🇺🇸
TPI-Abuse
2026-08-29 12:33:23
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 162.0.209.211 (business95.web-hosting.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 162.0.209.211 (business95.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:33:15.052648 2026] [security2:error] [pid 10623:tid 10623] [client 162.0.209.211:58346] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lasertherapyoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lasertherapyoc.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apLRizqskc_F_R2YuCUkQwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 10:44:37
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 162.0.209.211 (business95.web-hosting.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 162.0.209.211 (business95.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 06:44:30.995655 2026] [security2:error] [pid 28388:tid 28388] [client 162.0.209.211:46750] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kaldaragroup.com.greenlight.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kaldaragroup.com.greenlight.us"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apK4DsfJcBoqmSdKXhaU8wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 07:52:22
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 07:36:45
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 162.0.209.211 (business95.web-hosting.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 162.0.209.211 (business95.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:36:40.286393 2026] [security2:error] [pid 26178:tid 26178] [client 162.0.209.211:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||local639.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "local639.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apKMCBY3FdGH3v89Jx75tQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-08-29 05:47:46
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
FeG Deutschland
2026-08-29 04:45:54
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇩🇪
LRob
2026-08-29 04:29:01
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp/wp-login.php | 2026-08-29 04:29 UTC
show less
Hacking
Web App Attack
🇺🇸
lostswordfish.com
2026-08-29 04:10:06
(1 day ago)
Wordfence waf block on madesimpleskincare
Web App Attack
Anonymous
2026-08-29 03:35:17
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇺🇸
wordpresshosting.solutions
2026-08-29 03:26:38
(1 day ago)
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 162.0.209.211 - - [29/Aug/2026: ...
show more
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 162.0.209.211 - - [29/Aug/2026:03:26:35 +0000] "GET /wp-login.php HTTP/1.1" 200 9834 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
162.0.209.211 - - [29/Aug/2026:03:26:36 +0000] "POST /wp-login.php HTTP/1.1" 503 21510 "https://[DOMAIN]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
🇩🇪
LRob
2026-08-29 02:59:52
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp/wp-login.php | 2026-08-29 02:59 UTC
show less
Hacking
Web App Attack
🇬🇧
consul.to
2026-08-29 02:57:46
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇫🇮
YF
2026-08-29 02:00:37
(1 day ago)
wp-login.php Brute force
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-08-29 01:00:05
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:48:51
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 162.0.209.211 (business95.web-hosting.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 162.0.209.211 (business95.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:48:45.857703 2026] [security2:error] [pid 28864:tid 28864] [client 162.0.209.211:57506] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lambert-heating-and-air.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lambert-heating-and-air.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apIsbeqnZIDLbofZxzFkNgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack