๐ฉ๐ช
FeG Deutschland
2026-07-19 08:51:52
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐บ๐ธ
cwytech
2026-07-16 12:59:07
(1 week ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-16 04:08:33
(1 week ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-05 04:11:21
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 07:19:49
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 03:19:41.528285 2026] [security2:error] [pid 4718:tid 4768] [client 35.200.137.92:57196] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||leadingedgesupply.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "leadingedgesupply.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "aki0DSD9CF-1Z5bEzcY8SgAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 05:48:21
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 01:48:14.241969 2026] [security2:error] [pid 3257:tid 3277] [client 35.200.137.92:55506] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||supercyprus.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "supercyprus.com"] [uri "/wp-json/wp/v2/users/3"] [unique_id "akienpGilovBiHP1yjXt_wAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-04 02:15:44
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 00:49:57
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 20:49:52.811337 2026] [security2:error] [pid 15905:tid 15905] [client 35.200.137.92:52052] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lightupaustralia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lightupaustralia.com"] [uri "/wp-json/wp/v2/users/5"] [unique_id "akhYsABRfrfCLcJeldn2IwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-04 00:30:31
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 20:30:26.974808 2026] [security2:error] [pid 14502:tid 14502] [client 35.200.137.92:47208] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||femmefire.vanemby.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "femmefire.vanemby.com"] [uri "/wp-json/wp/v2/users/10"] [unique_id "akhUImQ1zyhfiAcT98gMugAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 21:53:43
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 17:53:39.148553 2026] [security2:error] [pid 12784:tid 12784] [client 35.200.137.92:59778] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||partners.imagineyourphotos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "partners.imagineyourphotos.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akgvYy2RUEQ3hxAlemUWKAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 19:36:07
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 35.200.137.92 (server1.wachost.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 15:36:00.046287 2026] [security2:error] [pid 22705:tid 22705] [client 35.200.137.92:45020] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "michelehoop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akgPINrDvgtyAMXKuZvuIAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-03 14:13:25
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ซ๐ฎ
JimArchon72
2026-07-02 22:35:01
(3 weeks ago)
2026/07/02 22:30:13 "GET /wp-login.php HTTP/2.0"
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-07-02 22:03:54
(3 weeks ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ฒ๐น
Malta
2026-07-02 00:30:21
(3 weeks ago)
35.200.137.92 - - [02/Jul/2026:02:30:21 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh ...
show more
35.200.137.92 - - [02/Jul/2026:02:30:21 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force