๐ฒ๐ฝ
octageeks.com
2026-09-26 04:15:22
(1 day ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 12:32:40
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 188.126.88.14 (188-126-88-14.static.glesys.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 188.126.88.14 (188-126-88-14.static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 08:32:34.067237 2026] [security2:error] [pid 7240:tid 7240] [client 188.126.88.14:55625] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.feiz.church|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.feiz.church"] [uri "/wp-json/wp/v2/users/"] [unique_id "arZp4snvsDFtCT703Yx6ngAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-25 12:13:11
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
paissangroup
2026-09-25 12:12:47
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 12:10:35
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 188.126.88.14 (188-126-88-14.static.glesys.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 188.126.88.14 (188-126-88-14.static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 08:10:28.005954 2026] [security2:error] [pid 9037:tid 9037] [client 188.126.88.14:6156] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||erikageyama.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "erikageyama.com"] [uri "/portfolio/wp-json/wp/v2/users/"] [unique_id "arZksz-bwqOCQTse0OGcJgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-09-25 11:09:39
(2 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐ฎ๐ฑ
Dolphi
2026-09-25 11:02:14
(2 days ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
๐ซ๐ฎ
YF
2026-09-25 11:00:30
(2 days ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
Anonymous
2026-09-25 10:52:49
(2 days ago)
(wordpress) Failed wordpress login from 188.126.88.14 (FI/Finland/188-126-88-14.static.glesys.net)
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-25 10:50:24
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 188.126.88.14 (188-126-88-14.static.glesys.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 188.126.88.14 (188-126-88-14.static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 06:50:17.146302 2026] [security2:error] [pid 28936:tid 28936] [client 188.126.88.14:58067] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.americanureport.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.americanureport.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "arZR6ZaoJ-gyPgFHzJCYBwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-25 10:17:16
(2 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-09-25 10:13:43
(2 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
SE/Sweden/188-126-88-14.static.glesys.net
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 10:07:13
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 188.126.88.14 (188-126-88-14.static.glesys.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 188.126.88.14 (188-126-88-14.static.glesys.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 06:07:07.348010 2026] [security2:error] [pid 30177:tid 30177] [client 188.126.88.14:40430] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.doreenkimura.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.doreenkimura.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "arZHy3AUAJckErey7TcH9QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRob
2026-09-25 10:05:24
(2 days ago)
This address sends abusive requests to WordPress sites we host: user enumeration through the REST AP ...
show more
This address sends abusive requests to WordPress sites we host: user enumeration through the REST API, xmlrpc.php calls the site refuses, endpoints the site does not serve. These are the reconnaissance and attack calls of automated WordPress attack tools, blocked on sight. Please check the machine behind it. | method: POST | path: //xmlrpc.php | 2026-09-25 10:05 UTC
show less
Web App Attack
Hacking
๐บ๐ธ
mnsf
2026-09-25 10:05:11
(2 days ago)
Too many Status 40X (11)
Brute-Force
Web App Attack