๐บ๐ธ
TPI-Abuse
2026-08-31 07:57:54
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 209.46.127.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 209.46.127.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:57:47.196148 2026] [security2:error] [pid 11970:tid 11970] [client 209.46.127.12:49872] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||apexandroids.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "apexandroids.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apUz-y__w2J5Td_GwNu9tQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-08-31 05:43:01
(1 day ago)
Multiple WP Login Attack
Hacking
Exploited Host
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-31 04:08:43
(1 day ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
www.winos.me
2026-08-31 03:53:22
(1 day ago)
Scanning for sensitive files/paths: /wp-login.php
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 03:50:33
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 209.46.127.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 209.46.127.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 23:50:25.822382 2026] [security2:error] [pid 11086:tid 11086] [client 209.46.127.12:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ipv6.local639.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ipv6.local639.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apT6AW-CEJdLL7nYqMnUDwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-31 03:25:28
(1 day ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
Anonymous
2026-08-31 03:11:26
(1 day ago)
Brute forcing Wordpress login
Hacking
Web App Attack
๐ฉ๐ช
nyt
2026-08-31 02:15:41
(1 day ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-08-31 01:31:34
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | 2026-08-31 01:31 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 23:50:05
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 209.46.127.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 209.46.127.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 19:49:57.277787 2026] [security2:error] [pid 3695:tid 3695] [client 209.46.127.12:54812] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||crr-construction.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "crr-construction.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apTBpcFrkMoWl1Piy0DOfgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xxkodedxx
2026-08-30 23:11:17
(1 day ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
Active: 23:10:28 UTC
Volume: 1 honeypot probe(s)
Bait taken: /wp-login.php
UA: "209.46.127.12"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-30 22:57:50
(1 day ago)
Web application attack detected.
Web App Attack
๐ฌ๐ง
spamverify.com
2026-08-30 22:55:31
(1 day ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ซ๐ท
tecnicorioja
2026-08-30 22:00:43
(1 day ago)
wp-login attack [30/Aug/2026:11:00:46
Brute-Force
Web App Attack
๐ฉ๐ช
AlexEventfahrtenIPDB
2026-08-30 21:55:04
(1 day ago)
[Sun Aug 30 23:55:03.123612 2026] [authz_core:error] [pid 771922:tid 771940] [remote 209.46.127.12:3 ...
show more
[Sun Aug 30 23:55:03.123612 2026] [authz_core:error] [pid 771922:tid 771940] [remote 209.46.127.12:37088] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php
[Sun Aug 30 23:55:04.017839 2026] [authz_core:error] [pid 771922:tid 771939] [remote 209.46.127.12:37098] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/wp-login.php
...
show less
Brute-Force
Web App Attack