๐บ๐ธ
TPI-Abuse
2026-08-28 00:43:56
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 162.0.209.22 (premium164.web-hosting.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.0.209.22 (premium164.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 20:43:47.881017 2026] [security2:error] [pid 17883:tid 17883] [client 162.0.209.22:34690] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||somehand.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "somehand.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apDZw3r74_LTiyUMSCduHAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-28 00:01:14
(1 hour ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
cwytech
2026-08-27 23:16:57
(2 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-27 22:58:57
(2 hours ago)
cloudlinux2 fail2ban: 2026-08-28 00:55:58,247 fail2ban.filter [1775]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-28 00:55:58,247 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 162.241.203.67 - 2026-08-28 00:55:57cloudlinux2 fail2ban: 2026-08-28 00:56:03,763 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 198.54.114.110 - 2026-08-28 00:56:03cloudlinux2 fail2ban: 2026-08-28 00:56:20,711 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 108.179.192.130 - 2026-08-28 00:56:20cloudlinux2 fail2ban: 2026-08-28 00:56:28,534 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 198.54.114.127 - 2026-08-28 00:56:27cloudlinux2 fail2ban: 2026-08-28 00:57:17,157 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 162.0.209.22 - 2026-08-28 00:57:17cloudlinux2 fail2ban: 2026-08-28 00:57:08,820 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 180.195.145.11 - 2026-08-28 00:57:08cloudlinux2 fail2ban: 2026-08-28 00:57:29,076 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 198.54.126.229 - 2026-08-28 00:57:28c
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 22:33:13
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 162.0.209.22 (premium164.web-hosting.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.0.209.22 (premium164.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 18:33:06.088009 2026] [security2:error] [pid 13737:tid 13737] [client 162.0.209.22:40512] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||talentstar2025.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "talentstar2025.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apC7IsdZK-zdOZztKh4P3wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
AlexEventfahrtenIPDB
2026-08-27 21:21:27
(4 hours ago)
[Thu Aug 27 23:21:24.476628 2026] [authz_core:error] [pid 1630:tid 1655] [remote 162.0.209.22:55576] ...
show more
[Thu Aug 27 23:21:24.476628 2026] [authz_core:error] [pid 1630:tid 1655] [remote 162.0.209.22:55576] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php
[Thu Aug 27 23:21:27.453228 2026] [authz_core:error] [pid 1630:tid 1648] [remote 162.0.209.22:55592] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/wp-login.php
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2026-08-27 20:33:15
(5 hours ago)
162.0.209.22 - - [27/Aug/2026:19:38:55 +0200] "GET /wp-login.php HTTP/2.0" 200 4259 "-" "Mozilla/5.0 ...
show more
162.0.209.22 - - [27/Aug/2026:19:38:55 +0200] "GET /wp-login.php HTTP/2.0" 200 4259 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 162.0.209.22 - - [27/Aug/2026:19:38:55 +0200] "POST /wp-login.php HTTP/2.0" 403 11933 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 162.0.209.22 - - [27/Aug/2026:21:13:10 +0200] "GET /wp-login.php HTTP/2.0" 200 4330 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 162.0.209.22 - - [27/Aug/2026:21:13:11 +0200] "POST /wp-login.php HTTP/2.0" 200 5000 "https://bente-personaldienstleistung.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 162.0.209.22 - - [27/Aug/2026:22:33:15 +0200] "GET /wp-login.php HTTP/2.0" 200 3922 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:20:22
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 162.0.209.22 (premium164.web-hosting.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.0.209.22 (premium164.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:20:17.167245 2026] [security2:error] [pid 23342:tid 23342] [client 162.0.209.22:57162] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||diamondtrailerserv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "diamondtrailerserv.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apCcAZ5ap5hp61qKNBIY1wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
oalver
2026-08-27 19:29:29
(6 hours ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-08-27. Risk score: 30/100.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 19:26:17
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 162.0.209.22 (premium164.web-hosting.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.0.209.22 (premium164.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 15:26:09.780032 2026] [security2:error] [pid 3364196:tid 3364303] [client 162.0.209.22:45362] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hmpdecors.com.oplconnect.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hmpdecors.com.oplconnect.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apCPUYXx47nwz6PfTcZ00AAAAco"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-27 18:35:05
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-27 16:44:18
(9 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
www.winos.me
2026-08-27 16:33:57
(9 hours ago)
Scanning for sensitive files/paths: /wp-login.php
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:42:48
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 162.0.209.22 (premium164.web-hosting.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 162.0.209.22 (premium164.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:42:40.114156 2026] [security2:error] [pid 8032:tid 8032] [client 162.0.209.22:50544] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goodfrequencies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goodfrequencies.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apA-0J42bNqjWmBuJBEAgQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
nyt
2026-08-27 12:10:12
(13 hours ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack