π©πͺ
FeG Deutschland
2026-07-24 04:44:46
(20 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
πΊπΈ
lostswordfish.com
2026-07-23 17:18:04
(1 day ago)
Wordfence waf block on a4ccivi1
Web App Attack
πΊπΈ
cwytech
2026-07-23 03:21:09
(1 day ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
ππΊ
bcsaba
2026-07-23 00:37:56
(2 days ago)
CMS (WordPress or Joomla) login attempt.
52.151.213.169 - - [23/Jul/2026:02:37:52 +0200] "POST /wp-l ...
show more
CMS (WordPress or Joomla) login attempt.
52.151.213.169 - - [23/Jul/2026:02:37:52 +0200] "POST /wp-login.php HTTP/2.0" 200 3203 "https://*REDACTED*.*REDACTED*/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack
π©πͺ
FeG Deutschland
2026-07-22 18:10:16
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
π©πͺ
london2038.com
2026-07-06 22:32:46
(2 weeks ago)
Attacking WordPress
52.151.213.169 - - [07/Jul/2026:00:32:42 +0200] "POST /wp-login.php HTTP/2.0" 50 ...
show more
Attacking WordPress
52.151.213.169 - - [07/Jul/2026:00:32:42 +0200] "POST /wp-login.php HTTP/2.0" 503 19289 "https://<REDACTED>/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
show less
Brute-Force
Web App Attack
πΊπΈ
wordpresshosting.solutions
2026-07-06 14:02:37
(2 weeks ago)
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 52.151.213.169 - - [06/Jul/2026 ...
show more
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 52.151.213.169 - - [06/Jul/2026:14:02:35 +0000] "GET /wp-login.php HTTP/1.1" 200 6708 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
52.151.213.169 - - [06/Jul/2026:14:02:36 +0000] "POST /wp-login.php HTTP/1.1" 503 20484 "https://[DOMAIN]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-04 23:00:47
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 52.151.213.169 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 52.151.213.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 19:00:39.702052 2026] [security2:error] [pid 28340:tid 28340] [client 52.151.213.169:2456] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rocksolidhomebuilders.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rocksolidhomebuilders.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "akmQlyTY-nS7kQzqiH_CAQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-04 20:25:00
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 52.151.213.169 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 52.151.213.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 16:24:53.606776 2026] [security2:error] [pid 27822:tid 27822] [client 52.151.213.169:2985] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mrccertification.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mrccertification.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aklsFd9O1hwJ1kJ4X_vAXQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-07-04 15:01:16
(2 weeks ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 52.151.213.169 (US/United States/-): 1 in the ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 52.151.213.169 (US/United States/-): 1 in the last 3600 secs (0-195)
show less
Hacking
π©πͺ
FeG Deutschland
2026-07-04 09:21:33
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-04 06:10:17
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 52.151.213.169 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 52.151.213.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 04 02:10:14.023635 2026] [security2:error] [pid 8292:tid 8292] [client 52.151.213.169:7564] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||circleinthesquare.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "circleinthesquare.org"] [uri "/wp-json/wp/v2/users"] [unique_id "akijxjaKLr4dUticxWJT_gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Mundo Bueno
2026-07-04 02:41:38
(2 weeks ago)
[ISILIA Protection v2.1] Tentative d'accès: /wp-json/wp/v2/users | Pays: US | UA: Mozilla/5.0 (Windo ...
show more
[ISILIA Protection v2.1] Tentative d'accès: /wp-json/wp/v2/users | Pays: US | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Sa
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-04 00:19:04
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 52.151.213.169 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 52.151.213.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 20:18:56.998918 2026] [security2:error] [pid 32470:tid 32470] [client 52.151.213.169:2026] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cycontechnology.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cycontechnology.com"] [uri "/wp-json/wp/v2/users"] [unique_id "akhRcN68tIhY1uQk3aR7agAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-03 16:28:57
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 52.151.213.169 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 52.151.213.169 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 12:28:50.773671 2026] [security2:error] [pid 19907:tid 19907] [client 52.151.213.169:7570] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||zoesaadeh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "zoesaadeh.com"] [uri "/wp-json/wp/v2/users/10"] [unique_id "akfjQsUjVag5FmD_aW9LDAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack