🇺🇸
TPI-Abuse
2026-09-09 05:36:53
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:36:46.000246 2026] [security2:error] [pid 31092:tid 31092] [client 46.126.29.155:42501] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||xcarsubscription.com.bamedica.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "xcarsubscription.com.bamedica.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDwbeRLb2BpL0nVfe2ImAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-09 05:06:43
(9 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-login.php | 2026-09-09 05:0 ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-login.php | 2026-09-09 05:06 UTC
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:57:46
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:57:40.946975 2026] [security2:error] [pid 4965:tid 4965] [client 46.126.29.155:46292] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||japanesejapan.info.smogsandiego.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "japanesejapan.info.smogsandiego.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDnRNkHiQjwXY6Vg0AYLgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-09 03:58:29
(11 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-09 02:25:04
(12 hours ago)
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/2.0, GET /wp-login.php HTTP/2.0, [2/ ...
show more
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/2.0, GET /wp-login.php HTTP/2.0, [2/2] done
show less
Hacking
Web App Attack
🇩🇪
F242
2026-09-09 00:26:30
(14 hours ago)
Wordpress Login or XMLRPC abuse
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:28:10
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:28:04.547742 2026] [security2:error] [pid 2142:tid 2142] [client 46.126.29.155:39168] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||oruhu.org.circulodesonido.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "oruhu.org.circulodesonido.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCaBP-NSgv6gZqQbIpOKAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:50:12
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:50:07.684644 2026] [security2:error] [pid 16581:tid 16581] [client 46.126.29.155:39514] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||whodatnation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "whodatnation.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCRH-8l8onRTQkrRHB3nQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 21:09:46
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:09:38.368343 2026] [security2:error] [pid 6983:tid 6983] [client 46.126.29.155:45363] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geckoturner.chezlubacov.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geckoturner.chezlubacov.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqB5kkuNUf4p9Uq7aI5mkAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 20:45:11
(18 hours ago)
Web attack blocked by Wordfence on limburgsekunstkring.nl (1 hit). Reported by CRMON.
Web App Attack
🇫🇷
ELYAZ
2026-09-08 20:15:29
(18 hours ago)
(wordpress) Failed wordpress login from 46.126.29.155 (CH/Switzerland/46-126-29-155.dynamic.hispeed. ...
show more
(wordpress) Failed wordpress login from 46.126.29.155 (CH/Switzerland/46-126-29-155.dynamic.hispeed.ch): (CF_ENABLE)
show less
Brute-Force
Anonymous
2026-09-08 20:01:48
(19 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 19:38:10
(19 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:17:29
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 46.126.29.155 (46-126-29-155.dynamic.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:17:22.153078 2026] [security2:error] [pid 32702:tid 32705] [client 46.126.29.155:45524] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||leaderoftheopposition.aafm.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "leaderoftheopposition.aafm.us"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqA1Erko9nTiG42FJdkNEgAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-08 16:10:49
(22 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack