🇩🇪
LRob
2026-09-09 07:43:31
(1 day ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-09 07:43 UTC
Brute-Force
Web App Attack
🇺🇸
lostswordfish.com
2026-09-09 07:06:03
(1 day ago)
Wordfence waf block on baystatereentrynetwork
Web App Attack
Anonymous
2026-09-09 06:00:30
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇮🇹
sssrit
2026-09-09 05:34:44
(1 day ago)
220.76.44.77 - - [09/Sep/2026:07:34:43 +0200] "POST /wp-login.php HTTP/2.0" 401 4719 "https://sssr.i ...
show more
220.76.44.77 - - [09/Sep/2026:07:34:43 +0200] "POST /wp-login.php HTTP/2.0" 401 4719 "https://sssr.it/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:28:22
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:28:16.685672 2026] [security2:error] [pid 25589:tid 25589] [client 220.76.44.77:37396] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||desertalfas.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "desertalfas.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDucLnbweM1k_w4AP2BmwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-09 03:15:41
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:59:19
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:59:13.455871 2026] [security2:error] [pid 925:tid 925] [client 220.76.44.77:37730] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||campnecon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "campnecon.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCvYbmSKMe6uoVb6X5s-wAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:43:50
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:43:43.384755 2026] [security2:error] [pid 536298:tid 536371] [client 220.76.44.77:45582] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nicholsinvest.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nicholsinvest.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCrv86I_NuYtFD3rFrYsgAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:21:40
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:21:34.321264 2026] [security2:error] [pid 20591:tid 20591] [client 220.76.44.77:33628] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kbalan.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kbalan.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCmjtNT1Sh6jIU0gimwHwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:13:05
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:13:00.484891 2026] [security2:error] [pid 9689:tid 9689] [client 220.76.44.77:40626] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mchen-arch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mchen-arch.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCIbGb0CBOeYyaagldtkgAAAHI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:38:50
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:38:43.632624 2026] [security2:error] [pid 26555:tid 26555] [client 220.76.44.77:51338] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wp.hotpay.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wp.hotpay.co"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqByU4hG-HQb4CQxrytZDQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:19:12
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:19:03.394925 2026] [security2:error] [pid 16954:tid 16954] [client 220.76.44.77:43446] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||globaldentalservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "globaldentalservices.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBtt7665vk4GQBJjTzIoAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-08 17:27:13
(1 day ago)
support.paulshipley.com.au:443 220.76.44.77 - - [09/Sep/2026:03:27:10 +1000] "GET /wp/wp-login.php H ...
show more
support.paulshipley.com.au:443 220.76.44.77 - - [09/Sep/2026:03:27:10 +1000] "GET /wp/wp-login.php HTTP/1.1" 404 27401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:54:29
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 220.76.44.77 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:54:21.882816 2026] [security2:error] [pid 650:tid 650] [client 220.76.44.77:41978] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rambleandprose.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rambleandprose.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqA9vRnnMpXg-M0OrYxWNgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 14:29:43
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack