Anonymous
2026-08-31 14:17:45
(3 weeks ago)
"GET /wp-login.php HTTP/1.1"
Hacking
Web App Attack
๐ฉ๐ช
Michel Wijnberg
2026-08-31 10:58:41
(3 weeks ago)
172.104.144.69 - - [31/Aug/2026:10:58:40 +0000] "GET /wp-login.php HTTP/1.1" 301 162 "" "Mozilla/5.0 ...
show more
172.104.144.69 - - [31/Aug/2026:10:58:40 +0000] "GET /wp-login.php HTTP/1.1" 301 162 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-08-31 10:39:36
(3 weeks ago)
Probing for Wordpress - /wp-login.php
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-31 10:33:27
(3 weeks ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-31 10:33 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
billfor
2026-08-31 09:53:49
(3 weeks ago)
172.104.144.69 - - [31/Aug/2026:05:53:46 -0400] "GET /wp-login.php HTTP/1.1" 404 0 "" "Mozilla/5.0 ( ...
show more
172.104.144.69 - - [31/Aug/2026:05:53:46 -0400] "GET /wp-login.php HTTP/1.1" 404 0 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 09:39:36
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 172.104.144.69 (li1660-69.members.linode.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 172.104.144.69 (li1660-69.members.linode.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:39:30.284566 2026] [security2:error] [pid 24662:tid 24662] [client 172.104.144.69:60332] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nwtree.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nwtree.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "apVL0tJwhvPz4oJhRZMprwAAAAE"], referer: http://www.nwtree.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-08-31 09:16:13
(3 weeks ago)
Web vulnerability probing: /wp-login.php
Web App Attack
Anonymous
2026-08-31 08:37:03
(3 weeks ago)
Bot / scanning and/or hacking attempts: GET /wp-login.php HTTP/1.1, GET / HTTP/2.0, [1/1] done
Hacking
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-31 07:38:53
(3 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 06:24:44
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 172.104.144.69 (li1660-69.members.linode.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 172.104.144.69 (li1660-69.members.linode.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 02:24:38.865250 2026] [security2:error] [pid 3918:tid 3918] [client 172.104.144.69:47202] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||loriarsenault.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "loriarsenault.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apUeJq-ErpggTP7pBtSqrQAAAAE"], referer: http://loriarsenault.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 05:23:20
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 172.104.144.69 (li1660-69.members.linode.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 172.104.144.69 (li1660-69.members.linode.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 01:23:12.636580 2026] [security2:error] [pid 2984:tid 2984] [client 172.104.144.69:53568] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thomasgardner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thomasgardner.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apUPwNSJkvAsOcpJNk8PPQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DocNetzwerk
2026-08-31 04:43:59
(3 weeks ago)
(wordpress) Failed wordpress login from 172.104.144.69 (DE/Germany/li1660-69.members.linode.com)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-31 04:40:59
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 172.104.144.69 (li1660-69.members.linode.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 172.104.144.69 (li1660-69.members.linode.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 00:40:55.113827 2026] [security2:error] [pid 11629:tid 11629] [client 172.104.144.69:60580] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ardath.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ardath.net"] [uri "/wp-json/wp/v2/users"] [unique_id "apUF1_lJY9CH_OdO_l7QzAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-31 04:03:27
(3 weeks ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: wp_login. Observed by 1 sensor(s); 2 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 03:52:02
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 172.104.144.69 (li1660-69.members.linode.com): ...
show more
(mod_security) mod_security (id:225170) triggered by 172.104.144.69 (li1660-69.members.linode.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 23:51:56.642393 2026] [security2:error] [pid 25260:tid 25260] [client 172.104.144.69:50744] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||learnserve.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "learnserve.net"] [uri "/wp-json/wp/v2/users"] [unique_id "apT6XOnx_OOP94AjQHocIQAAAB8"], referer: http://learnserve.net/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack