๐ฉ๐ช
LRob
2026-09-22 09:53:41
(22 hours ago)
This address sends abusive requests to WordPress sites we host: user enumeration through the REST AP ...
show more
This address sends abusive requests to WordPress sites we host: user enumeration through the REST API, xmlrpc.php calls the site refuses, endpoints the site does not serve. These are the reconnaissance and attack calls of automated WordPress attack tools, blocked on sight. Please check the machine behind it. | method: GET | path: /wp-login.php | 2026-09-22 09:53 UTC
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 17:44:56
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 218.38.103.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 218.38.103.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:44:48.698313 2026] [security2:error] [pid 27264:tid 27264] [client 218.38.103.207:39660] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geckoturner.chezlubacov.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geckoturner.chezlubacov.xyz"] [uri "/wp-json/wp/v2/users"] [unique_id "arFtEFw5ZgustyuIZborpwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:48:13
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 218.38.103.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 218.38.103.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:48:05.927547 2026] [security2:error] [pid 9718:tid 9718] [client 218.38.103.207:35446] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grandpont-house.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grandpont-house.org"] [uri "/wp-json/wp/v2/users"] [unique_id "arFRtXft-nsqCdD3ECkSnwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
AlexEventfahrtenIPDB
2026-09-20 15:10:55
(2 days ago)
[Sun Sep 20 17:10:54.358890 2026] [authz_core:error] [pid 509298:tid 509306] [remote 218.38.103.207: ...
show more
[Sun Sep 20 17:10:54.358890 2026] [authz_core:error] [pid 509298:tid 509306] [remote 218.38.103.207:52296] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://alex-eventfahrten.spdns.de/
[Sun Sep 20 17:10:55.351271 2026] [authz_core:error] [pid 509298:tid 509315] [remote 218.38.103.207:52296] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://alex-eventfahrten.de/wp-login.php
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-09-20 13:28:03
(2 days ago)
Wordfence waf block on registrymatters
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-14 13:41:16
(1 week ago)
(wordpress) Failed wordpress login from 218.38.103.207 (KR/South Korea/Gyeonggi-do/Namyangju/-/[reda ...
show more
(wordpress) Failed wordpress login from 218.38.103.207 (KR/South Korea/Gyeonggi-do/Namyangju/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐ฒ๐ฝ
octageeks.com
2026-09-14 04:24:24
(1 week ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 12:43:21
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 218.38.103.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 218.38.103.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 08:43:14.664958 2026] [security2:error] [pid 2373:tid 2373] [client 218.38.103.207:47644] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hotpay.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hotpay.co"] [uri "/wp-json/wp/v2/users"] [unique_id "aqaaYoEQzDHZEo-wSkhNkwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-10 18:48:31
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 218.38.103.207 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 218.38.103.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 14:48:23.104936 2026] [security2:error] [pid 28699:tid 28723] [client 218.38.103.207:46840] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||executiveaccounting.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "executiveaccounting.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aqL7d9UwO5a2VMqy4rkX4wAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
spamverify.com
2026-09-10 10:14:55
(1 week ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-09 14:04:55
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฉ๐ช
georgengelmann
2026-09-07 19:00:07
(2 weeks ago)
Failed login attempt for bchpls
Brute-Force
Web App Attack