🇺🇸
TPI-Abuse
2026-08-30 07:29:33
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 66.96.183.176 (176.183.96.66.static.eigbox.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 66.96.183.176 (176.183.96.66.static.eigbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 03:29:25.228396 2026] [security2:error] [pid 23525:tid 23525] [client 66.96.183.176:37834] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||greenmountainfeeds.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "greenmountainfeeds.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apPb1d3RWB0K8ukxmNo07wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇽
octageeks.com
2026-08-30 04:23:15
(7 hours ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇩🇪
FeG Deutschland
2026-08-29 05:52:45
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇫🇷
LRob
2026-08-26 12:43:54
(3 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: / | query: author=1 | 2026-08-26 12:43 UTC
show less
Hacking
Web App Attack
Anonymous
2026-08-14 00:10:37
(2 weeks ago)
WordPress Brute Force
Hacking
Brute-Force
Web App Attack
🇨🇿
ptlab
2026-08-13 00:45:10
(2 weeks ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
Anonymous
2026-08-13 00:10:37
(2 weeks ago)
WordPress Brute Force
Hacking
Brute-Force
Web App Attack
🇺🇸
xxkodedxx
2026-08-12 11:15:17
(2 weeks ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get in 10m window.
Active: 11:15:12→11:15:13 UTC
Volume: 2 honeypot probe(s)
Bait taken: /wp-login.php
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-11 06:23:35
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 66.96.183.176 (176.183.96.66.static.eigbox.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 66.96.183.176 (176.183.96.66.static.eigbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 02:23:28.836884 2026] [security2:error] [pid 25526:tid 25526] [client 66.96.183.176:52660] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rdhtrucking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rdhtrucking.com"] [uri "/wp-json/wp/v2/users"] [unique_id "anq_4MQW9lkCaf_VAZQkZwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-10 19:05:09
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 66.96.183.176 (176.183.96.66.static.eigbox.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 66.96.183.176 (176.183.96.66.static.eigbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 15:05:03.335463 2026] [security2:error] [pid 1356408:tid 1356408] [client 66.96.183.176:32848] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||servecon.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "servecon.net"] [uri "/wp-json/wp/v2/users"] [unique_id "anog3zm4xNKKa7uAuSchdQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇹
Malta
2026-08-10 06:30:41
(2 weeks ago)
66.96.183.176 - - [10/Aug/2026:08:30:41 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
66.96.183.176 - - [10/Aug/2026:08:30:41 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-08-10 05:29:38
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 66.96.183.176 (176.183.96.66.static.eigbox.net) ...
show more
(mod_security) mod_security (id:225170) triggered by 66.96.183.176 (176.183.96.66.static.eigbox.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 10 01:29:30.923252 2026] [security2:error] [pid 2039585:tid 2039585] [client 66.96.183.176:45376] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||iplayriichi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "iplayriichi.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "anlhunbreuo1n7SFsiqZcgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-09 23:45:23
(2 weeks ago)
WordPress Brute Force
Brute-Force
🇲🇽
octageeks.com
2026-08-09 04:14:35
(3 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇩🇪
FeG Deutschland
2026-08-08 22:28:01
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack