🇫🇷
LRob
2026-09-09 11:28:57
(7 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: /wp-login.php | 2026-09-09 11:28 UTC
show less
Bad Web Bot
Anonymous
2026-09-09 06:15:19
(12 hours ago)
Web attack blocked by Wordfence on www.gerhuntjens.nl (1 hit). Reported by CRMON.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 06:09:37
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 02:09:31.853754 2026] [security2:error] [pid 778130:tid 778138] [client 85.228.0.44:39098] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||luxury.property-management-companies-chicago.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "luxury.property-management-companies-chicago.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqD4GwNjybtgHJUbi9nSbQAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-09 06:00:01
(12 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇲🇹
Malta
2026-09-09 02:40:41
(16 hours ago)
85.228.0.44 - - [09/Sep/2026:04:40:41 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
85.228.0.44 - - [09/Sep/2026:04:40:41 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-09 02:04:36
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:04:28.694611 2026] [security2:error] [pid 19166:tid 19166] [client 85.228.0.44:56954] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||washcountyfair.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "washcountyfair.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqC-rOgb8Ih-5IXOlQrIrAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-09-09 01:47:58
(17 hours ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 00:18:17
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 20:18:14.014745 2026] [security2:error] [pid 23842:tid 23842] [client 85.228.0.44:32924] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cnphilos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cnphilos.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqClxpyhj48sleqVPdPZjgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 22:46:01
(20 hours ago)
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/2.0, [2/2] done
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 22:18:04
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 18:17:56.901057 2026] [security2:error] [pid 4235:tid 4235] [client 85.228.0.44:53018] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||billwegener.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "billwegener.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCJlAjV5W6uXrZi7mVWZwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-08 21:49:02
(21 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 21:16:52
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 17:16:48.400092 2026] [security2:error] [pid 7328:tid 7328] [client 85.228.0.44:39244] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||marklex.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "marklex.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqB7QIYcNKnbOdIdOeRYMgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
sverson
2026-09-08 18:53:04
(23 hours ago)
Trolling for resource vulnerabilities
Hacking
🇺🇸
TPI-Abuse
2026-09-08 16:21:37
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): ...
show more
(mod_security) mod_security (id:225170) triggered by 85.228.0.44 (c-85-228-0-44.bbcust.telenor.se): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:21:34.200605 2026] [security2:error] [pid 3675:tid 3675] [client 85.228.0.44:48894] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||j3pr.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "j3pr.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqA2DluIn5TuIRy5ZiaNwQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-08 16:14:32
(1 day ago)
📄 Probes for wp-login.php and other inexistent URLs
Hacking
Web App Attack