๐ฒ๐ฝ
octageeks.com
2026-08-29 04:40:01
(3 days ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ง๐ช
taivas.nl
2026-08-29 04:33:16
(3 days ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 18:05:18
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 52.62.214.81 (ec2-52-62-214-81.ap-southeast-2.c ...
show more
(mod_security) mod_security (id:225170) triggered by 52.62.214.81 (ec2-52-62-214-81.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 14:05:09.056354 2026] [security2:error] [pid 3833:tid 3833] [client 52.62.214.81:48554] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sharonmauldin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sharonmauldin.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apHN1NkW-mFFo9ZgzMZoLAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 18:01:00
(4 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
integrantservices.com
2026-08-28 17:51:15
(4 days ago)
(wordpress) Failed wordpress login from 52.62.214.81 (AU/Australia/ec2-52-62-214-81.ap-southeast-2.c ...
show more
(wordpress) Failed wordpress login from 52.62.214.81 (AU/Australia/ec2-52-62-214-81.ap-southeast-2.compute.amazonaws.com)
show less
Brute-Force
Anonymous
2026-08-28 17:39:03
(4 days ago)
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/2.0
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 17:33:21
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 52.62.214.81 (ec2-52-62-214-81.ap-southeast-2.c ...
show more
(mod_security) mod_security (id:225170) triggered by 52.62.214.81 (ec2-52-62-214-81.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 13:33:17.298512 2026] [security2:error] [pid 22601:tid 22601] [client 52.62.214.81:38440] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||guldunyayayinlari.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "guldunyayayinlari.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apHGXTVhvnnwGcnyE1jyrgAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2026-08-28 17:29:56
(4 days ago)
(XMLRPC) WP XMLPRC Attack 52.62.214.81 (AU/Australia/ec2-52-62-214-81.ap-southeast-2.compute.amazona ...
show more
(XMLRPC) WP XMLPRC Attack 52.62.214.81 (AU/Australia/ec2-52-62-214-81.ap-southeast-2.compute.amazonaws.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 52.62.214.81 - - [28/Aug/2026:20:29:52 +0300] "POST /xmlrpc.php HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Port Scan
๐ฉ๐ช
Hazzard
2026-08-28 17:25:36
(4 days ago)
(wordpress) Failed wordpress login from 52.62.214.81 (AU/Australia/New South Wales/Sydney/ec2-52-62- ...
show more
(wordpress) Failed wordpress login from 52.62.214.81 (AU/Australia/New South Wales/Sydney/ec2-52-62-214-81.ap-southeast-2.compute.amazonaws.com/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
cwytech
2026-08-28 17:16:57
(4 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
๐จ๐ฟ
plzenskypruvodce.cz
2026-08-28 17:16:42
(4 days ago)
2026-08-28T19:16:41.452047+02:00 web wordpress(upzcr.cz)[743967]: Authentication failure for markovi ...
show more
2026-08-28T19:16:41.452047+02:00 web wordpress(upzcr.cz)[743967]: Authentication failure for markovicova from 52.62.214.81
2026-08-28T19:16:41.484101+02:00 web wordpress(upzcr.cz)[743988]: Authentication failure for michela from 52.62.214.81
2026-08-28T19:16:41.612124+02:00 web wordpress(upzcr.cz)[743953]: Authentication failure for buchtic from 52.62.214.81
...
show less
Brute-Force
๐ฉ๐ช
ger-stg-sifi1
2026-08-28 17:01:41
(4 days ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 16:57:18
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 52.62.214.81 (ec2-52-62-214-81.ap-southeast-2.c ...
show more
(mod_security) mod_security (id:225170) triggered by 52.62.214.81 (ec2-52-62-214-81.ap-southeast-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:57:11.846292 2026] [security2:error] [pid 20859:tid 20859] [client 52.62.214.81:59476] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||agkgt.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "agkgt.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apG95x4UDyl4xnZmzCVztwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-28 16:48:56
(4 days ago)
cloudlinux2 fail2ban: 2026-08-28 18:43:56,793 fail2ban.filter [1478]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-28 18:43:56,793 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 212.227.154.251 - 2026-08-28 18:43:56cloudlinux2 fail2ban: 2026-08-28 18:44:05,429 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 39.34.166.61 - 2026-08-28 18:44:05cloudlinux2 fail2ban: 2026-08-28 18:44:02,713 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 188.166.239.157 - 2026-08-28 18:44:02cloudlinux2 fail2ban: 2026-08-28 18:44:39,081 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 212.227.154.251 - 2026-08-28 18:44:39cloudlinux2 fail2ban: 2026-08-28 18:44:39,406 fail2ban.filter [1478]: INFO [recidive] Found 212.227.154.251 - 2026-08-28 18:44:39cloudlinux2 fail2ban: 2026-08-28 18:44:39,400 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Ban 212.227.154.251cloudlinux2 fail2ban: 2026-08-28 18:44:56,134 fail2ban.filter [1478]: INFO [plesk-modsecurity] Found 52.62.214.81 - 2026-08-28 18:44:56cloudlinux2 fail2ban
show less
Brute-Force
๐บ๐ธ
xxkodedxx
2026-08-28 16:47:16
(4 days ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
Origin: AU / AS16509 Amazon.com, Inc.
Active: 16:47:03โ16:47:05 UTC
Volume: 1 HTTP req, 1 honeypot probe(s)
Bait taken: /wp-json/oembed/1.0/embed?url=https%3A%2F%2Fzvxlabs.com&format=json
Status mix: 200ร1
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack