Anonymous
2026-09-01 05:46:23
(8 hours ago)
Failed Wordpress Logins
Web App Attack
๐บ๐ธ
cwytech
2026-08-31 15:46:55
(22 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/tpot-web-high.
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 12:43:18
(1 day ago)
PSCSERV WPSCAN 37.60.255.145
Bad Web Bot
Web App Attack
๐ฌ๐ง
SilverZippo
2026-08-31 11:32:11
(1 day ago)
Web App Attack
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-08-31 10:41:17
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 10:15:30
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 37.60.255.145 (vmd182736.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 37.60.255.145 (vmd182736.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 06:15:24.583461 2026] [security2:error] [pid 3720718:tid 3720738] [client 37.60.255.145:35160] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kettlehill.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apVUPMwcvWxEfdoqgMGkZQAAAJI"], referer: http://kettlehill.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
on-com
2026-08-31 10:15:12
(1 day ago)
URL scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 09:42:01
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 37.60.255.145 (vmd182736.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 37.60.255.145 (vmd182736.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:41:54.678401 2026] [security2:error] [pid 29753:tid 29753] [client 37.60.255.145:42950] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||limeroc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "limeroc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apVMYprXXSZFYkm8CWDWjgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ph
2026-08-31 09:24:14
(1 day ago)
Bad web bot attempting to run wp-login.php on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-08-31 09:07:48
(1 day ago)
37.60.255.145 - - [31/Aug/2026:03:07:47 -0600] "GET /wp-login.php HTTP/1.1" 301 487 "" "Mozilla/5.0 ...
show more
37.60.255.145 - - [31/Aug/2026:03:07:47 -0600] "GET /wp-login.php HTTP/1.1" 301 487 "" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
...
show less
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-08-31 09:07:21
(1 day ago)
Wordpress hacking attempt
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-31 09:05:38
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-31 08:33:57
(1 day ago)
cloudlinux2 fail2ban: 2026-08-31 10:29:15,253 fail2ban.actions [1605]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-31 10:29:15,253 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 103.13.43.3cloudlinux2 fail2ban: 2026-08-31 10:29:15,888 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 216.252.238.251 - 2026-08-31 10:29:15cloudlinux2 fail2ban: 2026-08-31 10:29:35,289 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Unban 35.246.168.6cloudlinux2 fail2ban: 2026-08-31 10:29:57,573 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 27.130.199.53 - 2026-08-31 10:29:57cloudlinux2 fail2ban: 2026-08-31 10:30:06,696 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 175.101.143.54 - 2026-08-31 10:30:06cloudlinux2 fail2ban: 2026-08-31 10:30:16,747 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 175.101.143.54 - 2026-08-31 10:30:16cloudlinux2 fail2ban: 2026-08-31 10:31:11,056 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 27.130.199.53 - 2026-08-31 10:31:11cloudlinux2 fail2ban: 2026-08-31 10:31:1
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 06:59:19
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 37.60.255.145 (vmd182736.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 37.60.255.145 (vmd182736.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 02:59:14.733676 2026] [security2:error] [pid 23103:tid 23103] [client 37.60.255.145:43088] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tedharris.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tedharris.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apUmQngHF3DG08LMeryxAgAAAAw"], referer: http://tedharris.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 06:37:11
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 37.60.255.145 (vmd182736.contaboserver.net): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 37.60.255.145 (vmd182736.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 02:37:06.435771 2026] [security2:error] [pid 6004:tid 6004] [client 37.60.255.145:33204] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||talentstar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "talentstar.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apUhElGoFJw_BOm4DPyFFAAAABE"], referer: http://talentstar.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack