๐บ๐ธ
TPI-Abuse
2026-08-29 04:50:47
(24 minutes ago)
(mod_security) mod_security (id:225170) triggered by 69.49.241.76 (br1078.hostgator.com.br): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 69.49.241.76 (br1078.hostgator.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:50:43.146981 2026] [security2:error] [pid 9294:tid 9294] [client 69.49.241.76:42938] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tracytappan.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tracytappan.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apJlI4-KKEQeEvGTIdawewAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-08-29 04:35:37
(39 minutes ago)
(wordpress) Failed wordpress login from 69.49.241.76 (BR/Brazil/br1078.hostgator.com.br): (CF_ENABL ...
show more
(wordpress) Failed wordpress login from 69.49.241.76 (BR/Brazil/br1078.hostgator.com.br): (CF_ENABLE)
show less
Brute-Force
๐ฉ๐ช
bsoft.de
2026-08-29 04:34:19
(41 minutes ago)
69.49.241.76 - - [29/Aug/2026:01:56:06 +0200] "GET /wp-login.php HTTP/1.1" 404 74748 "-" "Mozilla/5. ...
show more
69.49.241.76 - - [29/Aug/2026:01:56:06 +0200] "GET /wp-login.php HTTP/1.1" 404 74748 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
69.49.241.76 - - [29/Aug/2026:05:56:55 +0200] "GET /wp-login.php HTTP/1.1" 404 74798 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
69.49.241.76 - - [29/Aug/2026:06:34:18 +0200] "GET /wp-login.php HTTP/1.1" 404 74824 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-29 04:33:01
(42 minutes ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐ฉ๐ช
LRob
2026-08-29 04:26:33
(48 minutes ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-login.php | 2026-08-29 04:26 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 04:17:02
(58 minutes ago)
(mod_security) mod_security (id:225170) triggered by 69.49.241.76 (br1078.hostgator.com.br): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 69.49.241.76 (br1078.hostgator.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 00:16:59.035860 2026] [security2:error] [pid 19913:tid 19913] [client 69.49.241.76:29720] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thorndikestudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thorndikestudio.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apJdO73Tk6haTjDWjDIBiAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 03:48:28
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 69.49.241.76 (br1078.hostgator.com.br): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 69.49.241.76 (br1078.hostgator.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 23:48:24.171935 2026] [security2:error] [pid 12918:tid 12918] [client 69.49.241.76:35808] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bostonmarathonstories.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bostonmarathonstories.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apJWiKjano2Kc0LUOzF-cQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 03:35:18
(1 hour ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐จ๐ฆ
KIsmay
2026-08-29 02:55:33
(2 hours ago)
Aug 28 18:58:21 www4 WPAudit[1859401]: 69.49.241.76 bestnelson.org "Mozilla/5.0 (Windows NT 10.0; Wi ...
show more
Aug 28 18:58:21 www4 WPAudit[1859401]: 69.49.241.76 bestnelson.org "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" katietabor-developer:katietabor-developer7 FAIL
Aug 28 18:58:22 www4 WPAudit[1859402]: 69.49.241.76 bestnelson.org "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" bestnelson-admin:bestnelson-admin7 FAIL
Aug 28 22:33:35 www4 WPAudit[1879016]: 69.49.241.76 www.lemoncreekcampground.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" lemoncreek:lemoncreek001 FAIL
Aug 28 22:33:36 www4 WPAudit[1879017]: 69.49.241.76 www.lemoncreekcampground.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" sbd-admin:sbd-admin001 FAIL
Aug 28 22:55:31 www4 WPAudit[1881190]: 69.49.241.76 servicesfyi.ca "Mozilla/5.0 (Windows NT 10.0; Win64;
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
R.G.
2026-08-29 02:28:40
(2 hours ago)
(WPLOGINorWHATEVER) Get lost please 69.49.241.76 (BR/Brazil/br1078.hostgator.com.br): 7 in the last ...
show more
(WPLOGINorWHATEVER) Get lost please 69.49.241.76 (BR/Brazil/br1078.hostgator.com.br): 7 in the last 600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ซ๐ท
francoisunix
2026-08-29 01:56:52
(3 hours ago)
69.49.241.76 - - [29/Aug/2026:03:56:47 +0200] "GET //wp-login.php HTTP/1.1" 401 15029 "https://eco-c ...
show more
69.49.241.76 - - [29/Aug/2026:03:56:47 +0200] "GET //wp-login.php HTTP/1.1" 401 15029 "https://eco-conscient.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" "69.49.241.76" "www.eco-conscient.com" sn="www.eco-conscient.com" rt=0.124 ua="unix:/var/run/php/php8.2-fpm.sock" us="401" ut="0.125" ul="15043" cs=BYPASScf_country="BR" cf_region="S\xC3\xA3o Paulo" cf_city="Vinhedo"rip=127.0.0.1 cf_ip=69.49.241.76 xff="69.49.241.76" p_xff="69.49.241.76, 69.49.241.76"
69.49.241.76 - - [29/Aug/2026:03:56:47 +0200] "GET //wp-login.php HTTP/1.1" 401 15029 "https://eco-conscient.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" "69.49.241.76" "www.eco-conscient.com" sn="www.eco-conscient.com" rt=0.140 ua="unix:/var/run/php/php8.2-fpm.sock" us="401" ut="0.141" ul="15043" cs=BYPASScf_country="BR" cf_region="S\xC3\xA3o Paulo" cf_city="Vinhed
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 01:37:15
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 69.49.241.76 (br1078.hostgator.com.br): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 69.49.241.76 (br1078.hostgator.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 21:37:09.522454 2026] [security2:error] [pid 25243:tid 25243] [client 69.49.241.76:37894] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blacktieokc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blacktieokc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apI3xQBwhzNC-2augb7nrwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-29 01:28:09
(3 hours ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 69.49.241.76 (BR/Brazil/br1078.hostgator.com. ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 69.49.241.76 (BR/Brazil/br1078.hostgator.com.br): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ช๐ธ
librebit
2026-08-29 01:24:52
(3 hours ago)
Brute force
Brute-Force
๐ช๐ธ
masterguru
2026-08-29 00:57:57
(4 hours ago)
(wplogin) Failed WordPress login from 69.49.241.76 (BR/Brazil/br1078.hostgator.com.br): 5 in the las ...
show more
(wplogin) Failed WordPress login from 69.49.241.76 (BR/Brazil/br1078.hostgator.com.br): 5 in the last 3600 secs (0-122)
show less
Hacking