π©πͺ
neckaralb-admin.de
2026-07-22 19:55:12
(8 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
ger-stg-sifi1
2026-07-22 19:20:46
(8 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
FeG Deutschland
2026-07-22 16:15:56
(11 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
π¨πΏ
ptlab
2026-07-22 12:45:08
(15 hours ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
π²π½
octageeks.com
2026-07-07 04:25:49
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
π©πͺ
ger-stg-sifi1
2026-07-07 01:22:39
(2 weeks ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
neckaralb-admin.de
2026-07-07 00:33:48
(2 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
FeG Deutschland
2026-07-04 02:42:23
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-03 11:00:53
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 07:00:49.748996 2026] [security2:error] [pid 27146:tid 27146] [client 20.84.23.223:5370] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||n4fh.cosentient.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "n4fh.cosentient.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akeWYZkeAurlYwf9goNZKwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-29 10:33:20
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 06:33:15.498458 2026] [security2:error] [pid 2842:tid 2842] [client 20.84.23.223:5596] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fractalsky.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fractalsky.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akJJ6-73TrXh0FyjozTiPgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-29 09:20:57
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 05:20:54.141522 2026] [security2:error] [pid 5322:tid 5322] [client 20.84.23.223:4206] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cornerstonecharitablescholarshiptrust.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cornerstonecharitablescholarshiptrust.org"] [uri "/wp-json/wp/v2/users/9"] [unique_id "akI49qapo21RzuDyIcKOTwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-29 08:07:50
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 04:07:43.515104 2026] [security2:error] [pid 12190:tid 12190] [client 20.84.23.223:4185] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||earthwormensemble.doublenaughtspycar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "earthwormensemble.doublenaughtspycar.com"] [uri "/wp-json/wp/v2/users/5"] [unique_id "akInz2eWBwmOzWqST5o6QQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
ketovoila.pl
2026-06-29 07:51:05
(3 weeks ago)
ketovoila.pl WordPress user/author enumeration: hits=1; unique_paths=1; sample_paths=/?author=3&feed ...
show more
ketovoila.pl WordPress user/author enumeration: hits=1; unique_paths=1; sample_paths=/?author=3&feed=rss2; UA="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"; window=2026-06-29T07:51:05Z..2026-06-29T07:51:05Z
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-29 02:53:28
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 22:53:21.572097 2026] [security2:error] [pid 1078:tid 1078] [client 20.84.23.223:3963] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||capriexpress.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "capriexpress.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akHeIQANz_LRlzbFqzwnDgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-29 02:17:34
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 20.84.23.223 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 22:17:30.291615 2026] [security2:error] [pid 32188:tid 32188] [client 20.84.23.223:3947] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greenmountainfeeds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greenmountainfeeds.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akHVunElIRHQ0RGEhZ5a-wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack