๐ซ๐ท
LRob
2026-09-11 14:51:32
(1 hour ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: /wp-login.php | 2026-09-11 14:51 UTC
show less
Bad Web Bot
๐บ๐ธ
cwytech
2026-09-11 14:00:13
(1 hour ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-09-11 13:58:10
(1 hour ago)
74.91.221.47 - - [11/Sep/2026:15:58:07 +0200] "GET /wp-login.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 ...
show more
74.91.221.47 - - [11/Sep/2026:15:58:07 +0200] "GET /wp-login.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-11 12:37:55
(3 hours ago)
5.388 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
Anonymous
2026-09-11 12:15:58
(3 hours ago)
Web attack blocked by Wordfence on kernoverlegsibbe-ijzeren.nl (6 hits). Reported by CRMON.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 11:37:26
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 74.91.221.47 (sh10003.vodien.com): 1 in the las ...
show more
(mod_security) mod_security (id:225170) triggered by 74.91.221.47 (sh10003.vodien.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 07:37:19.626603 2026] [security2:error] [pid 22294:tid 22294] [client 74.91.221.47:13072] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thorndikestudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thorndikestudio.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqPn7x72hD6oogX_MKr7qAAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-11 09:56:53
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
๐ฉ๐ช
LRob
2026-09-11 07:47:46
(8 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp/wp-login.php | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36 | 2026-09-11 07:47 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
stinpriza
2026-09-11 07:44:04
(8 hours ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 07:43:37
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 74.91.221.47 (sh10003.vodien.com): 1 in the las ...
show more
(mod_security) mod_security (id:225170) triggered by 74.91.221.47 (sh10003.vodien.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 03:43:29.580355 2026] [security2:error] [pid 21117:tid 21117] [client 74.91.221.47:54542] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.soundtrax.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.soundtrax.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqOxIRkLJIwe13gimaAEFwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 07:32:34
(8 hours ago)
74.91.221.47 - - [11/Sep/2026:09:32:29 +0200] "GET /wp-login.php HTTP/2.0" 200 4318 "-" "Mozilla/5.0 ...
show more
74.91.221.47 - - [11/Sep/2026:09:32:29 +0200] "GET /wp-login.php HTTP/2.0" 200 4318 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36"
...
show less
Web App Attack