🇲🇽
octageeks.com
2026-08-30 04:13:07
(12 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇺🇸
1cyb3rpunk
2026-08-29 21:50:59
(18 hours ago)
Coordinated campaign CMP-1786835248-000: 249 IPs sharing an attack fingerprint (admin_panel_probe, a ...
show more
Coordinated campaign CMP-1786835248-000: 249 IPs sharing an attack fingerprint (admin_panel_probe, attacker_objective_inferred, aws_creds_file_probe, bad_request_probe, ci_cd_config_leak, cicd_artifact_probe). Observed on sectrace.org honeypot surface.
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 10:41:21
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 06:41:17.250175 2026] [security2:error] [pid 20325:tid 20325] [client 66.29.148.11:53224] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||takeapawsboston.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "takeapawsboston.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apK3TcnJcJD-CHmkEnzh3gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 09:27:59
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 05:27:51.701754 2026] [security2:error] [pid 25274:tid 25274] [client 66.29.148.11:45078] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ubuciko.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ubuciko.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apKmF3-8A0IcaGpKx0gE2QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 08:39:47
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 04:39:40.912617 2026] [security2:error] [pid 28893:tid 28893] [client 66.29.148.11:43692] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||calvarycavaliers.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "calvarycavaliers.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apKazIV84B8iyD28moisYwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 06:55:50
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:55:42.461267 2026] [security2:error] [pid 32247:tid 32247] [client 66.29.148.11:52558] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||azcrittergetter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "azcrittergetter.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apKCboosn070lVeMaZ02KgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
SpaceHost-Server
2026-08-29 01:46:55
(1 day ago)
66.29.148.11 - - [29/Aug/2026:03:46:54 +0200] "POST /wp-login.php HTTP/1.1" 200 15983 "https://hans. ...
show more
66.29.148.11 - - [29/Aug/2026:03:46:54 +0200] "POST /wp-login.php HTTP/1.1" 200 15983 "https://hans.wp-knowhow.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
66.29.148.11 - - [29/Aug/2026:03:46:54 +0200] "POST /wp-login.php HTTP/1.1" 200 15985 "https://hans.wp-knowhow.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
66.29.148.11 - - [29/Aug/2026:03:46:54 +0200] "POST /wp-login.php HTTP/1.1" 200 15979 "https://hans.wp-knowhow.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 01:33:29
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:33:24.649137 2026] [security2:error] [pid 2738:tid 2738] [client 66.29.148.11:58068] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||magazine.angelabcomics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "magazine.angelabcomics.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apI25EpKzjbWJLTi4n5SUwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dbmwebdesign
2026-08-29 01:05:05
(1 day ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 23:56:11
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:56:05.948197 2026] [security2:error] [pid 17506:tid 17506] [client 66.29.148.11:56756] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tonydelov.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tonydelov.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apIgFcVjZtBp865opKx_2gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-08-28 23:39:13
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇬🇧
Apache
2026-08-28 23:35:41
(1 day ago)
(wplogin) WordPress login brute-force 66.29.148.11 (US/United States/server4.shared.spaceship.host): ...
show more
(wplogin) WordPress login brute-force 66.29.148.11 (US/United States/server4.shared.spaceship.host): 5 in the last 300 secs
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-08-28 23:35:08
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.11 (server4.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 19:34:58.274591 2026] [security2:error] [pid 24151:tid 24151] [client 66.29.148.11:57344] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||talentstar2025.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "talentstar2025.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apIbIptkJvlMbatJBAriIwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
1cyb3rpunk
2026-08-28 22:46:12
(1 day ago)
Coordinated campaign CMP-1786835248-000: 188 IPs sharing an attack fingerprint (admin_panel_probe, a ...
show more
Coordinated campaign CMP-1786835248-000: 188 IPs sharing an attack fingerprint (admin_panel_probe, attacker_objective_inferred, aws_creds_file_probe, ci_cd_config_leak, cicd_artifact_probe, cloud_config_probe). Observed on sectrace.org honeypot surface.
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-08-28 22:02:49
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH