🇺🇸
TPI-Abuse
2026-09-08 16:05:10
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.73.168.16 (84-73-168-16.dclient.hispeed.ch): ...
show more
(mod_security) mod_security (id:225170) triggered by 84.73.168.16 (84-73-168-16.dclient.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:05:05.138688 2026] [security2:error] [pid 20575:tid 20575] [client 84.73.168.16:59040] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||garantaconsulting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "garantaconsulting.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAyMfaBY191Ibov9nlt8AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-08 15:22:25
(5 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
FeG Deutschland
2026-09-08 14:58:09
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇩🇪
wpadm4
2026-09-08 14:50:33
(6 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-08 14:06:47
(6 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-08 13:34:22
(7 hours ago)
WordPress login attempt
Brute-Force
🇩🇪
LRob
2026-09-08 12:57:36
(7 hours ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-08 12:57 UTC
Brute-Force
Web App Attack
🇺🇸
cwytech
2026-09-08 12:50:21
(8 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 11:47:24
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.73.168.16 (84-73-168-16.dclient.hispeed.ch): ...
show more
(mod_security) mod_security (id:225170) triggered by 84.73.168.16 (84-73-168-16.dclient.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 07:47:20.274826 2026] [security2:error] [pid 14855:tid 14855] [client 84.73.168.16:58064] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kobraagencies.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kobraagencies.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_1yAqoadWb81bS3xlUiQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 09:59:37
(10 hours ago)
84.73.168.16 - - [08/Sep/2026:11:59:32 +0200] "GET /wp-login.php HTTP/2.0" 200 4318 "-" "Mozilla/5.0 ...
show more
84.73.168.16 - - [08/Sep/2026:11:59:32 +0200] "GET /wp-login.php HTTP/2.0" 200 4318 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:28:18
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 84.73.168.16 (84-73-168-16.dclient.hispeed.ch): ...
show more
(mod_security) mod_security (id:225170) triggered by 84.73.168.16 (84-73-168-16.dclient.hispeed.ch): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:28:14.041247 2026] [security2:error] [pid 20971:tid 20971] [client 84.73.168.16:42680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||robotsinme.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "robotsinme.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_VLupA-m-3qgosIEydnwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 06:31:03
(14 hours ago)
Web App Attack, Hacking
Hacking
Web App Attack
🇮🇹
CoreTech srl
2026-09-07 21:38:57
(23 hours ago)
cloudlinux2 fail2ban: 2026-09-07 23:34:35,164 fail2ban.filter [1794]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-07 23:34:35,164 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 84.73.168.16 - 2026-09-07 23:34:34cloudlinux2 fail2ban: 2026-09-07 23:34:45,635 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 188.213.202.128 - 2026-09-07 23:34:45cloudlinux2 fail2ban: 2026-09-07 23:36:09,401 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 54.159.52.120 - 2026-09-07 23:36:09cloudlinux2 fail2ban: 2026-09-07 23:36:35,322 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 118.196.139.226 - 2026-09-07 23:36:35cloudlinux2 fail2ban: 2026-09-07 23:36:35,344 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 118.196.139.226 - 2026-09-07 23:36:35cloudlinux2 fail2ban: 2026-09-07 23:37:36,681 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 188.213.202.156 - 2026-09-07 23:37:36cloudlinux2 fail2ban: 2026-09-07 23:38:43,713 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 35.229.96.85 - 2026-09-07 23:38:4
show less
Web App Attack
🇺🇸
lostswordfish.com
2026-09-07 09:12:02
(1 day ago)
Wordfence waf block on secure ftrecovery
Web App Attack
🇺🇸
gui-ying233
2026-08-20 15:38:14
(2 weeks ago)
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0. ...
show more
Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Bad Web Bot