🇩🇪
neckaralb-admin.de
2026-09-08 22:58:32
(41 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:55:43
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.117.208.11 (178-117-208-11.access.telenet.b ...
show more
(mod_security) mod_security (id:225170) triggered by 178.117.208.11 (178-117-208-11.access.telenet.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:55:39.624344 2026] [security2:error] [pid 32178:tid 32178] [client 178.117.208.11:40092] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aandbnaturalfoods.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aandbnaturalfoods.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBoO5QR76Bk9tzHVWWdvAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:23:46
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.117.208.11 (178-117-208-11.access.telenet.b ...
show more
(mod_security) mod_security (id:225170) triggered by 178.117.208.11 (178-117-208-11.access.telenet.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:23:40.754232 2026] [security2:error] [pid 13281:tid 13281] [client 178.117.208.11:46286] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.avaliantlife.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBSrOmOSYqIVD4s2yoNNQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 15:06:58
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:13:28
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.117.208.11 (178-117-208-11.access.telenet.b ...
show more
(mod_security) mod_security (id:225170) triggered by 178.117.208.11 (178-117-208-11.access.telenet.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:13:23.225391 2026] [security2:error] [pid 17263:tid 17263] [client 178.117.208.11:56600] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lambert-heating-and-air.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lambert-heating-and-air.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_fw5Vvzb5bfk8RiZgcOAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:42:41
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.117.208.11 (178-117-208-11.access.telenet.b ...
show more
(mod_security) mod_security (id:225170) triggered by 178.117.208.11 (178-117-208-11.access.telenet.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:42:35.573030 2026] [security2:error] [pid 26534:tid 26534] [client 178.117.208.11:51828] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jacquelineperriam.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jacquelineperriam.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_Ke8p-RbClYaJq8a-GZgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 04:13:55
(19 hours ago)
WordPress login brute-force | path: /wp-fi/wp-login.php (+1 more) | 2026-09-08 04:13 UTC
Brute-Force
Web App Attack
🇩🇪
Hazzard
2026-09-07 21:29:22
(1 day ago)
(wordpress) Failed wordpress login from 178.117.208.11 (BE/Belgium/West Flanders Province/Roeselare/ ...
show more
(wordpress) Failed wordpress login from 178.117.208.11 (BE/Belgium/West Flanders Province/Roeselare/178-117-208-11.access.telenet.be/[redacted]): (CF_ENABLE)
show less
Brute-Force
🇫🇷
ELYAZ
2026-09-07 18:24:06
(1 day ago)
(wordpress) Failed wordpress login from 178.117.208.11 (BE/Belgium/178-117-208-11.access.telenet.be) ...
show more
(wordpress) Failed wordpress login from 178.117.208.11 (BE/Belgium/178-117-208-11.access.telenet.be): (CF_ENABLE)
show less
Brute-Force
🇬🇧
ISPLtd
2026-09-07 14:03:28
(1 day ago)
178.117.208.11 - - [07/Sep/2026:11:03:28 -0300] "GET /wp-login.php
178.117.208.11 - - [07/Sep/2026:1 ...
show more
178.117.208.11 - - [07/Sep/2026:11:03:28 -0300] "GET /wp-login.php
178.117.208.11 - - [07/Sep/2026:11:03:28 -0300] "POST /wp-login.php
...
show less
Hacking
Web App Attack
🇩🇪
FeG Deutschland
2026-09-07 12:45:04
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
Anonymous
2026-09-07 12:21:30
(1 day ago)
Repeated inbound connection attempts blocked by firewall. Observed at least twice within 24 hours.
Hacking
Anonymous
2026-06-11 15:17:46
(2 months ago)
Unauthorized VPN login attempts
Hacking
Brute-Force
🇩🇪
SMARTNET
2026-05-27 06:03:53
(3 months ago)
Aisuru(Mirai variant) DDoS | Incident ID: 6ed80dcf-192e-41b9-b3cf-8e7356812aa9
DDoS Attack