🇬🇧
spamverify.com
2026-09-08 16:54:19
(40 minutes ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:33:14
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz ...
show more
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:33:08.180001 2026] [security2:error] [pid 21447:tid 21447] [client 47.72.224.157:45596] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||constructionloansfunding.internetnameregistration.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "constructionloansfunding.internetnameregistration.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqA4xLjRUMO6zfytcgxAHAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:37:17
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz ...
show more
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:37:11.765041 2026] [security2:error] [pid 1278:tid 1278] [client 47.72.224.157:48406] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||splashstation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "splashstation.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqArp_qJV0FM3U3CFyrtMgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:00:22
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz ...
show more
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:00:14.645288 2026] [security2:error] [pid 25533:tid 25533] [client 47.72.224.157:34286] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "humbliaslaw.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAi_gofpWnGiPEi-2tnSwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:35:48
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz ...
show more
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:35:43.043038 2026] [security2:error] [pid 14572:tid 14572] [client 47.72.224.157:35662] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||georgegourmet.visionremota.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "georgegourmet.visionremota.info"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAdP-k3DHJO7ePE2I-OjwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
QT
2026-09-08 13:47:21
(3 hours ago)
Unauthorised WordPress admin login attempted at 2026-09-08 23:47:14 +1000
Web App Attack
🇩🇪
Lino Project
2026-09-08 12:04:47
(5 hours ago)
47.72.224.157 - - [08/Sep/2026:14:04:44 +0200] "GET /wp-login.php HTTP/2.0" 403 282 "-" "Mozilla/5.0 ...
show more
47.72.224.157 - - [08/Sep/2026:14:04:44 +0200] "GET /wp-login.php HTTP/2.0" 403 282 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:04:23
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz ...
show more
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:04:16.433180 2026] [security2:error] [pid 3076:tid 3076] [client 47.72.224.157:43744] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||expresstires.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "expresstires.us"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_5wKGwnxhbLUkf1VkSIAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-08 10:58:41
(6 hours ago)
(wordpress) Failed wordpress login from 47.72.224.157 (NZ/New Zealand/Auckland/Auckland/47-72-224-15 ...
show more
(wordpress) Failed wordpress login from 47.72.224.157 (NZ/New Zealand/Auckland/Auckland/47-72-224-157.dsl.dyn.ihug.co.nz/[redacted]): (CF_ENABLE)
show less
Brute-Force
🇺🇸
Starburst SysOp Team
2026-09-08 10:30:04
(7 hours ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 157.224.72.47.rbl.malwa ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 157.224.72.47.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-mnz6-3)
show less
Hacking
🇺🇸
dtorrer
2026-09-08 10:29:41
(7 hours ago)
Forged login request.
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 10:07:33
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz ...
show more
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:07:28.127739 2026] [security2:error] [pid 27961:tid 27961] [client 47.72.224.157:56058] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.major33.com.cruanyes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.major33.com.cruanyes.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_eYCXOe2T1amXDzGixkgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇹
Malta
2026-09-08 09:16:10
(8 hours ago)
47.72.224.157 - - [08/Sep/2026:11:16:10 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
47.72.224.157 - - [08/Sep/2026:11:16:10 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 09:07:32
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz ...
show more
(mod_security) mod_security (id:225170) triggered by 47.72.224.157 (47-72-224-157.dsl.dyn.ihug.co.nz): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:07:23.146510 2026] [security2:error] [pid 735:tid 735] [client 47.72.224.157:39284] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||morninginc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "morninginc.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_QSzEv57Pa7xsbK4tfHgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 08:52:00
(8 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack