🇺🇸
cwytech
2026-09-08 10:35:14
(7 minutes ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:00:09
(42 minutes ago)
(mod_security) mod_security (id:225170) triggered by 193.92.55.159 (193.92.55.159.dsl.dyn.forthnet.g ...
show more
(mod_security) mod_security (id:225170) triggered by 193.92.55.159 (193.92.55.159.dsl.dyn.forthnet.gr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:00:02.879339 2026] [security2:error] [pid 9036:tid 9036] [client 193.92.55.159:39252] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gvimmobilier.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gvimmobilier.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_couiw0P6n6_CsECRPiAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 09:54:49
(47 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
Anonymous
2026-09-08 09:40:01
(1 hour ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-08 09:34:15
(1 hour ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:24:46
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 193.92.55.159 (193.92.55.159.dsl.dyn.forthnet.g ...
show more
(mod_security) mod_security (id:225170) triggered by 193.92.55.159 (193.92.55.159.dsl.dyn.forthnet.gr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:24:40.705415 2026] [security2:error] [pid 3307558:tid 3307558] [client 193.92.55.159:51130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nancyscafeandcatering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nancyscafeandcatering.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_UWPhxidcQT3fBryArtAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:50:49
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 193.92.55.159 (193.92.55.159.dsl.dyn.forthnet.g ...
show more
(mod_security) mod_security (id:225170) triggered by 193.92.55.159 (193.92.55.159.dsl.dyn.forthnet.gr): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:50:42.527351 2026] [security2:error] [pid 18033:tid 18033] [client 193.92.55.159:49356] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||americanacademyofteachersofsinging.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "americanacademyofteachersofsinging.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_MYnjAEJ_2VrDNibpE1QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 08:48:57
(1 hour ago)
cloudlinux2 fail2ban: 2026-09-08 10:43:59,126 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-08 10:43:59,126 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 216.73.160.64 - 2026-09-08 10:43:58cloudlinux2 fail2ban: 2026-09-08 10:44:11,346 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 136.108.5.145cloudlinux2 fail2ban: 2026-09-08 10:44:30,583 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 37.228.254.95cloudlinux2 fail2ban: 2026-09-08 10:44:49,314 fail2ban.filter [1794]: INFO [recidive] Found 175.100.53.184 - 2026-09-08 10:44:48cloudlinux2 fail2ban: 2026-09-08 10:44:48,819 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Ban 175.100.53.184cloudlinux2 fail2ban: 2026-09-08 10:44:48,754 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 175.100.53.184 - 2026-09-08 10:44:48cloudlinux2 fail2ban: 2026-09-08 10:45:30,082 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 34.65.208.106cloudlinux2 fail2ban: 2026-09-08 10:45:32,247 fail2ban.filter [1794]: INFO [plesk-
show less
Web App Attack
🇩🇪
nyt
2026-09-08 03:59:01
(6 hours ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
🇩🇪
LRob
2026-09-08 03:55:25
(6 hours ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-08 03:55 UTC
Brute-Force
Web App Attack
🇩🇪
Lino Project
2026-09-08 02:42:07
(8 hours ago)
193.92.55.159 - - [08/Sep/2026:04:42:02 +0200] "GET /wp-login.php HTTP/2.0" 403 282 "-" "Mozilla/5.0 ...
show more
193.92.55.159 - - [08/Sep/2026:04:42:02 +0200] "GET /wp-login.php HTTP/2.0" 403 282 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
AWW-Admin
2026-09-08 00:21:49
(10 hours ago)
(wordpress) Failed wordpress login from 193.92.55.159 (GR/Greece/193.92.55.159.dsl.dyn.forthnet.gr)
Brute-Force
🇺🇸
nyt
2026-09-07 13:07:18
(21 hours ago)
WP login POST blocked by WAF
Brute-Force
Web App Attack
🇩🇪
Hazzard
2026-09-07 09:58:58
(1 day ago)
(wordpress) Failed wordpress login from 193.92.55.159 (GR/Greece/Attica/Athens/193.92.55.159.dsl.dyn ...
show more
(wordpress) Failed wordpress login from 193.92.55.159 (GR/Greece/Attica/Athens/193.92.55.159.dsl.dyn.forthnet.gr/[redacted]): (CF_ENABLE)
show less
Brute-Force
🇺🇸
sumnone
2026-09-06 18:25:02
(1 day ago)
Port probing on unauthorized port 23
Port Scan
Hacking
Exploited Host