🇩🇪
neckaralb-admin.de
2026-09-05 23:33:09
(5 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
LRob
2026-09-05 23:05:21
(5 hours ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-05 23:05 UTC
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-09-05 23:03:56
(5 hours ago)
cloudlinux2 fail2ban: 2026-09-06 00:59:12,891 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-06 00:59:12,891 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 39.70.12.40 - 2026-09-06 00:59:12cloudlinux2 fail2ban: 2026-09-06 00:59:35,291 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 123.135.77.56 - 2026-09-06 00:59:35cloudlinux2 fail2ban: 2026-09-06 00:59:35,424 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 62.182.156.52cloudlinux2 fail2ban: 2026-09-06 00:59:56,061 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.88.32.131cloudlinux2 fail2ban: 2026-09-06 01:00:03,559 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 66.29.148.157 - 2026-09-06 01:00:03cloudlinux2 fail2ban: 2026-09-06 01:00:28,853 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 198.54.114.32 - 2026-09-06 01:00:28cloudlinux2 fail2ban: 2026-09-06 01:01:08,166 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.77.240.144cloudlinux2 fail2ban: 2026-09-06 01:01:09,382 fail2ban.actions
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:01:52
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.157 (server51.shared.spaceship.host): ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.157 (server51.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:01:47.866659 2026] [security2:error] [pid 17941:tid 17941] [client 66.29.148.157:43016] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thefrontporchoffering.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thefrontporchoffering.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apyfW_Buww0XnFHhjwHjPAAAAFw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:42:06
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.157 (server51.shared.spaceship.host): ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.157 (server51.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:42:01.216150 2026] [security2:error] [pid 4927:tid 4927] [client 66.29.148.157:34256] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rambleandprose.cyberclay.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rambleandprose.cyberclay.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apyMqf5_FD27ifI0v5K_pQAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-05 20:53:55
(7 hours ago)
cloudlinux2 fail2ban: 2026-09-05 22:48:52,572 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-05 22:48:52,572 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 117.253.128.227 - 2026-09-05 22:48:52cloudlinux2 fail2ban: 2026-09-05 22:48:54,841 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 117.253.128.227 - 2026-09-05 22:48:53cloudlinux2 fail2ban: 2026-09-05 22:49:03,301 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 211.248.235.67 - 2026-09-05 22:49:01cloudlinux2 fail2ban: 2026-09-05 22:48:59,804 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 211.248.235.67 - 2026-09-05 22:48:59cloudlinux2 fail2ban: 2026-09-05 22:49:07,927 fail2ban.filter [1594]: INFO [recidive] Found 211.248.235.67 - 2026-09-05 22:49:07cloudlinux2 fail2ban: 2026-09-05 22:49:05,221 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 211.248.235.67 - 2026-09-05 22:49:04cloudlinux2 fail2ban: 2026-09-05 22:49:07,911 fail2ban.actions [1594]: NOTICE [plesk-wordpress] Ban 211.248.235.67cloudlinux2 fail2ban: 2026-
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 19:55:54
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.157 (server51.shared.spaceship.host): ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.157 (server51.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 15:55:47.557622 2026] [security2:error] [pid 1162:tid 1162] [client 66.29.148.157:47546] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||majesticsolutions.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "majesticsolutions.co"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apxzwwbGuu25tdPJkoJVJgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-05 19:55:15
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
Anonymous
2026-09-05 16:02:47
(12 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-05 15:45:18
(13 hours ago)
Web attack blocked by Wordfence on limburgsekunstkring.nl (1 hit). Reported by CRMON.
Web App Attack
🇩🇪
LRob
2026-09-05 13:53:20
(14 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | 2026-09-05 13:53 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 09:30:12
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.157 (server51.shared.spaceship.host): ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.157 (server51.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 05:30:05.880839 2026] [security2:error] [pid 29003:tid 29003] [client 66.29.148.157:39956] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||realdesigninterior.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "realdesigninterior.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apvhHZkZoresqrxRyWk1rAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
lostswordfish.com
2026-09-05 07:14:04
(21 hours ago)
Wordfence waf block on fairregistry
Web App Attack
🇫🇷
masterguru
2026-09-05 07:09:09
(21 hours ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 66.29.148.157 (US/United States/server51.shar ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 66.29.148.157 (US/United States/server51.shared.spaceship.host): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-05 07:06:58
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 66.29.148.157 (server51.shared.spaceship.host): ...
show more
(mod_security) mod_security (id:225170) triggered by 66.29.148.157 (server51.shared.spaceship.host): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 03:06:54.271866 2026] [security2:error] [pid 11915:tid 11915] [client 66.29.148.157:60408] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||robotsinme.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "robotsinme.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apu_jiJu2fFJKgzXNs8duwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack