🇩🇪
LRob
2026-09-08 20:43:22
(1 hour ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /wp-json/wp/v2/users/me | 2026-09-08 20:43 UTC
show less
Bad Web Bot
Anonymous
2026-09-08 19:06:02
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-login.php HTTP/2.0, POST /wp-login.php HTTP/2.0
Hacking
Web App Attack
Anonymous
2026-09-08 18:49:12
(3 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 18:33:58
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 14:33:52.722593 2026] [security2:error] [pid 24505:tid 24505] [client 185.75.49.71:39427] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||guarinofurnituredesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "guarinofurnituredesigns.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBVEAPhNk4co2UuJ8ixvwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 18:18:18
(3 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:54:22
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:54:16.055686 2026] [security2:error] [pid 4641:tid 4641] [client 185.75.49.71:33098] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||casapapayasanmiguel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "casapapayasanmiguel.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBLyEbh4aH8_nNfbrApLAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-08 17:17:22
(4 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:56:14
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:56:08.906131 2026] [security2:error] [pid 8848:tid 8848] [client 185.75.49.71:51855] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||washcountyfair.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "washcountyfair.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqA-KJ9n7MWxrcVAOcIVCwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:59:13
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:59:08.691566 2026] [security2:error] [pid 10587:tid 10587] [client 185.75.49.71:40832] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||livinghopehighschool.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "livinghopehighschool.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAwzNvyiyj3ZKhKVutx2wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
gigatech
2026-09-08 14:40:05
(7 hours ago)
Webserver Probing
Web App Attack
Anonymous
2026-09-08 12:49:04
(9 hours ago)
WordPress Brute Force
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 10:41:51
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:41:44.797191 2026] [security2:error] [pid 24708:tid 24708] [client 185.75.49.71:54572] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bethanpearce.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bethanpearce.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_maJF47WU9hJx03FCeyAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-08 09:22:15
(12 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:01:53
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.75.49.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:01:46.083204 2026] [security2:error] [pid 20073:tid 20073] [client 185.75.49.71:45194] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lenorasflowers.lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lenorasflowers.lahamradio.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_O-sGYONgOm6zBX8bMkAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-07 21:43:55
(1 day ago)
(wordpress) Failed wordpress login from 185.75.49.71 (GR/Greece/Central Macedonia/Serres/-/[redacted ...
show more
(wordpress) Failed wordpress login from 185.75.49.71 (GR/Greece/Central Macedonia/Serres/-/[redacted]): (CF_ENABLE)
show less
Brute-Force