๐ฉ๐ช
juutis
2026-06-30 16:11:37
(21 minutes ago)
Multiple WAF abuses - IP blocked
Hacking
Brute-Force
Web App Attack
๐ซ๐ท
ELYAZ
2026-06-30 16:03:44
(29 minutes ago)
(y4) Failed scan -byebye- from 52.44.250.30 (US/United States/ec2-52-44-250-30.compute-1.amazonaws.c ...
show more
(y4) Failed scan -byebye- from 52.44.250.30 (US/United States/ec2-52-44-250-30.compute-1.amazonaws.com): (CF_ENABLE)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-30 16:01:19
(31 minutes ago)
(mod_security) mod_security (id:225170) triggered by 52.44.250.30 (ec2-52-44-250-30.compute-1.amazon ...
show more
(mod_security) mod_security (id:225170) triggered by 52.44.250.30 (ec2-52-44-250-30.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 12:01:15.285830 2026] [security2:error] [pid 20475:tid 20475] [client 52.44.250.30:58128] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||soonerstone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "soonerstone.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "akPoS7FdNe3FHjzHfOSHSwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-06-30 15:59:46
(33 minutes ago)
WordPress bruteforce
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ซ๐ท
Yepngo
2026-06-30 15:41:23
(51 minutes ago)
52.44.250.30 - - [30/Jun/2026:17:41:23 +0200] "POST /wp-login.php HTTP/2.0" 200 11371 "https://blog. ...
show more
52.44.250.30 - - [30/Jun/2026:17:41:23 +0200] "POST /wp-login.php HTTP/2.0" 200 11371 "https://blog.yepngo.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 15:41:21
(51 minutes ago)
(mod_security) mod_security (id:225170) triggered by 52.44.250.30 (ec2-52-44-250-30.compute-1.amazon ...
show more
(mod_security) mod_security (id:225170) triggered by 52.44.250.30 (ec2-52-44-250-30.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 11:41:16.371636 2026] [security2:error] [pid 8037:tid 8037] [client 52.44.250.30:36216] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.investorsfundingusa.internetnameregistration.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.investorsfundingusa.internetnameregistration.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "akPjnLlSZkXAjphbU_D0ygAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-30 15:39:20
(53 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
cwytech
2026-06-30 15:35:56
(57 minutes ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-06-30 15:31:08
(1 hour ago)
WP Exploit attempt. Evidence: [REDACTED_DOMAIN]:443 52.44.250.30 - - [30/Jun/2026:16:31:00 +0100] PO ...
show more
WP Exploit attempt. Evidence: [REDACTED_DOMAIN]:443 52.44.250.30 - - [30/Jun/2026:16:31:00 +0100] POST /wp-login.php HTTP/2.0 200 3861 https://[REDACTED_DOMAIN]/wp-login.php Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15
show less
Web App Attack
Anonymous
2026-06-30 15:27:06
(1 hour ago)
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/2.0
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-06-30 15:20:26
(1 hour ago)
(wordpress) Apache: Failed WordPress login from 52.44.250.30 (US/United States/ec2-52-44-250-30.comp ...
show more
(wordpress) Apache: Failed WordPress login from 52.44.250.30 (US/United States/ec2-52-44-250-30.compute-1.amazonaws.com): 10 in the last 3600 secs (0-193)
show less
Hacking
๐ณ๐ฑ
ipoac.nl
2026-06-30 15:19:24
(1 hour ago)
2026-06-30T17:19:23.151058+02:00 ipoac.nl wordpress(-)-: Authentication failure for-from 52.44.250.3 ...
show more
2026-06-30T17:19:23.151058+02:00 ipoac.nl wordpress(-)-: Authentication failure for-from 52.44.250.30
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 15:11:31
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 52.44.250.30 (ec2-52-44-250-30.compute-1.amazon ...
show more
(mod_security) mod_security (id:225170) triggered by 52.44.250.30 (ec2-52-44-250-30.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 11:11:25.982597 2026] [security2:error] [pid 12176:tid 12184] [client 52.44.250.30:40298] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||danelandia.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "danelandia.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "akPcnSB_pBNQ0A92RBls1wAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
SCLwebadministrator
2026-06-30 14:46:00
(1 hour ago)
Bruteforce WordPress logins detected with Loginizer
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
nyt
2026-06-30 14:45:06
(1 hour ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack