🇺🇸
TPI-Abuse
2026-09-12 00:14:57
(27 minutes ago)
(mod_security) mod_security (id:234930) triggered by 84.235.251.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:234930) triggered by 84.235.251.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 20:14:53.218073 2026] [security2:error] [pid 2872060:tid 2872080] [client 84.235.251.112:64280] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||browbrew.metalartgate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "browbrew.metalartgate.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aqSZfakndES6lwXZVUAF9QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-12 00:10:42
(31 minutes ago)
ccideas.com.au:443 84.235.251.112 - - [12/Sep/2026:10:10:38 +1000] "GET /inputs.php HTTP/1.1" 404 96 ...
show more
ccideas.com.au:443 84.235.251.112 - - [12/Sep/2026:10:10:38 +1000] "GET /inputs.php HTTP/1.1" 404 96436 "http://ccideas.com.au/inputs.php" "Go-http-client/1.1"
...
show less
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-12 00:08:18
(34 minutes ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇮🇳
evicky2002
2026-09-12 00:05:18
(37 minutes ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-11 23:51:43
(50 minutes ago)
(mod_security) mod_security (id:234930) triggered by 84.235.251.112 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:234930) triggered by 84.235.251.112 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 19:51:39.271498 2026] [security2:error] [pid 2060:tid 2060] [client 84.235.251.112:55103] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||alsetsystems.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "alsetsystems.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aqSUCzBjEsKiUv8ZcPNt1QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
marten_o
2026-09-11 23:28:18
(1 hour ago)
84.235.251.112 - - [12/Sep/2026:01:28:18 +0200] "GET /wp-content/plugins/revslider/temp/update_extra ...
show more
84.235.251.112 - - [12/Sep/2026:01:28:18 +0200] "GET /wp-content/plugins/revslider/temp/update_extract/revslider.php HTTP/2.0" 404 236 "http://ehrliche-lotsen.de/wp-content/plugins/revslider/temp/update_extract/revslider.php" "Go-http-client/2.0" 126 291
...
show less
Web App Attack
🇷🇴
SpamStopper
2026-09-11 23:16:10
(1 hour ago)
Fail2Ban - Directory index forbidden
Hacking
Bad Web Bot
Anonymous
2026-09-11 23:14:13
(1 hour ago)
Web probing (320 hits in 24h) on cuypersinvalkenburg.nl,default-vhost: sensitive-path scans and/or 4 ...
show more
Web probing (320 hits in 24h) on cuypersinvalkenburg.nl,default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
🇩🇪
Marc
2026-09-11 23:09:59
(1 hour ago)
84.235.251.112 - - [12/Sep/2026:01:06:41 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fwww.als ...
show more
84.235.251.112 - - [12/Sep/2026:01:06:41 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fwww.als-arnsberg.de%2Fwp-admin%2F&reauth=1 HTTP/2.0" 200 4585 "https://www.als-arnsberg.de/wp-admin/" "Go-http-client/2.0" 84.235.251.112 - - [12/Sep/2026:01:06:58 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fwww.als-arnsberg.de%2Fwp-admin%2F&reauth=1 HTTP/2.0" 200 4536 "https://www.als-arnsberg.de/wp-admin/" "Go-http-client/2.0" 84.235.251.112 - - [12/Sep/2026:01:07:41 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fwww.als-arnsberg.de%2Fwp-admin%2Fnetwork%2F&reauth=1 HTTP/2.0" 200 4592 "https://www.als-arnsberg.de/wp-admin/network/" "Go-http-client/2.0" 84.235.251.112 - - [12/Sep/2026:01:08:42 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fwww.als-arnsberg.de%2Fwp-admin%2Fabout.php&reauth=1 HTTP/2.0" 200 4593 "https://www.als-arnsberg.de/wp-admin/about.php" "Go-http-client/2.0" 84.235.251.112 - - [12/Sep/2026:01:09:58 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%2Fwww.als-arnsberg.de%2Fwp-admin%
show less
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-11 23:00:05
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
Baking333
2026-09-11 22:44:07
(1 hour ago)
[redacted] 84.235.251.112 - - [11/Sep/2026:23:44:05 +0100] "GET /wp-admin/[redacted] HTTP/2.0" 301 1 ...
show more
[redacted] 84.235.251.112 - - [11/Sep/2026:23:44:05 +0100] "GET /wp-admin/[redacted] HTTP/2.0" 301 177 "http://[redacted]/wp-admin/[redacted]" "Go-http-client/2.0" [redacted] 84.235.251.112 - - [11/Sep/2026:23:44:05 +0100] "GET /wp-admin/[redacted] HTTP/2.0" 301 154 "https://[redacted]/wp-admin/[redacted]" "Go-http-client/2.0"
show less
Bad Web Bot
Web App Attack
🇩🇪
abuse-detection
2026-09-11 22:33:28
(2 hours ago)
Security detection: http-wordpress-admin-probes
Web App Attack
🇸🇬
Cloudkul Cloudkul
2026-09-11 22:11:03
(2 hours ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
🇩🇪
cloudmax
2026-09-11 21:52:44
(2 hours ago)
Cloudmax Protect [WEB BLOCK] - Too many 400/500 requests. Possible attack or hacking attempt
Hacking
Web App Attack
🇧🇪
madeit
2026-09-11 21:50:19
(2 hours ago)
Web App Attack