🇩🇪
FeG Deutschland
2026-09-11 08:53:45
(13 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇩🇪
LRob
2026-09-11 07:19:49
(15 hours ago)
WordPress login brute-force | path: /wp-fi/wp-login.php | 2026-09-11 07:19 UTC
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 02:39:20
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:39:12.149924 2026] [security2:error] [pid 25475:tid 25475] [client 222.120.25.190:35519] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||customhumanrobots.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "customhumanrobots.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqNp0BqIABHzT9h6McRuswAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 01:12:34
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 21:12:28.702970 2026] [security2:error] [pid 4523:tid 4523] [client 222.120.25.190:11406] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theroyalhouseofelohim.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theroyalhouseofelohim.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aqNVfGj5xnn3QtXHhl_IyAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 23:33:05
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 19:33:00.798039 2026] [security2:error] [pid 2548:tid 2548] [client 222.120.25.190:60766] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||schwanpaint.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "schwanpaint.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqM-LPNNnfPbk-TzgdeasgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-10 06:31:46
(1 day ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /wp-login.php | 2026-09-10 06:31 UTC
show less
Bad Web Bot
🇲🇽
octageeks.com
2026-09-10 04:21:36
(1 day ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇩🇪
FeG Deutschland
2026-09-10 01:42:04
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-09 05:51:21
(2 days ago)
WordPress login attempt
Brute-Force
Anonymous
2026-09-09 05:48:11
(2 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:38:35
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:38:29.093990 2026] [security2:error] [pid 7595:tid 7595] [client 222.120.25.190:10005] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||georgesmarina.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "georgesmarina.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDw1WhajPr8O0-dzrY22wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lostswordfish.com
2026-09-09 05:04:04
(2 days ago)
Wordfence waf block on ncrsol
Web App Attack
🇩🇪
LRob
2026-09-09 03:35:10
(2 days ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-09 03:35 UTC
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:15:18
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:15:10.199387 2026] [security2:error] [pid 563455:tid 563455] [client 222.120.25.190:60955] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arogun.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arogun.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDPPsPw3HeIlQplgdw64wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:24:05
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 222.120.25.190 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:23:57.052749 2026] [security2:error] [pid 13277:tid 13277] [client 222.120.25.190:46388] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goodfrequencies.circleofsound.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goodfrequencies.circleofsound.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDDPbgFXn0Nzir7j1NsSgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack