๐บ๐ธ
TPI-Abuse
2026-06-20 18:53:40
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.80.9.235 (mail.megagroup.biz): 1 in the las ...
show more
(mod_security) mod_security (id:225170) triggered by 212.80.9.235 (mail.megagroup.biz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 14:53:32.141634 2026] [security2:error] [pid 23149:tid 23149] [client 212.80.9.235:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "avaliantlife.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajbhrP2CP6rFCPYMcGBykgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 17:07:17
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 212.80.9.235 (mail.megagroup.biz): 1 in the las ...
show more
(mod_security) mod_security (id:225170) triggered by 212.80.9.235 (mail.megagroup.biz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 13:07:13.744179 2026] [security2:error] [pid 16887:tid 16887] [client 212.80.9.235:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||local639.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "local639.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajbIwUknOH1uab7b0xg8CgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-20 12:33:13
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐จ๐ฆ
polycoda
2026-06-20 10:38:55
(10 hours ago)
๐ Probes for wp-login.php and other inexistent URLs
Hacking
Web App Attack
Anonymous
2026-06-20 09:07:04
(12 hours ago)
Bot / scanning and/or hacking attempts: [2/2] done, POST /wp-login.php HTTP/2.0
Hacking
Web App Attack
Anonymous
2026-06-20 08:59:52
(12 hours ago)
2026-06-20T09:51:17.934180+02:00 aion wordpress[1149559]: Authentication attempt for unknown user mi ...
show more
2026-06-20T09:51:17.934180+02:00 aion wordpress[1149559]: Authentication attempt for unknown user michael from 212.80.9.235
2026-06-20T10:59:50.468305+02:00 aion wordpress[713979]: Authentication attempt for unknown user michael from 212.80.9.235
...
show less
Hacking
Brute-Force
๐บ๐ธ
nationaleventpros.com
2026-06-20 08:56:54
(12 hours ago)
WordPress login attempt
Brute-Force
๐ฉ๐ช
Ba-Yu
2026-06-20 08:55:38
(12 hours ago)
WordPress bruteforce
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TAY
2026-06-20 08:51:52
(12 hours ago)
212.80.9.235 - - [20/Jun/2026:16:43:20 +0800] "POST /wp-login.php HTTP/1.1" 200 2642 "https://little ...
show more
212.80.9.235 - - [20/Jun/2026:16:43:20 +0800] "POST /wp-login.php HTTP/1.1" 200 2642 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
212.80.9.235 - - [20/Jun/2026:16:47:25 +0800] "POST /wp-login.php HTTP/1.1" 200 2741 "https://lifetunes.org/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
212.80.9.235 - - [20/Jun/2026:16:51:52 +0800] "POST /wp-login.php HTTP/1.1" 200 2630 "https://athenscross.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐ซ๐ท
tilellit.pro
2026-06-20 08:47:10
(12 hours ago)
Fail2Ban banned 212.80.9.235 for security violations in jail wp-armour. Log: 2026/06/20 08:47:10 [er ...
show more
Fail2Ban banned 212.80.9.235 for security violations in jail wp-armour. Log: 2026/06/20 08:47:10 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 212.80.9.235 | Target: wplogin" , client: 212.80.9.235, server: [REDACTED], request: "POST /wp-login.php HTTP/2.0", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
Anonymous
2026-06-20 08:46:02
(12 hours ago)
Failed Wordpress Logins
Web App Attack
๐จ๐ฟ
ptlab
2026-06-20 08:45:28
(12 hours ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-06-20 08:42:14
(12 hours ago)
(wplogin) Failed WordPress login from 212.80.9.235 (IR/Iran/mail.megagroup.biz): 5 in the last 3600 ...
show more
(wplogin) Failed WordPress login from 212.80.9.235 (IR/Iran/mail.megagroup.biz): 5 in the last 3600 secs (0-122)
show less
Hacking
๐ซ๐ท
dynamix
2026-06-20 08:41:13
(12 hours ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-06-20 08:39:54
(12 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack