π©πͺ
neckaralb-admin.de
2026-10-01 04:26:08
(13 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
neckaralb-admin.de
2026-09-30 03:19:52
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
IndigoRidge
2026-09-30 02:48:40
(1 day ago)
181.49.223.246 - - [29/Sep/2026:22:48:34 -0400] "GET /?author=3 HTTP/1.1" 404 32591 "-" "Mozilla/5.0 ...
show more
181.49.223.246 - - [29/Sep/2026:22:48:34 -0400] "GET /?author=3 HTTP/1.1" 404 32591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
181.49.223.246 - - [29/Sep/2026:22:48:35 -0400] "GET /?author=4 HTTP/1.1" 404 32591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
181.49.223.246 - - [29/Sep/2026:22:48:37 -0400] "GET /?author=5 HTTP/1.1" 301 259 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
181.49.223.246 - - [29/Sep/2026:22:48:38 -0400] "GET /author/kristen/ HTTP/1.1" 200 32916 "http://www.upcountryremembers.org/?author=5" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
181.49.223.246 - - [29/Sep/2026:22:48:39 -0400] "GET /?author=6 HTTP/1.1" 404 32591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
...
show less
Web App Attack
π©πͺ
stinpriza
2026-09-30 02:44:15
(1 day ago)
Web App Attack
Web App Attack
πΊπΈ
IndigoRidge
2026-09-30 02:27:49
(1 day ago)
181.49.223.246 - - [29/Sep/2026:22:27:45 -0400] "GET /?author=7 HTTP/1.1" 404 34412 "http://landscap ...
show more
181.49.223.246 - - [29/Sep/2026:22:27:45 -0400] "GET /?author=7 HTTP/1.1" 404 34412 "http://landscapeperceptions.com/?author=7" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
181.49.223.246 - - [29/Sep/2026:22:27:46 -0400] "GET /?author=8 HTTP/1.1" 301 348 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
181.49.223.246 - - [29/Sep/2026:22:27:46 -0400] "GET /?author=8 HTTP/1.1" 404 34412 "http://landscapeperceptions.com/?author=8" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
181.49.223.246 - - [29/Sep/2026:22:27:48 -0400] "GET /?author=9 HTTP/1.1" 301 348 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
181.49.223.246 - - [29/Sep/2026:22:27:48 -0400] "GET /?author=9 HTTP/1.1" 404 34412 "http://landscapeperceptions.com/?author=9" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
...
show less
Web App Attack
π¬π§
gigatech
2026-09-29 18:20:25
(1 day ago)
Webserver Probing
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 01:13:57
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 181.49.223.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 181.49.223.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 21:13:50.868146 2026] [security2:error] [pid 12454:tid 12486] [client 181.49.223.246:41800] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||woofnrose.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "woofnrose.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arsQzgfnCsl20LD08IQy9wAAAYE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 23:09:20
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 181.49.223.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 181.49.223.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 19:09:13.947364 2026] [security2:error] [pid 7437:tid 7437] [client 181.49.223.246:60756] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||semisysteme.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "semisysteme.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arrzmddag1-88qPB_gEefwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 20:33:01
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 181.49.223.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 181.49.223.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 16:32:55.617066 2026] [security2:error] [pid 31199:tid 31199] [client 181.49.223.246:60004] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.nationalenq.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.nationalenq.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arrO93Ye4zxtgxlOMbkqfAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-09-28 06:07:43
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 01:17:24
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 181.49.223.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 181.49.223.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 21:17:20.093233 2026] [security2:error] [pid 13844:tid 13844] [client 181.49.223.246:40950] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hydrometal-js.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hydrometal-js.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arnAIPwMPzWwaqIWl43tewAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-27 23:05:07
(3 days ago)
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, ...
show more
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, secrets and build files, injected payloads. This is an attack on the sites we host, blocked on sight. Please check the machine behind it for an attack tool or malware. | method: GET | path: / | query: author=3 | 2026-09-27 23:05 UTC
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-27 22:54:32
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 181.49.223.246 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 181.49.223.246 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 18:54:24.740196 2026] [security2:error] [pid 4477:tid 4477] [client 181.49.223.246:57924] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cmcnow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cmcnow.com"] [uri "/wp-json/wp/v2/users"] [unique_id "armeoNbRjWzgnHlbISpFOAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-09-27 21:15:22
(3 days ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
π«π·
dynamix
2026-09-24 21:22:05
(6 days ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack