Anonymous
2026-09-03 00:10:37
(1 week ago)
WordPress Brute Force
Hacking
Brute-Force
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-01 03:47:44
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
lostswordfish.com
2026-08-31 19:16:03
(1 week ago)
Wordfence waf block on decarcerationnation
Web App Attack
🇲🇹
Malta
2026-08-31 18:45:45
(1 week ago)
5.135.37.210 - - [31/Aug/2026:20:45:45 +0200] "POST /wp-login.php HTTP/1.1" "5.135.37.210"
Brute-for ...
show more
5.135.37.210 - - [31/Aug/2026:20:45:45 +0200] "POST /wp-login.php HTTP/1.1" "5.135.37.210"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇩🇪
AlexEventfahrtenIPDB
2026-08-31 18:24:54
(1 week ago)
[Mon Aug 31 20:24:53.610722 2026] [authz_core:error] [pid 1252346:tid 1252371] [remote 5.135.37.210: ...
show more
[Mon Aug 31 20:24:53.610722 2026] [authz_core:error] [pid 1252346:tid 1252371] [remote 5.135.37.210:54928] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php
[Mon Aug 31 20:24:53.878596 2026] [authz_core:error] [pid 1252346:tid 1252350] [remote 5.135.37.210:54930] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/wp-login.php
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 09:20:14
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 5.135.37.210 (gwc.cluster128.hosting.ovh.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 5.135.37.210 (gwc.cluster128.hosting.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:20:09.629599 2026] [security2:error] [pid 27540:tid 27540] [client 5.135.37.210:47430] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grabagame.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grabagame.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apVHScl2q5K-P3HTKjkJLgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
posicionarte.cl
2026-08-30 23:55:18
(2 weeks ago)
Intento fallido de inicio de sesión en WordPress
Brute-Force
🇩🇪
Hazzard
2026-08-30 22:20:46
(2 weeks ago)
(wordpress) Failed wordpress login from 5.135.37.210 (FR/France/-/-/gwc.cluster128.hosting.ovh.net/[ ...
show more
(wordpress) Failed wordpress login from 5.135.37.210 (FR/France/-/-/gwc.cluster128.hosting.ovh.net/[redacted]): (CF_ENABLE)
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-08-30 13:26:18
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 5.135.37.210 (gwc.cluster128.hosting.ovh.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 5.135.37.210 (gwc.cluster128.hosting.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 09:26:10.768135 2026] [security2:error] [pid 25093:tid 25093] [client 5.135.37.210:33036] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||radicalchange.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "radicalchange.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apQvcpjDhRhTZLfurIZCugAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 07:56:54
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 5.135.37.210 (gwc.cluster128.hosting.ovh.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 5.135.37.210 (gwc.cluster128.hosting.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 03:56:50.721845 2026] [security2:error] [pid 5105:tid 5105] [client 5.135.37.210:56976] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||caymancline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "caymancline.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apPiQm0rOVmZ1vpCkF4PqgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
tecnicorioja
2026-08-29 22:01:40
(2 weeks ago)
wp-login attack [29/Aug/2026:09:17:36
Brute-Force
Web App Attack
🇲🇹
Malta
2026-08-29 00:36:41
(2 weeks ago)
5.135.37.210 - - [29/Aug/2026:02:36:41 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
5.135.37.210 - - [29/Aug/2026:02:36:41 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-08-28 22:57:18
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 5.135.37.210 (gwc.cluster128.hosting.ovh.net): ...
show more
(mod_security) mod_security (id:225170) triggered by 5.135.37.210 (gwc.cluster128.hosting.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:57:10.347794 2026] [security2:error] [pid 12017:tid 12034] [client 5.135.37.210:39614] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cynosureinternetservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cynosureinternetservices.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apISRk0OYshBUKc-_X_fPwAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇹
Malta
2026-08-27 15:49:06
(2 weeks ago)
5.135.37.210 - - [27/Aug/2026:17:49:06 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
5.135.37.210 - - [27/Aug/2026:17:49:06 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
🇺🇸
craudiovizai
2026-08-27 06:33:14
(2 weeks ago)
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-login.php. Blocked ...
show more
Automated honeypot detection. honeypot against a Next.js application. Paths: /wp-login.php. Blocked at the edge.
show less
Web App Attack
Bad Web Bot