Anonymous
2026-08-26 16:47:08
(51 minutes ago)
Multiple failed login attemps RDS-Web-Access-Server
Brute-Force
Web App Attack
Anonymous
2026-08-24 19:35:13
(1 day ago)
Multiple failed login attemps RDS-Web-Access-Server
Brute-Force
Web App Attack
Anonymous
2026-08-21 23:41:47
(4 days ago)
Multiple failed login attemps RDS-Web-Access-Server
Brute-Force
Web App Attack
๐ช๐ธ
librebit
2026-08-20 10:41:08
(6 days ago)
Brute force
Brute-Force
๐ฉ๐ช
georgengelmann
2026-07-15 14:29:57
(1 month ago)
Failed login attempt for admin
Brute-Force
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-06-14 20:45:27
(2 months ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-02 21:42:57
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.136.221 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.136.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 17:42:51.296437 2026] [security2:error] [pid 29965:tid 29965] [client 185.201.136.221:9357] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mtalame.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mtalame.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah9OW45Ckc-ukTZZZw9VbQAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 00:58:50
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.136.221 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.136.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 20:58:43.563057 2026] [security2:error] [pid 31453:tid 31453] [client 185.201.136.221:29119] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newerc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newerc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahjkw1X_U3SrXa4T-cnBRQAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ne1for23
2026-05-24 21:56:46
(3 months ago)
185.201.136.221 - - [24/May/2026:21:56:46 +0000] "POST /xmlrpc.php HTTP/1.1" 403 153 "-" "Apache-Htt ...
show more
185.201.136.221 - - [24/May/2026:21:56:46 +0000] "POST /xmlrpc.php HTTP/1.1" 403 153 "-" "Apache-HttpClient/4.5.13 (Java/17.0.18)"
show less
Hacking
Web App Attack
๐บ๐ธ
ambor
2026-05-18 21:10:03
(3 months ago)
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: ...
show more
Honeypot triggered on tcpdata.com - Attempted to access /wp-login.php (wordpress_login). User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Web App Attack
๐จ๐ญ
4server
2026-05-18 16:41:34
(3 months ago)
[MonMay1818:41:28.4503002026][security2:error][pid801074:tid801094][client185.201.136.221:0]ModSecur ...
show more
[MonMay1818:41:28.4503002026][security2:error][pid801074:tid801094][client185.201.136.221:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"367\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"shakary.com\"][uri\"/xmlrpc.php\"][unique_id\"agtBOIdgYe_wtlKV2LYl5wAAABI\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
kjaerulff
2026-05-13 17:47:57
(3 months ago)
Failed Wordpress login using wp-login.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-13 13:21:35
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 185.201.136.221 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 185.201.136.221 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 09:21:32.615498 2026] [security2:error] [pid 30585:tid 30602] [client 185.201.136.221:58971] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jab-us.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jab-us.com"] [uri "/wp-json/wp/v2/users"] [unique_id "agR63NwALXZxZ7CnJRSfvwAAAY4"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2026-04-18 15:51:58
(4 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-04-13 06:38:30
(4 months ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH