🇲🇽
octageeks.com
2026-08-29 04:33:34
(12 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇹🇷
oalver
2026-08-28 23:27:35
(17 hours ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-08-28. Risk score: 60/100.
show less
Web App Attack
🇳🇱
Site.eu
2026-08-28 20:07:29
(21 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-08-28 20:03:19
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.60 (business-52.default-host.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.60 (business-52.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 16:03:11.631863 2026] [security2:error] [pid 12141:tid 12141] [client 185.104.44.60:55684] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||persnicketyinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "persnicketyinc.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apHpf-lIDocW_2AHXSc_nAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Apache
2026-08-28 19:53:17
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.60 (UA/Ukraine/business-52.default-h ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.60 (UA/Ukraine/business-52.default-host.net): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇩🇪
Lino Project
2026-08-28 19:50:26
(21 hours ago)
185.104.44.60 - - [28/Aug/2026:21:50:23 +0200] "GET /wp-login.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 ...
show more
185.104.44.60 - - [28/Aug/2026:21:50:23 +0200] "GET /wp-login.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
tmiland
2026-08-28 19:40:17
(21 hours ago)
(wordpress_login) WordPress Login Attack 185.104.44.60 (UA/Ukraine/business-52.default-host.net): 3 ...
show more
(wordpress_login) WordPress Login Attack 185.104.44.60 (UA/Ukraine/business-52.default-host.net): 3 in the last 3600 secs; IP: 185.104.44.60; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 185.104.44.60 - - [28/Aug/2026:21:19:10 +0200] "GET /wp-login.php HTTP/1.1" 200 2251 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 185.104.44.60 - - [28/Aug/2026:21:19:11 +0200] "POST /wp-login.php HTTP/1.1" 200 2380 "https://*.*/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 185.104.44.60 - - [28/Aug/2026:21:40:12 +0200] "GET /wp-login.php HTTP/1.1" 200 2251 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Brute-Force
🇳🇿
Tripwire
2026-08-28 19:37:57
(21 hours ago)
Wordpress login attempts
Brute-Force
Web App Attack
Anonymous
2026-08-28 19:29:18
(21 hours ago)
[Fri Aug 28 20:53:24.566539 2026] [authz_core:error] [pid 1637:tid 1821] [client 185.104.44.60:39126 ...
show more
[Fri Aug 28 20:53:24.566539 2026] [authz_core:error] [pid 1637:tid 1821] [client 185.104.44.60:39126] AH01630: client denied by server configuration: /var/www/wordp/wp-login.php
[Fri Aug 28 20:53:24.568620 2026] [authz_core:error] [pid 7160:tid 7204] [client 185.104.44.60:39124] AH01630: client denied by server configuration: /var/www/wordp/wp-login.php
[Fri Aug 28 21:29:17.446436 2026] [authz_core:error] [pid 7160:tid 7209] [client 185.104.44.60:26188] AH01630: client denied by server configuration: /var/www/wordp/wp-login.php
[Fri Aug 28 21:29:17.446438 2026] [authz_core:error] [pid 7160:tid 7201] [client 185.104.44.60:26190] AH01630: client denied by server configuration: /var/www/wordp/wp-login.php
...
show less
Brute-Force
Web App Attack
🇺🇸
nyt
2026-08-28 19:13:19
(22 hours ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
🇲🇹
Malta
2026-08-28 19:12:42
(22 hours ago)
185.104.44.60 - - [28/Aug/2026:21:12:42 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
185.104.44.60 - - [28/Aug/2026:21:12:42 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
Anonymous
2026-08-28 19:10:05
(22 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
🇨🇦
SSH-Admin
2026-08-28 19:00:05
(22 hours ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 18:49:28
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.104.44.60 (business-52.default-host.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 185.104.44.60 (business-52.default-host.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:49:23.354799 2026] [security2:error] [pid 11981:tid 11981] [client 185.104.44.60:58680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||midcityrotary.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "midcityrotary.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apHYM-zVTH01uzb71Q8AOAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇿
ptlab
2026-08-28 18:45:18
(22 hours ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack