🇺🇸
nationaleventpros.com
2026-09-19 07:57:40
(1 hour ago)
WordPress login attempt
Brute-Force
🇩🇪
ger-stg-sifi1
2026-09-18 19:34:34
(13 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇬🇧
spamverify.com
2026-09-18 04:15:38
(1 day ago)
Honeypot Hit: xmlrpc.php
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
🇪🇸
masterguru
2026-09-15 02:44:30
(4 days ago)
*Port Scan* detected from 42.60.187.121 (SG/Singapore/bb42.60-187-121.singnet.com.sg). 11 hits in th ...
show more
*Port Scan* detected from 42.60.187.121 (SG/Singapore/bb42.60-187-121.singnet.com.sg). 11 hits in the last 171 seconds (0-122)
show less
Port Scan
🇩🇪
FeG Deutschland
2026-09-12 15:17:50
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇲🇽
octageeks.com
2026-09-12 04:24:10
(1 week ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇺🇸
lostswordfish.com
2026-09-11 18:14:04
(1 week ago)
Wordfence waf block on pameganslaw
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 14:35:43
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 42.60.187.121 (bb42.60-187-121.singnet.com.sg): ...
show more
(mod_security) mod_security (id:225170) triggered by 42.60.187.121 (bb42.60-187-121.singnet.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 10:35:38.067249 2026] [security2:error] [pid 15309:tid 15309] [client 42.60.187.121:38000] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fatbastardcompetition.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fatbastardcompetition.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqQRunlhaplAJvMW6IfSVAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇽
octageeks.com
2026-09-10 04:16:09
(1 week ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇩🇪
LRob
2026-09-09 06:38:57
(1 week ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-login.php | 2026-09-09 06:3 ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-login.php | 2026-09-09 06:38 UTC
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:35:27
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 42.60.187.121 (bb42.60-187-121.singnet.com.sg): ...
show more
(mod_security) mod_security (id:225170) triggered by 42.60.187.121 (bb42.60-187-121.singnet.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:35:23.430728 2026] [security2:error] [pid 16715:tid 16715] [client 42.60.187.121:51182] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.webseographics.smogsandiego.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.webseographics.smogsandiego.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDwG9WZfppc9MYoC3UysgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:18:22
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 42.60.187.121 (bb42.60-187-121.singnet.com.sg): ...
show more
(mod_security) mod_security (id:225170) triggered by 42.60.187.121 (bb42.60-187-121.singnet.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:18:16.398508 2026] [security2:error] [pid 5073:tid 5073] [client 42.60.187.121:52830] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mainefirst.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mainefirst.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDsGN99Py_-e9PUG5kIJQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:31:04
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 42.60.187.121 (bb42.60-187-121.singnet.com.sg): ...
show more
(mod_security) mod_security (id:225170) triggered by 42.60.187.121 (bb42.60-187-121.singnet.com.sg): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:30:56.442651 2026] [security2:error] [pid 7914:tid 7948] [client 42.60.187.121:43978] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||maroontribe.philacentric.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "maroontribe.philacentric.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDhALfT04HDEc2PtozalgAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-09 03:33:15
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇩🇪
AlexEventfahrtenIPDB
2026-09-09 03:25:55
(1 week ago)
[Wed Sep 09 05:25:53.818960 2026] [authz_core:error] [pid 526603:tid 526667] [remote 42.60.187.121:5 ...
show more
[Wed Sep 09 05:25:53.818960 2026] [authz_core:error] [pid 526603:tid 526667] [remote 42.60.187.121:55874] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/wp-login.php
[Wed Sep 09 05:25:54.616312 2026] [authz_core:error] [pid 526603:tid 526671] [remote 42.60.187.121:55874] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/wp-login.php
...
show less
Brute-Force
Web App Attack