๐บ๐ธ
nyt
2026-08-24 13:52:08
(5 hours ago)
Brute-Force, Web App Attack, suspicious: WP login POST blocked by WAF
Brute-Force
Web App Attack
๐ต๐ฑ
lns.bz
2026-08-24 13:06:29
(6 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 12:59:58
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.105.137.176 (static.176.137.105.178.clients ...
show more
(mod_security) mod_security (id:225170) triggered by 178.105.137.176 (static.176.137.105.178.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 08:59:51.690664 2026] [security2:error] [pid 2900:tid 2900] [client 178.105.137.176:32994] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||susanleeward.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "susanleeward.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aoxARx6nglEtpWMu7x398gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-24 12:55:02
(6 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-24 12:48:57
(6 hours ago)
cloudlinux2 fail2ban: 2026-08-24 14:43:52,153 fail2ban.actions [1464]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-24 14:43:52,153 fail2ban.actions [1464]: NOTICE [plesk-modsecurity] Unban 38.134.139.66cloudlinux2 fail2ban: 2026-08-24 14:44:09,879 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 37.142.150.221 - 2026-08-24 14:44:09cloudlinux2 fail2ban: 2026-08-24 14:44:10,187 fail2ban.actions [1464]: NOTICE [plesk-modsecurity] Ban 37.142.150.221cloudlinux2 fail2ban: 2026-08-24 14:44:10,194 fail2ban.filter [1464]: INFO [recidive] Found 37.142.150.221 - 2026-08-24 14:44:10cloudlinux2 fail2ban: 2026-08-24 14:44:47,658 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 146.19.140.185 - 2026-08-24 14:44:47cloudlinux2 fail2ban: 2026-08-24 14:46:45,370 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 178.105.137.176 - 2026-08-24 14:46:45cloudlinux2 fail2ban: 2026-08-24 14:46:45,380 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 178.105.137.176 - 2026-08-24 14:46:45cloudlinux2 fail2ban: 2026-08-24 14:46:46,39
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 12:39:02
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.105.137.176 (static.176.137.105.178.clients ...
show more
(mod_security) mod_security (id:225170) triggered by 178.105.137.176 (static.176.137.105.178.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 08:38:54.028794 2026] [security2:error] [pid 25350:tid 25350] [client 178.105.137.176:53964] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "michelehoop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aow7XuCyN0G7r-ZcXZi3_QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-24 12:16:32
(7 hours ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-24 11:49:24
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.105.137.176 (static.176.137.105.178.clients ...
show more
(mod_security) mod_security (id:225170) triggered by 178.105.137.176 (static.176.137.105.178.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 07:49:18.729691 2026] [security2:error] [pid 9415:tid 9415] [client 178.105.137.176:52514] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||igolfallday.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "igolfallday.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aowvvjsxi2lJMo9asEOR0QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-08-24 11:30:30
(8 hours ago)
WordPress author enumeration
Web App Attack
๐ฉ๐ช
rh24
2026-08-24 11:29:12
(8 hours ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 178.105.137.176 (DE/Germany/static.176 ...
show more
(wordpress-user-enum) Failed wordpress-user-enum trigger from 178.105.137.176 (DE/Germany/static.176.137.105.178.clients.your-server.de): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-24 11:21:05
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.105.137.176 (static.176.137.105.178.clients ...
show more
(mod_security) mod_security (id:225170) triggered by 178.105.137.176 (static.176.137.105.178.clients.your-server.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 07:20:56.892344 2026] [security2:error] [pid 20217:tid 20217] [client 178.105.137.176:45628] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "humbliaslaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aowpGOWbXdA8TkJ-B_l-1wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-24 04:32:37
(15 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฆ๐บ
QT
2026-08-23 20:09:32
(23 hours ago)
Unauthorised WordPress admin login attempted at 2026-08-24 06:09:26 +1000
Web App Attack
๐บ๐ธ
craudiovizai
2026-08-23 18:30:11
(1 day ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-login.php. Blocked ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-login.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-23 17:06:01
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01]
Hacking
Brute-Force
Bad Web Bot
Web App Attack