Anonymous
2026-08-31 20:46:34
(1 day ago)
Failed Wordpress Logins
Web App Attack
๐ฎ๐ณ
evicky2002
2026-08-31 00:02:20
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฎ๐ณ
evicky2002
2026-08-31 00:01:03
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-08-30 11:46:21
(3 days ago)
Failed Wordpress Logins
Web App Attack
๐ฌ๐ง
spamverify.com
2026-08-29 13:03:35
(4 days ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 12:37:16
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 43.157.58.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 43.157.58.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 08:37:10.328470 2026] [security2:error] [pid 8409:tid 8409] [client 43.157.58.134:58822] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||asapstarsmogcheck.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "asapstarsmogcheck.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apLSdpGi0OB6r5peM6fjrAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-08-29 11:52:57
(4 days ago)
Honeypot triggered: /wp-json/wp/v2/posts on ifebridge.com. User-Agent: Mozilla/5.0 (Windows NT 10.0; ...
show more
Honeypot triggered: /wp-json/wp/v2/posts on ifebridge.com. User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36. Method: GET
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 11:41:03
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 43.157.58.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 43.157.58.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 07:40:57.278009 2026] [security2:error] [pid 32172:tid 32285] [client 43.157.58.134:53066] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ethicmark.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ethicmark.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apLFSQbImfQ5iYSxTir2VwAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 08:07:10
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 43.157.58.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 43.157.58.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:07:06.680391 2026] [security2:error] [pid 85711:tid 85829] [client 43.157.58.134:43996] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cjherbalremedies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cjherbalremedies.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apKTKkQvfVR31JRUvG6TYgAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 07:15:40
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 43.157.58.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 43.157.58.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 03:15:32.776848 2026] [security2:error] [pid 19979:tid 19979] [client 43.157.58.134:41352] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thingstodonude.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thingstodonude.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apKHFHvswLWR1HFnBqAFJwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-29 06:59:28
(4 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-29 06:59 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
4server
2026-08-29 06:56:44
(4 days ago)
[SatAug2908:56:41.8874682026][security2:error][pid3766287:tid3766309][client43.157.58.134:0]ModSecur ...
show more
[SatAug2908:56:41.8874682026][security2:error][pid3766287:tid3766309][client43.157.58.134:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"maxay.ch.136-243-54-122.cpanel.site\"][uri\"/xmlrpc.php\"][unique_id\"apKCqajg4HT7he2R0OP8xAAAAAs\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
ELYAZ
2026-08-29 05:30:38
(4 days ago)
(wordpress) Failed wordpress login from 43.157.58.134 (DE/Germany/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
mnsf
2026-08-29 05:05:06
(4 days ago)
Abuse Detected (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 04:41:23
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 43.157.58.134 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 43.157.58.134 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:41:18.181483 2026] [security2:error] [pid 31859:tid 31859] [client 43.157.58.134:55384] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grexicon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grexicon.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apJi7ugxBk7aj7psSMKlxQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack