Anonymous
2026-08-28 19:00:02
(47 minutes ago)
Failed Wordpress Logins
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:44:02
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net ...
show more
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:43:58.077398 2026] [security2:error] [pid 22680:tid 22680] [client 2400:b800:8::91:52506] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kaldaragroup.com.greenlight.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kaldaragroup.com.greenlight.us"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apHI3i7JcRD2rkT9F9mQRAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-28 07:53:58
(11 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-28 07:39:30
(12 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ท
Yepngo
2026-08-28 05:53:01
(13 hours ago)
2400:b800:8::91 - - [28/Aug/2026:07:53:00 +0200] "POST /wp-login.php HTTP/2.0" 200 12510 "https://ye ...
show more
2400:b800:8::91 - - [28/Aug/2026:07:53:00 +0200] "POST /wp-login.php HTTP/2.0" 200 12510 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 05:40:27
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net ...
show more
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:40:20.892069 2026] [security2:error] [pid 1509:tid 1509] [client 2400:b800:8::91:42926] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||walkercline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "walkercline.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apEfRE1UxvD0phzGdZAiNwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-08-28 05:10:15
(14 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 05:10:01
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net ...
show more
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:09:56.066247 2026] [security2:error] [pid 2626:tid 2626] [client 2400:b800:8::91:32794] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nesetsv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nesetsv.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apEYJAqp4IjUd1B2-GImaAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 04:11:53
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net ...
show more
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:11:39.920534 2026] [security2:error] [pid 3411:tid 3411] [client 2400:b800:8::91:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ac.cloudex.click|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ac.cloudex.click"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apEKe9Oy9Y-oWIu8pBZ2OwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Yepngo
2026-08-28 01:18:30
(18 hours ago)
2400:b800:8::91 - - [28/Aug/2026:03:18:30 +0200] "POST /wp-login.php HTTP/2.0" 200 12510 "https://ye ...
show more
2400:b800:8::91 - - [28/Aug/2026:03:18:30 +0200] "POST /wp-login.php HTTP/2.0" 200 12510 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
Yepngo
2026-08-27 21:44:44
(22 hours ago)
2400:b800:8::91 - - [27/Aug/2026:23:36:00 +0200] "POST /wp-login.php HTTP/2.0" 200 12507 "https://bl ...
show more
2400:b800:8::91 - - [27/Aug/2026:23:36:00 +0200] "POST /wp-login.php HTTP/2.0" 200 12507 "https://blog.yepngo.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
2400:b800:8::91 - - [27/Aug/2026:23:44:43 +0200] "POST /wp-login.php HTTP/2.0" 200 12510 "https://blog.yepngo.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 18:24:23
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net ...
show more
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:24:18.293046 2026] [security2:error] [pid 11330:tid 11330] [client 2400:b800:8::91:43408] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||churchbehindthewalls.bridgital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "churchbehindthewalls.bridgital.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apCA0qKC8WiW30zYlEMKIgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
www.winos.me
2026-08-27 17:09:13
(1 day ago)
Scanning for sensitive files/paths: /wp-login.php
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 15:14:39
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net ...
show more
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 11:14:31.241369 2026] [security2:error] [pid 22417:tid 22417] [client 2400:b800:8::91:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "avaliantlife.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apBUV54G-c7fF7D7pnfZawAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 14:07:31
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net ...
show more
(mod_security) mod_security (id:225170) triggered by 2400:b800:8::91 (s06ae.syd6.hostingplatform.net.au): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:07:24.282955 2026] [security2:error] [pid 31541:tid 31541] [client 2400:b800:8::91:44008] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||soudertonbigred.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "soudertonbigred.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apBEnK-O3vGNupY8CCoW_AAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack