🇩🇪
LRob
2026-09-06 11:58:35
(22 hours ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-06 11:58 UTC
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 05:19:38
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 01:19:31.314085 2026] [security2:error] [pid 25817:tid 25817] [client 66.29.148.124:38846] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||uccryakima.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "uccryakima.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apz341GJ-_eO0Ts2FpYi1gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:29:54
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:29:48.122842 2026] [security2:error] [pid 16631:tid 16631] [client 66.29.148.124:49466] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||designingdestinynow.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "designingdestinynow.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apzQHJ4sO9uS6xx9Ciy0pwAAAHA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-06 02:29:40
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | 2026-09-06 02:29 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:14:38
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:14:27.871540 2026] [security2:error] [pid 16348:tid 16364] [client 66.29.148.124:54136] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||supercyprus.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "supercyprus.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apy-czIu3NXoDoPvqInxyAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:12:32
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:12:25.846257 2026] [security2:error] [pid 17094:tid 17094] [client 66.29.148.124:46552] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sandpointidaho.com.kh6jim.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sandpointidaho.com.kh6jim.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apyh2XpQ3rlxgdrPLFhvKwAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-05 21:09:26
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇲🇹
Malta
2026-09-05 19:10:48
(1 day ago)
66.29.148.124 - - [05/Sep/2026:21:10:48 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
66.29.148.124 - - [05/Sep/2026:21:10:48 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇩🇪
ger-stg-sifi1
2026-09-05 19:08:04
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 17:51:50
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 13:51:45.325281 2026] [security2:error] [pid 29062:tid 29062] [client 66.29.148.124:45966] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||glendaleheritage.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "glendaleheritage.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apxWscQIIPMUf6V_dMOsMAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 17:20:16
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 17:00:10
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.124 (server40.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 13:00:02.808123 2026] [security2:error] [pid 9802:tid 9802] [client 66.29.148.124:40280] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aifactoid.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aifactoid.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apxKkpVs6VfCmmLsEgBXzAAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-05 16:31:01
(1 day ago)
(wordpress) Failed wordpress login from 66.29.148.124 (US/United States/-/-/server40.shared.spaceshi ...
show more
(wordpress) Failed wordpress login from 66.29.148.124 (US/United States/-/-/server40.shared.spaceship.host/[redacted]): (CF_ENABLE)
show less
Brute-Force
🇫🇷
masterguru
2026-09-05 14:19:21
(1 day ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 66.29.148.124 (US/United States/server40.shar ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 66.29.148.124 (US/United States/server40.shared.spaceship.host): 1 in the last 3600 secs (0-196)
show less
Hacking
🇩🇪
karger
2026-09-05 12:56:28
(1 day ago)
Wordpress attack - soft filter
Brute-Force
Web App Attack