๐ณ๐ฑ
Mangelot Hosting
2026-10-03 13:29:58
(5 days ago)
(wp_user_enum) srv104 WordPress user enumeration 2a02:c207:2292:4160::1 (DE/Germany/-): 8 in the las ...
show more
(wp_user_enum) srv104 WordPress user enumeration 2a02:c207:2292:4160::1 (DE/Germany/-): 8 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-10-03 12:50:52
(5 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
LRob
2026-10-03 12:43:36
(5 days ago)
Web exploit attempt | method: GET, POST | path: /wp-json/wp/v2/users | ua: Mozilla/5.0 (Windows NT 1 ...
show more
Web exploit attempt | method: GET, POST | path: /wp-json/wp/v2/users | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36 Edg/127.0.0.0, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36 | 2026-10-03 12:43 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
stinpriza
2026-10-03 12:40:06
(5 days ago)
WP Authentication attempt for unknown user
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-10-03 12:12:07
(5 days ago)
Try to access /xmlrpc.php
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-03 11:57:55
(5 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-03 11:55:47
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2292:4160::1 (srv.i237.cc): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2292:4160::1 (srv.i237.cc): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 07:55:40.239691 2026] [security2:error] [pid 17339:tid 17339] [client 2a02:c207:2292:4160::1:52638] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thebrotherhoodlounge.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thebrotherhoodlounge.com"] [uri "/wp-json/wp/v2/users/12"] [unique_id "asDtPDr-ezhSab0k4_j7qAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-10-03 11:55:41
(5 days ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-03 11:38:44
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2292:4160::1 (srv.i237.cc): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2292:4160::1 (srv.i237.cc): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 07:38:38.243265 2026] [security2:error] [pid 23803:tid 23803] [client 2a02:c207:2292:4160::1:42916] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "humbliaslaw.com"] [uri "/wp-json/wp/v2/users/5"] [unique_id "asDpPgBPHlfit3CI4v_uDQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-03 11:38:37
(5 days ago)
[ti-24al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-24al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 2a02:c207:2292:4160::1 - - [03/Oct/2026:13:38:16 +0200] "GET /index.php?rest_route=/wp/v2/users?roles=administrator&per_page=100 HTTP/1.1" 404 662 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
2a02:c207:2292:4160::1 - - [03/Oct/2026:13:38:16 +0200] "GET /?rest_route=/wp/v2/users?roles=administrator&per_page=100 HTTP/1.1" 404 662 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/127.0.0.0 Safari/537.36"
2a02:c207:2292:4160::1 - - [03/Oct/2026:13:38:16 +0200] "GET /index.php?rest_route=/wp/v2/users?per_page=100&context=edit HTTP/1.1" 404 662 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gec
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-10-03 11:37:54
(5 days ago)
[03/Oct/2026:13:37:53.785685 +0200] asDpEVioVyPTzrIqakWzAgAAAAE 2a02:c207:2292:4160::1 36234 127.0.0 ...
show more
[03/Oct/2026:13:37:53.785685 +0200] asDpEVioVyPTzrIqakWzAgAAAAE 2a02:c207:2292:4160::1 36234 127.0.0.1 7081
[03/Oct/2026:13:37:53.792215 +0200] asDpEYeUaQ50AKQVA1WXbQAAAEU 2a02:c207:2292:4160::1 36248
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 11:20:29
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2292:4160::1 (srv.i237.cc): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2292:4160::1 (srv.i237.cc): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 07:20:25.757683 2026] [security2:error] [pid 19185:tid 19185] [client 2a02:c207:2292:4160::1:34114] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bigheartskitchen.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bigheartskitchen.net"] [uri "/wp-json/wp/v2/users/15"] [unique_id "asDk-WbZ9l9okED6tLJgEQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-10-03 11:00:44
(5 days ago)
WordPress author enumeration
Web App Attack
๐บ๐ธ
infra-monitor
2026-09-29 11:00:04
(1 week ago)
Automated ban via infra-monitor: wp-sensitive-paths
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-29 09:14:24
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-admin-interface-probing
Web App Attack
Hacking