🇫🇷
tecnicorioja
2026-09-09 22:00:55
(13 minutes ago)
wp-login attack [09/Sep/2026:17:37:53
Brute-Force
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-09 13:16:51
(8 hours ago)
WordPress login attempt
Brute-Force
🇬🇷
setupgr
2026-09-09 09:56:42
(12 hours ago)
(wplogin_block) Blocked WP-Login Access Attempt 46.11.210.91 (MT/Malta/Tas-Sliema/Sliema/-/[AS15735 ...
show more
(wplogin_block) Blocked WP-Login Access Attempt 46.11.210.91 (MT/Malta/Tas-Sliema/Sliema/-/[AS15735 GO p.l.c.]): 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 46.11.210.91 - - [09/Sep/2026:12:54:23 +0300] "GET /wp-login.php HTTP/2.0" 200 - "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Safari/537.36"
show less
Port Scan
🇫🇮
JimArchon72
2026-09-09 06:55:01
(15 hours ago)
2026/09/09 06:54:57 "GET /wp-login.php HTTP/2.0"
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 06:49:49
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:49:45.700531 2026] [security2:error] [pid 5064:tid 5064] [client 46.11.210.91:45024] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.toepferlab.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.toepferlab.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqEBiQBEJeDNfaCqgyBnxAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 05:50:50
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:50:45.960871 2026] [security2:error] [pid 6937:tid 6937] [client 46.11.210.91:56242] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wc2023.renju.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wc2023.renju.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDztfmBLog2a0BUZn3kSgAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:56:46
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:56:39.675905 2026] [security2:error] [pid 20865:tid 20869] [client 46.11.210.91:35826] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||streamriders.com.hdtv55.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "streamriders.com.hdtv55.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDnB7LURJB02KcPz3tzvwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇽
octageeks.com
2026-09-09 04:06:38
(18 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:02:35
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:02:30.323418 2026] [security2:error] [pid 19741:tid 19741] [client 46.11.210.91:56096] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||naturalacu.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "naturalacu.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDaVmUWrkn-yHUWER6sjgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:21:53
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:21:47.228750 2026] [security2:error] [pid 16252:tid 16252] [client 46.11.210.91:44594] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lenorasflowers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lenorasflowers.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDQy43_xus1vJVDLC499QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:35:04
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:34:58.689257 2026] [security2:error] [pid 32192:tid 32192] [client 46.11.210.91:51290] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||llew.life.78cardsofthetarot-tarotmancy-tarot-cards-and-tarot-readings.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "llew.life.78cardsofthetarot-tarotmancy-tarot-cards-and-tarot-readings.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDF0ngm1vqwVCeWSPuCxAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:03:55
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:03:50.796849 2026] [security2:error] [pid 19533:tid 19533] [client 46.11.210.91:41138] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||puckerbuttbikinis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "puckerbuttbikinis.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC-hhfK8Q_txHrKpDrBkgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:44:54
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 46.11.210.91 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:44:50.973065 2026] [security2:error] [pid 28757:tid 28757] [client 46.11.210.91:50614] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||brexitop.bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "brexitop.bamedica.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCsAp7gGLLoFGf3Ou0mVgAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 23:43:03
(22 hours ago)
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/2.0, GET / HTTP/2.0, GET /wp-login.p ...
show more
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/2.0, GET / HTTP/2.0, GET /wp-login.php HTTP/2.0, GET /not_found HTTP/2.0, [6/6] done
show less
Hacking
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 23:18:19
(22 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack