Anonymous
2026-08-30 06:46:29
(2 days ago)
Failed Wordpress Logins
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-29 00:00:42
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-08-28 21:46:24
(3 days ago)
Failed Wordpress Logins
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 01:35:16
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:3071:1f6e::2 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:3071:1f6e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 21:35:10.656469 2026] [security2:error] [pid 18645:tid 18708] [client 2a01:4f9:3071:1f6e::2:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mindgardens.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mindgardens.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apDlzoQynPaB_UprtL0-GQAAAdg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
F242
2026-08-28 01:08:37
(4 days ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐ซ๐ท
Yepngo
2026-08-28 00:19:44
(4 days ago)
2a01:4f9:3071:1f6e::2 - - [28/Aug/2026:02:19:44 +0200] "POST /wp-login.php HTTP/2.0" 200 12503 "http ...
show more
2a01:4f9:3071:1f6e::2 - - [28/Aug/2026:02:19:44 +0200] "POST /wp-login.php HTTP/2.0" 200 12503 "https://dev.yepngo.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
karger
2026-08-27 23:24:57
(4 days ago)
Wordpress attack - soft filter
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 23:17:55
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:3071:1f6e::2 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:3071:1f6e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 19:17:51.350875 2026] [security2:error] [pid 30042:tid 30042] [client 2a01:4f9:3071:1f6e::2:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||yggdrasil.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "yggdrasil.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apDFn1aSThKCTyIIQ5x7CQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-27 23:13:41
(4 days ago)
WordPress login brute-force | path: /wp-login.php | 2026-08-27 23:13 UTC
Brute-Force
Web App Attack
๐ฉ๐ช
juutis
2026-08-27 20:16:41
(4 days ago)
2a01:4f9:3071:1f6e::2 - - [27/Aug/2026:08:42:28 +0200] "POST /wp-login.php HTTP/1.1" 200 9634 "https ...
show more
2a01:4f9:3071:1f6e::2 - - [27/Aug/2026:08:42:28 +0200] "POST /wp-login.php HTTP/1.1" 200 9634 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
2a01:4f9:3071:1f6e::2 - - [27/Aug/2026:21:20:42 +0200] "POST /wp-login.php HTTP/1.1" 200 9635 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
2a01:4f9:3071:1f6e::2 - - [27/Aug/2026:22:16:39 +0200] "POST /wp-login.php HTTP/1.1" 200 9604 "https://taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 20:16:00
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:3071:1f6e::2 (Unknown): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 2a01:4f9:3071:1f6e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 16:15:53.636287 2026] [security2:error] [pid 25651:tid 25651] [client 2a01:4f9:3071:1f6e::2:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ipv6.local639.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ipv6.local639.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apCa-b-5xDrmD3a2gHcn9wAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-08-27 19:37:15
(4 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
๐ซ๐ท
Yepngo
2026-08-27 18:59:01
(4 days ago)
2a01:4f9:3071:1f6e::2 - - [27/Aug/2026:20:59:00 +0200] "POST /wp-login.php HTTP/2.0" 200 12510 "http ...
show more
2a01:4f9:3071:1f6e::2 - - [27/Aug/2026:20:59:00 +0200] "POST /wp-login.php HTTP/2.0" 200 12510 "https://yepngo.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
www.winos.me
2026-08-27 18:38:22
(4 days ago)
Scanning for sensitive files/paths: /wp-login.php
Hacking
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-27 17:51:11
(4 days ago)
(PERMBLOCK) 2a01:4f9:3071:1f6e::2 (FI/Finland/Uusimaa/Helsinki/-/[redacted]) has had more than 4 tem ...
show more
(PERMBLOCK) 2a01:4f9:3071:1f6e::2 (FI/Finland/Uusimaa/Helsinki/-/[redacted]) has had more than 4 temp blocks
show less
Hacking