🇩🇪
ger-stg-sifi1
2026-09-11 06:02:00
(23 minutes ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇲🇽
octageeks.com
2026-09-11 04:06:26
(2 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇩🇪
LRob
2026-09-11 02:04:55
(4 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /rss/ | 2026-09-11 02:04 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 01:31:18
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.11.7.197 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 46.11.7.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 21:31:10.688961 2026] [security2:error] [pid 379:tid 379] [client 46.11.7.197:42582] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||premierveterinarysurgery.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "premierveterinarysurgery.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqNZ3vroygY6jzHQLkIbBAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 18:42:25
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.11.7.197 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 46.11.7.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 14:42:17.630568 2026] [security2:error] [pid 26701:tid 26701] [client 46.11.7.197:57534] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||christineaholtz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "christineaholtz.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqL6Cey15Mj3kcjhPAJgZwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 10:11:26
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.11.7.197 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:225170) triggered by 46.11.7.197 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 06:11:21.083719 2026] [security2:error] [pid 25369:tid 25369] [client 46.11.7.197:52002] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||investorsfundingusa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "investorsfundingusa.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqKCSUgJYNzk7Au2lH0l5QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-10 02:29:35
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇮🇹
CoreTech srl
2026-09-09 23:54:00
(1 day ago)
cloudlinux2 fail2ban: 2026-09-10 01:49:27,758 fail2ban.filter [1892]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-10 01:49:27,758 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 103.80.12.165 - 2026-09-10 01:49:27cloudlinux2 fail2ban: 2026-09-10 01:49:56,569 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 23.94.155.32 - 2026-09-10 01:49:55cloudlinux2 fail2ban: 2026-09-10 01:50:42,692 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Ban 103.80.12.165cloudlinux2 fail2ban: 2026-09-10 01:50:42,161 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 103.80.12.165 - 2026-09-10 01:50:42cloudlinux2 fail2ban: 2026-09-10 01:50:42,873 fail2ban.filter [1892]: INFO [recidive] Found 103.80.12.165 - 2026-09-10 01:50:42cloudlinux2 fail2ban: 2026-09-10 01:51:58,212 fail2ban.filter [1892]: INFO [plesk-wordpress] Found 142.111.152.182 - 2026-09-10 01:51:57cloudlinux2 fail2ban: 2026-09-10 01:52:17,790 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 8.234.156.216 - 2026-09-10 01:52:17cloudlinux2 fail2ban: 2026-09-1
show less
Web App Attack
🇫🇷
ELYAZ
2026-09-09 23:16:33
(1 day ago)
(wordpress) Failed wordpress login from 46.11.7.197 (MT/Malta/-): (CF_ENABLE)
Brute-Force
🇩🇪
Lino Project
2026-09-09 20:53:40
(1 day ago)
46.11.7.197 - - [09/Sep/2026:22:53:39 +0200] "GET /wp-login.php HTTP/2.0" 403 282 "-" "Mozilla/5.0 ( ...
show more
46.11.7.197 - - [09/Sep/2026:22:53:39 +0200] "GET /wp-login.php HTTP/2.0" 403 282 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
netclix.gr
2026-09-09 17:07:18
(1 day ago)
(wordpress) Failed wordpress login from 46.11.7.197 (MT/Malta/-): (CF_ENABLE)
Brute-Force
🇺🇸
nationaleventpros.com
2026-09-09 16:45:35
(1 day ago)
WordPress login attempt
Brute-Force