🇩🇪
ger-stg-sifi1
2026-09-09 06:41:01
(4 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇮🇳
evicky2002
2026-09-09 06:00:01
(5 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-09 05:49:04
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 01:48:58.634943 2026] [security2:error] [pid 4542:tid 4542] [client 81.88.181.116:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||upskirtcrazy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "upskirtcrazy.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDzSjUaWSGkGcIbrn7sEgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-09 01:20:40
(9 hours ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 81.88.181.116 (CH/Switzerland/-): 1 in the la ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 81.88.181.116 (CH/Switzerland/-): 1 in the last 3600 secs (0-196)
show less
Hacking
🇩🇪
stinpriza
2026-09-08 22:23:20
(12 hours ago)
Web App Attack
Web App Attack
🇩🇪
Hazzard
2026-09-08 20:43:32
(14 hours ago)
(wordpress) Failed wordpress login from 81.88.181.116 (CH/Switzerland/Valais/Sierre/-/[redacted]): ...
show more
(wordpress) Failed wordpress login from 81.88.181.116 (CH/Switzerland/Valais/Sierre/-/[redacted]): (CF_ENABLE)
show less
Brute-Force
🇩🇪
neckaralb-admin.de
2026-09-08 17:51:39
(17 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:55:21
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:55:15.831618 2026] [security2:error] [pid 21959:tid 21959] [client 81.88.181.116:65049] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||twogocamping.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "twogocamping.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAh04XfIbk2Gd0t58eHxAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 14:07:03
(21 hours ago)
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/2.0
Hacking
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 13:08:56
(22 hours ago)
cloudlinux2 fail2ban: 2026-09-08 15:03:57,348 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-08 15:03:57,348 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 142.111.152.85 - 2026-09-08 15:03:56cloudlinux2 fail2ban: 2026-09-08 15:04:20,062 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 91.193.232.192 - 2026-09-08 15:04:19cloudlinux2 fail2ban: 2026-09-08 15:05:10,284 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 34.86.232.121cloudlinux2 fail2ban: 2026-09-08 15:05:49,296 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 217.77.5.57 - 2026-09-08 15:05:49cloudlinux2 fail2ban: 2026-09-08 15:06:33,356 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 142.111.152.71 - 2026-09-08 15:06:33cloudlinux2 fail2ban: 2026-09-08 15:06:29,709 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 142.111.152.71 - 2026-09-08 15:06:28cloudlinux2 fail2ban: 2026-09-08 15:06:29,730 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 142.111.152.63 - 2026-09-08 15:06:28cloudlinux2 fail2ban: 20
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 13:05:25
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:05:17.841699 2026] [security2:error] [pid 26172:tid 26172] [client 81.88.181.116:60475] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||palumbodesigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "palumbodesigns.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAIDd6uC-WYKyvY8mE_IQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:43:39
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:43:33.652334 2026] [security2:error] [pid 12377:tid 12377] [client 81.88.181.116:62386] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.theaccents.mainstreetofficesuites.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.theaccents.mainstreetofficesuites.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_05bAOwq6-O2J33efsiAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:06:13
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:06:08.830944 2026] [security2:error] [pid 17300:tid 17300] [client 81.88.181.116:63931] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abilityengraving.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abilityengraving.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_sIJxt7XI2-mBdnsjRbwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:14:28
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 81.88.181.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:14:21.086081 2026] [security2:error] [pid 7339:tid 7339] [client 81.88.181.116:62850] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||solporpoise.com.herston.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "solporpoise.com.herston.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_R7WuHyRB_z43eSiOJPQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
AlexEventfahrtenIPDB
2026-09-08 09:11:47
(1 day ago)
[Tue Sep 08 11:11:46.737287 2026] [authz_core:error] [pid 305879:tid 305881] [remote 81.88.181.116:5 ...
show more
[Tue Sep 08 11:11:46.737287 2026] [authz_core:error] [pid 305879:tid 305881] [remote 81.88.181.116:59763] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/wp-login.php
[Tue Sep 08 11:11:47.349363 2026] [authz_core:error] [pid 305879:tid 305882] [remote 81.88.181.116:59763] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/wp-login.php
...
show less
Brute-Force
Web App Attack