🇲🇽
octageeks.com
2026-08-30 04:07:39
(16 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 04:05:54
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 199.188.201.127 (server282.web-hosting.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 199.188.201.127 (server282.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 00:05:48.331625 2026] [security2:error] [pid 23951:tid 23951] [client 199.188.201.127:47266] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||texascottagebakers.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "texascottagebakers.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apOsHLO4dEKWh1D66iryAwAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-30 04:03:04
(16 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-30 03:47:05
(17 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 01:01:32
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 199.188.201.127 (server282.web-hosting.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 199.188.201.127 (server282.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 21:01:24.874601 2026] [security2:error] [pid 21255:tid 21255] [client 199.188.201.127:33068] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lasertherapyoc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lasertherapyoc.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apOA5OJDnBCyluPtFA-bRQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-08-29 22:53:55
(22 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇨🇿
ptlab
2026-08-29 20:45:28
(1 day ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 19:08:42
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 199.188.201.127 (server282.web-hosting.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 199.188.201.127 (server282.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 15:08:34.688824 2026] [security2:error] [pid 23272:tid 23272] [client 199.188.201.127:59196] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nolaanime.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nolaanime.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apMuMguMO6KRKKPJ7Uv67AAAAGY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
gigatech
2026-08-29 16:50:03
(1 day ago)
Webserver Probing
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 16:47:24
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 199.188.201.127 (server282.web-hosting.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 199.188.201.127 (server282.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 12:47:19.192086 2026] [security2:error] [pid 21547:tid 21547] [client 199.188.201.127:60502] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||egelfitness.nl|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "egelfitness.nl"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apMNF4xt7-rVs_zP3IsNDwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-08-29 16:24:34
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇺🇸
wordpresshosting.solutions
2026-08-29 16:22:47
(1 day ago)
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 199.188.201.127 - - [29/Aug/202 ...
show more
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 199.188.201.127 - - [29/Aug/2026:16:22:46 +0000] "GET /wp-login.php HTTP/1.1" 200 9836 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
199.188.201.127 - - [29/Aug/2026:16:22:47 +0000] "POST /wp-login.php HTTP/1.1" 503 26322 "https://[DOMAIN]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
🇹🇷
oalver
2026-08-29 11:28:35
(1 day ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-08-29. Risk score: 30/100.
show less
Web App Attack
🇫🇷
SpaceHost-Server
2026-08-29 10:16:30
(1 day ago)
199.188.201.127 - - [29/Aug/2026:12:16:29 +0200] "POST /wp-login.php HTTP/1.1" 200 16112 "https://de ...
show more
199.188.201.127 - - [29/Aug/2026:12:16:29 +0200] "POST /wp-login.php HTTP/1.1" 200 16112 "https://demo-2020child.wp4dich.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
199.188.201.127 - - [29/Aug/2026:12:16:29 +0200] "POST /wp-login.php HTTP/1.1" 200 16106 "https://demo-2020child.wp4dich.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
199.188.201.127 - - [29/Aug/2026:12:16:29 +0200] "POST /wp-login.php HTTP/1.1" 200 16128 "https://demo-2020child.wp4dich.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 07:09:05
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 199.188.201.127 (server282.web-hosting.com): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 199.188.201.127 (server282.web-hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:08:57.926652 2026] [security2:error] [pid 11085:tid 11085] [client 199.188.201.127:37070] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||georgesmarina.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "georgesmarina.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apKFiVSH78GlGbKed30w0QAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack