๐บ๐ธ
TPI-Abuse
2026-08-31 11:44:01
(30 minutes ago)
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 07:43:57.013362 2026] [security2:error] [pid 31659:tid 31659] [client 69.6.222.143:52984] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||natickvillagerentals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "natickvillagerentals.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apVo_SysJxq8VGKoHCKjWwAAABQ"], referer: http://natickvillage.net/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-31 11:43:53
(30 minutes ago)
URL Probing: /wp-login.php
Web App Attack
๐ช๐ธ
masterguru
2026-08-31 10:57:09
(1 hour ago)
(wplogin) Failed WordPress login from 69.6.222.143 (BR/Brazil/vps-14728844.redeeserv.com.br): 5 in t ...
show more
(wplogin) Failed WordPress login from 69.6.222.143 (BR/Brazil/vps-14728844.redeeserv.com.br): 5 in the last 3600 secs (0-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-31 09:49:37
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:49:28.606848 2026] [security2:error] [pid 31277:tid 31277] [client 69.6.222.143:57026] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rogerheath.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rogerheath.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apVOKCLhCjpj8rocsbvkWwAAAAM"], referer: http://rogerheath.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
solution.it
2026-08-31 08:33:22
(3 hours ago)
[Mon Aug 31 10:33:22.227487 2026] [php7:error] [pid 3607893:tid 3607893] [client 69.6.222.143:35528] ...
show more
[Mon Aug 31 10:33:22.227487 2026] [php7:error] [pid 3607893:tid 3607893] [client 69.6.222.143:35528] script '/var/www/html/wp-login.php' not found or unable to stat
show less
Web App Attack
๐บ๐ธ
ph
2026-08-31 08:28:40
(3 hours ago)
Bad web bot attempting to run wp-login.php on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
iNetWorker
2026-08-31 07:59:44
(4 hours ago)
trolling for resource vulnerabilities
Web App Attack
๐บ๐ธ
etu brutus
2026-08-31 07:44:37
(4 hours ago)
69.6.222.143 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-08-31 05:49:21
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 01:49:17.543709 2026] [security2:error] [pid 3770:tid 3770] [client 69.6.222.143:47394] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||prostar.industries|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "prostar.industries"] [uri "/wp-json/wp/v2/users"] [unique_id "apUV3VRQ2FUtoxA7KSJAvgAAAAU"], referer: http://hyperpig.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 05:00:56
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 01:00:51.632607 2026] [security2:error] [pid 29791:tid 29791] [client 69.6.222.143:44594] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.billymitchell.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.billymitchell.com"] [uri "/wordpress/wp-json/wp/v2/users"] [unique_id "apUKg3aYolyXiqu2MR4znwAAAAo"], referer: http://www.billymitchell.com/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-08-31 03:53:05
(8 hours ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-08-31 03:33:59
(8 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-login\.php (Match: /wp-login.php)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 02:55:32
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 22:55:29.817423 2026] [security2:error] [pid 15355:tid 15355] [client 69.6.222.143:35030] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arapi.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arapi.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apTtIRzJglbGDWwS0hQiHgAAAAw"], referer: http://arapi.org/wp-login.php
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 01:31:50
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 ...
show more
(mod_security) mod_security (id:225170) triggered by 69.6.222.143 (vps-14728844.redeeserv.com.br): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 21:31:43.204531 2026] [security2:error] [pid 26795:tid 26902] [client 69.6.222.143:50130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||asetiadi.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "asetiadi.net"] [uri "/wp-json/wp/v2/users"] [unique_id "apTZf8SNcQ19oT6WDznX0wAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
seniorlinuxadmin
2026-08-31 01:23:04
(10 hours ago)
69.6.222.143 - - [30/Aug/2026:12:33:47 +0100] "GET /wp-login.php HTTP/2.0" 404 158 "-" "Mozilla/5.0 ...
show more
69.6.222.143 - - [30/Aug/2026:12:33:47 +0100] "GET /wp-login.php HTTP/2.0" 404 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:154.0) Gecko/20100101 Firefox/154.0"
show less
Port Scan
Web App Attack