
(6 days ago)
Illegal port scans
Port Scan
🇩🇪
wlt-blocker
2026-08-23 04:22:48
(1 week ago)
Illegal port scans
Port Scan
🇳🇱
EGP Abuse Dept
2026-08-23 02:27:55
(1 week ago)
Unauthorized connection to RDP port 3389
Port Scan
Hacking