🇺🇸
TPI-Abuse
2026-09-20 21:02:50
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.118.190.222 (vm380.diagonalhosting.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 185.118.190.222 (vm380.diagonalhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:02:41.941376 2026] [security2:error] [pid 22534:tid 22534] [client 185.118.190.222:34044] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.taekwondoit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.taekwondoit.com"] [uri "/about-us/wp-json/wp/v2/users"] [unique_id "arBJ8UesEWMNM9sMM2JSowAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
maxxsense
2026-09-20 15:07:32
(17 hours ago)
(wordpress-user-enum) Failed wordpress-user-enum trigger from 185.118.190.222 (ES/Spain/vm380.diagon ...
show more
(wordpress-user-enum) Failed wordpress-user-enum trigger from 185.118.190.222 (ES/Spain/vm380.diagonalhosting.com)
show less
Brute-Force
🇲🇽
octageeks.com
2026-09-20 04:14:06
(1 day ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
🇮🇹
CoreTech srl
2026-09-20 02:53:56
(1 day ago)
cloudlinux2 fail2ban: 2026-09-20 04:48:53,846 fail2ban.filter [1813]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-20 04:48:53,846 fail2ban.filter [1813]: INFO [plesk-modsecurity] Found 185.118.190.222 - 2026-09-20 04:48:53cloudlinux2 fail2ban: 2026-09-20 04:49:37,136 fail2ban.filter [1813]: INFO [plesk-wordpress] Found 172.98.33.68 - 2026-09-20 04:49:36cloudlinux2 fail2ban: 2026-09-20 04:49:42,966 fail2ban.actions [1813]: NOTICE [plesk-wordpress] Ban 172.98.33.68cloudlinux2 fail2ban: 2026-09-20 04:49:41,420 fail2ban.filter [1813]: INFO [plesk-wordpress] Found 172.98.33.68 - 2026-09-20 04:49:41cloudlinux2 fail2ban: 2026-09-20 04:49:42,427 fail2ban.filter [1813]: INFO [plesk-wordpress] Found 172.98.33.68 - 2026-09-20 04:49:42cloudlinux2 fail2ban: 2026-09-20 04:49:43,131 fail2ban.filter [1813]: INFO [recidive] Found 172.98.33.68 - 2026-09-20 04:49:42cloudlinux2 fail2ban: 2026-09-20 04:50:31,920 fail2ban.filter [1813]: INFO [plesk-wordpress] Found 45.131.195.197 - 2026-09-20 04:50:30cloudlinux2 fail2ban: 2026-09-20 04:50:3
show less
Web App Attack
🇩🇪
wpadm3
2026-09-19 22:43:40
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇫🇷
masterguru
2026-09-19 19:08:32
(1 day ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking
🇩🇪
ger-stg-sifi1
2026-09-19 17:30:06
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-19 17:00:53
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 185.118.190.222 (vm380.diagonalhosting.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 185.118.190.222 (vm380.diagonalhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 13:00:49.091324 2026] [security2:error] [pid 11390:tid 11390] [client 185.118.190.222:50034] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.eileensharaga.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.eileensharaga.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq6_wQE9UKoEL0YtSvwUdQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
stinpriza
2026-09-19 16:31:39
(1 day ago)
WP Authentication attempt for unknown user
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-09-19 12:57:06
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
cwytech
2026-09-18 03:48:53
(3 days ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: crowdsecurity/http-wordpress_user-enum.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-18 02:08:13
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.118.190.222 (vm380.diagonalhosting.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 185.118.190.222 (vm380.diagonalhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 22:08:05.781356 2026] [security2:error] [pid 5887:tid 5887] [client 185.118.190.222:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rodrigoaldecoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rodrigoaldecoa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqydBRk1AnJ-nOEZH-8DLAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-17 11:20:57
(3 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 185.118.190.222 (ES/Spain/vm380.diagonalhostin ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 185.118.190.222 (ES/Spain/vm380.diagonalhosting.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 185.118.190.222 - - [17/Sep/2026:13:20:52 +0200] "GET /wp-json/wp/v2/users HTTP/1.1" 200 12058 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:41.0) Gecko/20100101 Firefox/41.0" "-" host=archabi.it
show less
Port Scan
🇫🇷
masterguru
2026-09-17 10:47:37
(3 days ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-197)
Hacking
🇺🇸
TPI-Abuse
2026-09-17 09:48:39
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 185.118.190.222 (vm380.diagonalhosting.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 185.118.190.222 (vm380.diagonalhosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:48:35.712730 2026] [security2:error] [pid 27263:tid 27263] [client 185.118.190.222:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.pixacast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.pixacast.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqu3cznthlEr6BSRhk07ewAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack