Anonymous
2026-09-25 12:20:50
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-25 10:50:35
(1 day ago)
(wordpress) Failed wordpress login from 2600:3c02::f03c:91ff:fe1f:dc4a (US/United States/Georgia/Atl ...
show more
(wordpress) Failed wordpress login from 2600:3c02::f03c:91ff:fe1f:dc4a (US/United States/Georgia/Atlanta/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
lostswordfish.com
2026-09-23 06:36:04
(3 days ago)
Wordfence waf block on lostswordfish
Web App Attack
๐บ๐ธ
1cyb3rpunk
2026-09-21 23:05:54
(4 days ago)
Coordinated campaign CMP-1790024482-139: 3 IPs sharing an attack fingerprint (wordpress_xmlrpc). Obs ...
show more
Coordinated campaign CMP-1790024482-139: 3 IPs sharing an attack fingerprint (wordpress_xmlrpc). Observed on sectrace.org honeypot surface.
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 18:33:53
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 14:33:47.557410 2026] [security2:error] [pid 30234:tid 30234] [client 2600:3c02::f03c:91ff:fe1f:dc4a:58454] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||healthmarkcounseling.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "healthmarkcounseling.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arAnC6fuHRA_hCeW8U_xjQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 17:57:18
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 13:57:10.917360 2026] [security2:error] [pid 24249:tid 24249] [client 2600:3c02::f03c:91ff:fe1f:dc4a:27914] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lightbender.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lightbender.net"] [uri "/wp-json/wp/v2/users"] [unique_id "arAedlduLF70owAZDcfPgQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 21:31:36
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 17:31:30.433708 2026] [security2:error] [pid 10320:tid 10407] [client 2600:3c02::f03c:91ff:fe1f:dc4a:34216] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jeanpaullederer.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jeanpaullederer.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7_Mtgj7Z0NdhbqBI9KxAAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 18:28:07
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 14:28:04.740492 2026] [security2:error] [pid 24169:tid 24169] [client 2600:3c02::f03c:91ff:fe1f:dc4a:58056] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||crep-psych.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "crep-psych.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7UNPZ25EsFxZ3vrmbnBgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 17:32:22
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 13:32:16.500069 2026] [security2:error] [pid 15371:tid 15371] [client 2600:3c02::f03c:91ff:fe1f:dc4a:16574] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||d365geek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "d365geek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq7HIAUrYG267lVF0LAVJAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-19 17:26:40
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-19 16:59:37
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
ger-stg-sifi1
2026-09-19 13:26:36
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 12:26:06
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 08:26:02.711601 2026] [security2:error] [pid 28373:tid 28373] [client 2600:3c02::f03c:91ff:fe1f:dc4a:47292] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fuentevictoria.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fuentevictoria.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5_Wmmdt6dLb_iGki_y6gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-09-19 11:30:52
(1 week ago)
WordPress author enumeration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 10:42:01
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 2600:3c02::f03c:91ff:fe1f:dc4a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 06:41:56.640169 2026] [security2:error] [pid 3744:tid 3744] [client 2600:3c02::f03c:91ff:fe1f:dc4a:38714] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.takemehomedogrescue.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.takemehomedogrescue.org"] [uri "/wp-json/wp/v2/users"] [unique_id "aq5m9Pxsxkw0W1GcTegKXQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack