🇩🇪
neckaralb-admin.de
2026-09-09 06:42:42
(37 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:30:43
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:30:35.952760 2026] [security2:error] [pid 23525:tid 23525] [client 84.72.128.199:39182] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pixelspective.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pixelspective.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDg6ycUFKQwHCDmbMJx5AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 03:12:22
(4 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:47:17
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:47:10.364761 2026] [security2:error] [pid 819:tid 819] [client 84.72.128.199:48728] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||verdeprofundo.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "verdeprofundo.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDIrqiADClkiwJ6UTcB-wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 01:56:28
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 21:56:20.660373 2026] [security2:error] [pid 462687:tid 462687] [client 84.72.128.199:53424] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thesmithcouple.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thesmithcouple.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC8xFki6d66klfN0sxHHgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 00:24:11
(6 hours ago)
Web application attack detected.
Web App Attack
🇫🇷
ELYAZ
2026-09-08 23:37:42
(7 hours ago)
(wordpress) Failed wordpress login from 84.72.128.199 (CH/Switzerland/84-72-128-199.dclient.hispeed. ...
show more
(wordpress) Failed wordpress login from 84.72.128.199 (CH/Switzerland/84-72-128-199.dclient.hispeed.ch): (CF_ENABLE)
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 23:37:05
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:36:57.610471 2026] [security2:error] [pid 13145:tid 13145] [client 84.72.128.199:43690] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thorndikestudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thorndikestudio.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCcGXrRG5G3m9ih1HUApwAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:59:40
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:59:35.804548 2026] [security2:error] [pid 2535:tid 2535] [client 84.72.128.199:39522] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||diamondtrailerserv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "diamondtrailerserv.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCTV2tuzchsQwHYVEbwGAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:32:41
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:32:36.801940 2026] [security2:error] [pid 16019:tid 16019] [client 84.72.128.199:35958] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||firebelly.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "firebelly.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCNBANkVlJ55XDo0xWxUwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 21:07:27
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:07:18.678881 2026] [security2:error] [pid 23611:tid 23611] [client 84.72.128.199:60722] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||adlc18.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "adlc18.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqB5BpmyZfyXJ70VAiih4wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 20:43:13
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 19:54:30
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch ...
show more
(mod_security) mod_security (id:225170) triggered by 84.72.128.199 (84-72-128-199.dclient.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 15:54:21.826247 2026] [security2:error] [pid 2333:tid 2333] [client 84.72.128.199:58590] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flatchestedmama.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flatchestedmama.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBn7Tf0b_x1MP-Qa31xIwAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-08 19:22:49
(11 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
LRob
2026-09-08 19:17:23
(12 hours ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-login.php | 2026-09-08 19:1 ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /wp-login.php | 2026-09-08 19:17 UTC
show less
Port Scan
Web App Attack