π¬π§
spamverify.com
2026-07-31 17:11:46
(14 hours ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-07-22 07:33:16
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π©πͺ
Hazzard
2026-07-20 16:05:53
(1 week ago)
(wordpress) Failed wordpress login from 216.222.196.106 (US/United States/-/-/sh-cp7.lax2.servername ...
show more
(wordpress) Failed wordpress login from 216.222.196.106 (US/United States/-/-/sh-cp7.lax2.servername.online/[redacted]): (CF_ENABLE)
show less
Brute-Force
π²πΉ
Malta
2026-06-30 09:53:42
(1 month ago)
216.222.196.106 - - [30/Jun/2026:11:53:42 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Ub ...
show more
216.222.196.106 - - [30/Jun/2026:11:53:42 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-29 02:18:59
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online) ...
show more
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 22:18:56.220675 2026] [security2:error] [pid 18797:tid 18797] [client 216.222.196.106:46584] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||walterceron.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "walterceron.com"] [uri "/wp-json/wp/v2/users/9"] [unique_id "akHWEFi5MQzLZ7QxLHNSHAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-28 21:36:31
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online) ...
show more
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 17:36:24.920759 2026] [security2:error] [pid 12028:tid 12028] [client 216.222.196.106:59264] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||market1st.bridgital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "market1st.bridgital.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "akGT2LXPQyAbF7Pr--2pHAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-28 15:02:12
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online) ...
show more
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 11:02:05.653603 2026] [security2:error] [pid 5438:tid 5438] [client 216.222.196.106:45354] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||naturalacu.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "naturalacu.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akE3bauHHCnD9b31zI885wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-28 14:30:23
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online) ...
show more
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 10:30:18.079228 2026] [security2:error] [pid 19775:tid 19775] [client 216.222.196.106:58120] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "humbliaslaw.com"] [uri "/wp-json/wp/v2/users/7"] [unique_id "akEv-pMFti1BMmvgLmTlmgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-06-28 09:35:52
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π¨πΏ
ptlab
2026-06-28 04:45:10
(1 month ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
π²πΉ
Malta
2026-06-27 00:56:13
(1 month ago)
216.222.196.106 - - [27/Jun/2026:02:56:12 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Ub ...
show more
216.222.196.106 - - [27/Jun/2026:02:56:12 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-25 04:46:15
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online) ...
show more
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 00:46:11.239174 2026] [security2:error] [pid 3089:tid 3099] [client 216.222.196.106:33938] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||travelusa.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "travelusa.us"] [uri "/wp-json/wp/v2/users"] [unique_id "ajyyk8tGI2kRddl9lju7KQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
cwytech
2026-06-17 01:57:53
(1 month ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
Anonymous
2026-06-16 07:45:19
(1 month ago)
Web attack blocked by Wordfence on mezzia.nl (1 hit). Reported by CRMON.
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-13 03:03:58
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online) ...
show more
(mod_security) mod_security (id:225170) triggered by 216.222.196.106 (sh-cp7.lax2.servername.online): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 23:03:52.481043 2026] [security2:error] [pid 31024:tid 31024] [client 216.222.196.106:56294] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||birdlovesfish.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "birdlovesfish.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aizImLBFJuYFAZ5GndZFVAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack