🇺🇸
cwytech
2026-09-13 23:43:43
(1 hour ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-13 15:27:58
(9 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇲🇽
octageeks.com
2026-09-13 04:22:00
(20 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇩🇪
Hazzard
2026-09-13 02:33:04
(22 hours ago)
(wordpress) Failed wordpress login from 31.30.166.217 (CZ/Czechia/Prague/Prague/cst2-166-217.cust.vo ...
show more
(wordpress) Failed wordpress login from 31.30.166.217 (CZ/Czechia/Prague/Prague/cst2-166-217.cust.vodafone.cz/[redacted]): (CF_ENABLE)
show less
Brute-Force
Anonymous
2026-09-13 01:25:49
(23 hours ago)
WordPress Brute Force
Brute-Force
🇩🇪
ger-stg-sifi1
2026-09-12 19:42:16
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇮🇹
CoreTech srl
2026-09-12 18:08:56
(1 day ago)
cloudlinux2 fail2ban: 2026-09-12 20:04:50,047 fail2ban.filter [1606]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-12 20:04:50,047 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 27.34.64.62 - 2026-09-12 20:04:50cloudlinux2 fail2ban: 2026-09-12 20:04:55,135 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Unban 34.174.75.231cloudlinux2 fail2ban: 2026-09-12 20:05:51,668 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 27.34.64.62 - 2026-09-12 20:05:51cloudlinux2 fail2ban: 2026-09-12 20:06:05,230 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Unban 34.86.28.158cloudlinux2 fail2ban: 2026-09-12 20:06:43,293 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Unban 34.35.75.156cloudlinux2 fail2ban: 2026-09-12 20:06:58,689 fail2ban.filter [1606]: INFO [plesk-wordpress] Found 31.30.166.217 - 2026-09-12 20:06:58cloudlinux2 fail2ban: 2026-09-12 20:07:46,521 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 188.27.132.171 - 2026-09-12 20:07:46cloudlinux2 fail2ban: 2026-09-12 20:08:27,888 fail2ban.filter
show less
Web App Attack
🇦🇺
QT
2026-09-12 15:14:21
(1 day ago)
Unauthorised WordPress admin login attempted at 2026-09-13 01:14:14 +1000
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-12 13:10:03
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇫🇮
JimArchon72
2026-09-12 10:15:02
(1 day ago)
2026/09/12 10:11:47 "GET /wp-login.php HTTP/2.0"
Web App Attack
🇧🇪
taivas.nl
2026-09-12 10:02:11
(1 day ago)
Bad_requests
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 09:58:27
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 31.30.166.217 (cst2-166-217.cust.vodafone.cz): ...
show more
(mod_security) mod_security (id:225170) triggered by 31.30.166.217 (cst2-166-217.cust.vodafone.cz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:58:21.052112 2026] [security2:error] [pid 11802:tid 11802] [client 31.30.166.217:54872] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newhopepetgrooming.leonardodecaprio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newhopepetgrooming.leonardodecaprio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqUiPTgMKNlPXnHRFlgBAgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇹
Malta
2026-09-12 08:05:27
(1 day ago)
31.30.166.217 - - [12/Sep/2026:10:05:27 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh ...
show more
31.30.166.217 - - [12/Sep/2026:10:05:27 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇩🇪
FeG Deutschland
2026-09-12 04:28:46
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1257
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 02:21:43
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 31.30.166.217 (cst2-166-217.cust.vodafone.cz): ...
show more
(mod_security) mod_security (id:225170) triggered by 31.30.166.217 (cst2-166-217.cust.vodafone.cz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 22:21:38.673813 2026] [security2:error] [pid 12229:tid 12229] [client 31.30.166.217:54500] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||convtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "convtek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqS3MoRsHY-JQDJkZiJfkQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack