🇨🇭
backslash
2026-08-30 20:42:00
(11 minutes ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇯🇵
Valhalla
2026-08-30 20:23:07
(29 minutes ago)
/wp-login.php
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 20:15:10
(37 minutes ago)
(mod_security) mod_security (id:225170) triggered by 178.254.28.42 (v45858.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 178.254.28.42 (v45858.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:15:06.043481 2026] [security2:error] [pid 1561:tid 1561] [client 178.254.28.42:58898] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||the-it-man.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "the-it-man.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apSPShOsyijJ00D1ZaQfZAAAAAI"], referer: http://the-it-man.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nyt
2026-08-30 20:10:03
(43 minutes ago)
WP User Enumeration, WP login POST blocked by WAF
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 19:29:08
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 178.254.28.42 (v45858.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 178.254.28.42 (v45858.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 15:29:01.136691 2026] [security2:error] [pid 12958:tid 12958] [client 178.254.28.42:42206] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tedharris.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tedharris.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apSEfeMad1jC_G_KbaIrSAAAABA"], referer: http://tedharris.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-30 19:27:36
(1 hour ago)
DEAGICO WEBEXPLOIT 178.254.28.42 (v45858.1blu.de)
Web App Attack
Anonymous
2026-08-30 19:16:58
(1 hour ago)
Failed Wordpress Logins
Web App Attack
🇮🇹
VHosting
2026-08-30 19:10:03
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 18:58:18
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 178.254.28.42 (v45858.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 178.254.28.42 (v45858.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 14:58:14.217278 2026] [security2:error] [pid 18987:tid 18987] [client 178.254.28.42:55904] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||major33.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "major33.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apR9RlhKLmo9wbAreMWaFQAAABQ"], referer: http://major33.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 18:40:53
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 178.254.28.42 (v45858.1blu.de): 1 in the last 3 ...
show more
(mod_security) mod_security (id:225170) triggered by 178.254.28.42 (v45858.1blu.de): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 14:40:46.118548 2026] [security2:error] [pid 15583:tid 15604] [client 178.254.28.42:35046] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||inal.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "inal.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apR5LcdaPMiaf61oNHZEGwAAAVA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Rom74
2026-08-28 19:04:53
(2 days ago)
2026-08-28T21:04:51.312712+02:00 serveur1 sshd[2862180]: pam_unix(sshd:auth): authentication failure ...
show more
2026-08-28T21:04:51.312712+02:00 serveur1 sshd[2862180]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=178.254.28.42
2026-08-28T21:04:53.183677+02:00 serveur1 sshd[2862180]: Failed password for invalid user rom74 from 178.254.28.42 port 53720 ssh2
...
show less
Brute-Force
SSH
🇺🇸
cwytech
2026-08-27 07:29:29
(3 days ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/tpot-ssh-crit.
Brute-Force
SSH
🇩🇪
wlt-blocker
2026-08-24 07:35:37
(6 days ago)
Illegal port scans
Port Scan