🇳🇿
Tripwire
2026-09-08 21:52:23
(9 minutes ago)
Wordpress login attempts
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 21:52:19
(9 minutes ago)
(mod_security) mod_security (id:225170) triggered by 185.176.113.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.176.113.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:52:15.298624 2026] [security2:error] [pid 6715:tid 6715] [client 185.176.113.5:34500] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bostonlog.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bostonlog.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCDjwevWFWUi2mGZ3_5nwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 20:23:02
(1 hour ago)
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/2.0, GET /wp-login.php HTTP/2.0
Hacking
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-08 19:50:15
(2 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:33:48
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.176.113.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.176.113.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:33:40.134782 2026] [security2:error] [pid 30191:tid 30191] [client 185.176.113.5:34334] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||speedgo.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "speedgo.mx"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBVBFeqSbj37UmZP8WMYAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
JRID
2026-09-08 18:16:24
(3 hours ago)
Detected by CrowdSec + Suricata IDS: automated attack/scan against web servers.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:12:52
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.176.113.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.176.113.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:12:47.881048 2026] [security2:error] [pid 8035:tid 8058] [client 185.176.113.5:34357] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||annacaird.com.iancaird.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "annacaird.com.iancaird.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBQHzLTzi_xtK_R4SFmaAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
QT
2026-09-08 16:26:06
(5 hours ago)
Unauthorised WordPress admin login attempted at 2026-09-09 02:26:00 +1000
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:48:54
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.176.113.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.176.113.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:48:51.112904 2026] [security2:error] [pid 1714850:tid 1715215] [client 185.176.113.5:32159] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||managementlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "managementlaw.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqASQ90VIYzC24HGNdGvnwAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lostswordfish.com
2026-09-08 13:44:03
(8 hours ago)
Wordfence waf block on illinoisvoices
Web App Attack
🇲🇹
Malta
2026-09-08 13:24:00
(8 hours ago)
185.176.113.5 - - [08/Sep/2026:15:24:00 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
185.176.113.5 - - [08/Sep/2026:15:24:00 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 12:08:27
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.176.113.5 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 185.176.113.5 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:08:21.144348 2026] [security2:error] [pid 5218:tid 5218] [client 185.176.113.5:32019] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||parastesh.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "parastesh.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_6tRJliUn2mYBVhXY_vgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 11:51:43
(10 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-08 11:37:19
(10 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
nyt
2026-09-08 11:19:11
(10 hours ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack