๐บ๐ธ
xxkodedxx
2026-08-27 01:53:55
(58 minutes ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
Active: 01:53:07 UTC
Volume: 2 honeypot probe(s)
Bait taken: /wp-login.php
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-27 01:42:07
(1 hour ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
LRob
2026-08-26 11:08:59
(15 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-26 11:08 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 07:03:58
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 70.32.23.119 (mi3-ss104.a2hosting.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 70.32.23.119 (mi3-ss104.a2hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 03:03:52.326707 2026] [security2:error] [pid 21293:tid 21293] [client 70.32.23.119:50292] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||laura-stone.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "laura-stone.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6P2DcPu4JMz-TjPqacpAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 06:47:30
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 70.32.23.119 (mi3-ss104.a2hosting.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 70.32.23.119 (mi3-ss104.a2hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 02:47:24.493442 2026] [security2:error] [pid 383:tid 383] [client 70.32.23.119:45898] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ramseycountycorruption.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ramseycountycorruption.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6L_LcmWmobJg90Y8oJgAAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 06:17:16
(20 hours ago)
Web application attack detected.
Web App Attack
๐ฉ๐ช
LRob
2026-08-25 06:35:49
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp/wp-login.php | 2026-08-25 06:35 UTC
show less
Hacking
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-25 04:15:32
(1 day ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐น๐ท
oalver
2026-08-24 22:11:18
(2 days ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-08-24. Risk score: 30/100.
show less
Web App Attack
๐ฌ๐ง
spamverify.com
2026-08-24 11:11:54
(2 days ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-24 07:13:56
(2 days ago)
cloudlinux2 fail2ban: 2026-08-24 09:08:44,801 fail2ban.filter [1464]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-24 09:08:44,801 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 49.36.211.172 - 2026-08-24 09:08:44cloudlinux2 fail2ban: 2026-08-24 09:09:31,277 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 70.32.23.119 - 2026-08-24 09:09:31cloudlinux2 fail2ban: 2026-08-24 09:09:59,625 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 49.36.211.172 - 2026-08-24 09:09:59cloudlinux2 fail2ban: 2026-08-24 09:10:05,301 fail2ban.filter [1464]: INFO [plesk-wordpress] Found 146.19.90.233 - 2026-08-24 09:10:04cloudlinux2 fail2ban: 2026-08-24 09:10:31,543 fail2ban.filter [1464]: INFO [plesk-modsecurity] Found 49.36.211.172 - 2026-08-24 09:10:31cloudlinux2 fail2ban: 2026-08-24 09:10:32,329 fail2ban.filter [1464]: INFO [recidive] Found 49.36.211.172 - 2026-08-24 09:10:32cloudlinux2 fail2ban: 2026-08-24 09:10:32,322 fail2ban.actions [1464]: NOTICE [plesk-modsecurity] Ban 49.36.211.172cloudlinux2 fail2ban: 2026-08-2
show less
Web App Attack
๐ซ๐ท
LRob
2026-08-24 00:45:14
(3 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-24 00:45 UTC
show less
Hacking
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-21 04:06:49
(5 days ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 14:19:55
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 70.32.23.119 (mi3-ss104.a2hosting.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 70.32.23.119 (mi3-ss104.a2hosting.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 10:19:50.832739 2026] [security2:error] [pid 27051:tid 27051] [client 70.32.23.119:45090] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||montidaunitour.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "montidaunitour.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aocNBqUID1FgM1hKf2UMhQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack