🇺🇸
TPI-Abuse
2026-08-29 10:38:11
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 160.236.186.245 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 160.236.186.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 06:38:07.794471 2026] [security2:error] [pid 13923:tid 13923] [client 160.236.186.245:37122] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||indoorsfinishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "indoorsfinishing.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apK2j7CvNHceJjBqvugJ6AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
SpaceHost-Server
2026-08-29 10:24:40
(7 hours ago)
160.236.186.245 - - [29/Aug/2026:12:24:39 +0200] "POST /wp-login.php HTTP/1.1" 200 21855 "https://fi ...
show more
160.236.186.245 - - [29/Aug/2026:12:24:39 +0200] "POST /wp-login.php HTTP/1.1" 200 21855 "https://finsimple.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
160.236.186.245 - - [29/Aug/2026:12:24:39 +0200] "POST /wp-login.php HTTP/1.1" 200 21857 "https://finsimple.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
160.236.186.245 - - [29/Aug/2026:12:24:39 +0200] "POST /wp-login.php HTTP/1.1" 200 21863 "https://finsimple.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 09:59:19
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 160.236.186.245 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 160.236.186.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 05:59:12.458911 2026] [security2:error] [pid 4112:tid 4112] [client 160.236.186.245:52156] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gaeltv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gaeltv.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apKtcEtGmxL1GepAXCmqRQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
SpaceHost-Server
2026-08-29 09:29:38
(8 hours ago)
160.236.186.245 - - [29/Aug/2026:11:29:36 +0200] "POST /wp-login.php HTTP/1.1" 200 9521 "https://sta ...
show more
160.236.186.245 - - [29/Aug/2026:11:29:36 +0200] "POST /wp-login.php HTTP/1.1" 200 9521 "https://start-the-loop.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
160.236.186.245 - - [29/Aug/2026:11:29:36 +0200] "POST /wp-login.php HTTP/1.1" 200 9516 "https://start-the-loop.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
160.236.186.245 - - [29/Aug/2026:11:29:36 +0200] "POST /wp-login.php HTTP/1.1" 200 9515 "https://start-the-loop.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
🇩🇪
LRob
2026-08-29 09:03:58
(8 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | 2026-08-29 09:03 UTC
show less
Hacking
Web App Attack
Anonymous
2026-08-29 07:48:41
(9 hours ago)
Network service scanning detected by FortiGate; source quarantined.
Port Scan
🇺🇸
TPI-Abuse
2026-08-29 07:43:50
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 160.236.186.245 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 160.236.186.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:43:42.406957 2026] [security2:error] [pid 25874:tid 25874] [client 160.236.186.245:36332] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.godcanuseyou.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.godcanuseyou.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apKNrvzKefvmJsaqLa_QZAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
stinpriza
2026-08-29 07:31:23
(10 hours ago)
Web App Attack
Web App Attack
🇩🇪
Viveronese
2026-08-29 07:27:04
(10 hours ago)
Wordpress vulnerability scanning
Web App Attack
🇺🇸
cwytech
2026-08-29 07:26:48
(10 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 07:25:35
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 160.236.186.245 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 160.236.186.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:25:28.514336 2026] [security2:error] [pid 18146:tid 18146] [client 160.236.186.245:50242] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||targetbinario.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "targetbinario.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apKJaNV7F7nPW5twF_UJHwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-08-29 07:16:15
(10 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇬🇧
Apache
2026-08-29 07:03:12
(10 hours ago)
(wplogin) WordPress login brute-force 160.236.186.245 (IN/India/-): 5 in the last 300 secs
Brute-Force
🇺🇸
TPI-Abuse
2026-08-29 07:03:07
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 160.236.186.245 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 160.236.186.245 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:02:59.596366 2026] [security2:error] [pid 17610:tid 17610] [client 160.236.186.245:43362] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thesmithcouple.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thesmithcouple.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apKEI1t-2Aaf9hc9oiUIWgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Roderic
2026-08-29 06:49:48
(10 hours ago)
(wordpress) Failed wordpress login from 160.236.186.245 (IN/India/-/-/-/[redacted])
Brute-Force