Anonymous
2026-08-31 01:53:34
(49 minutes ago)
PSCSERV WPSCAN 184.174.37.63
Bad Web Bot
Web App Attack
🇦🇹
joe-abuse
2026-08-31 01:42:54
(1 hour ago)
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-30 1 ...
show more
Automated report from fail2ban on www.fitzgerald.eu. Jail: apache-badpaths. First seen: 2026-08-30 19:30:16. Events: 1. Reported by ipdb-security/fitzgerald.eu
show less
Web App Attack
🇺🇸
nyt
2026-08-31 01:28:46
(1 hour ago)
WP User Enumeration, WP login POST blocked by WAF
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 01:19:01
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 184.174.37.63 (server.orixwebhosting.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 184.174.37.63 (server.orixwebhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 21:18:57.847221 2026] [security2:error] [pid 2412:tid 2480] [client 184.174.37.63:34504] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||woodamy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "woodamy.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apTWgVq2SrUGhdp85WLLMwAAANU"], referer: http://woodamy.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
xmission.com
2026-08-31 00:05:49
(2 hours ago)
184.174.37.63 - - [30/Aug/2026:18:05:47 -0600] "POST /wp-login.php HTTP/2.0" 200 2654 "https://dooce ...
show more
184.174.37.63 - - [30/Aug/2026:18:05:47 -0600] "POST /wp-login.php HTTP/2.0" 200 2654 "https://dooce.com/wp-login.php?redirect_to=https%3A%2F%2Fdooce.com%2Fwp-admin%2F" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
184.174.37.63 - - [30/Aug/2026:18:05:48 -0600] "POST /wp-login.php HTTP/2.0" 200 2651 "https://dooce.com/wp-login.php?redirect_to=https%3A%2F%2Fdooce.com%2Fwp-admin%2F" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
184.174.37.63 - - [30/Aug/2026:18:05:49 -0600] "POST /wp-login.php HTTP/2.0" 200 2649 "https://dooce.com/wp-login.php?redirect_to=https%3A%2F%2Fdooce.com%2Fwp-admin%2F" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
...
show less
Brute-Force
Anonymous
2026-08-30 23:45:35
(2 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇧🇪
voormedia
2026-08-30 23:10:43
(3 hours ago)
Accessed trap at '/wp-login.php'
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 22:56:53
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 184.174.37.63 (server.orixwebhosting.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 184.174.37.63 (server.orixwebhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 18:56:50.767255 2026] [security2:error] [pid 3183559:tid 3183584] [client 184.174.37.63:53062] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.rubenluis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.rubenluis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apS1MpxUFX9oR5PDSNASBgAAAFQ"], referer: http://rubenluis.net/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ph
2026-08-30 22:43:04
(3 hours ago)
Bad web bot attempting to run wp-login.php on non-WP site
Hacking
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-08-30 22:41:21
(4 hours ago)
URL Probing: /wp-login.php
Web App Attack
Anonymous
2026-08-30 22:13:52
(4 hours ago)
Failed Wordpress Logins
Web App Attack
🇳🇱
tmiland
2026-08-30 21:57:45
(4 hours ago)
(wordpress_login) WordPress Login Attack 184.174.37.63 (FR/France/server.orixwebhosting.com): 3 in t ...
show more
(wordpress_login) WordPress Login Attack 184.174.37.63 (FR/France/server.orixwebhosting.com): 3 in the last 3600 secs; IP: 184.174.37.63; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 184.174.37.63 - - [30/Aug/2026:23:57:42 +0200] "GET /wp-login.php HTTP/1.1" 302 138 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0" 184.174.37.63 - - [30/Aug/2026:23:57:42 +0200] "GET /wp-login.php HTTP/1.1" 200 2250 "http://*.*/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0" 184.174.37.63 - - [30/Aug/2026:23:57:42 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 314 "http://*.*/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
show less
Brute-Force
🇺🇸
ambor
2026-08-30 21:49:21
(4 hours ago)
L0ss Honeypot: WordPress login access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
🇺🇸
slay3r9903
2026-08-30 21:12:03
(5 hours ago)
IP address blocked by Cloudflare security rules due to suspicious activity and security violations.
Hacking
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-30 21:04:00
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 184.174.37.63 (server.orixwebhosting.com): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 184.174.37.63 (server.orixwebhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 17:03:55.129980 2026] [security2:error] [pid 27665:tid 27665] [client 184.174.37.63:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yggdrasil.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yggdrasil.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apSau3fDE63632PHisMcZgAAABI"], referer: http://yggdrasil.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack