🇩🇪
neckaralb-admin.de
2026-09-09 09:08:08
(16 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 04:48:18
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): ...
show more
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:48:12.013406 2026] [security2:error] [pid 27508:tid 27508] [client 87.229.87.248:43980] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ohiohca.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ohiohca.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDlDMK0Cj9MGmWrB-pW1gAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 03:16:26
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): ...
show more
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 23:16:19.120166 2026] [security2:error] [pid 14190:tid 14190] [client 87.229.87.248:36522] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||altoshp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "altoshp.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDPgy0MO6B3MOekBaphtQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 02:29:07
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): ...
show more
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 22:29:00.541051 2026] [security2:error] [pid 28308:tid 28308] [client 87.229.87.248:46700] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||vr-squaredance.kdgsf.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "vr-squaredance.kdgsf.xyz"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDEbHv5l2mzY583ay60tQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
cwytech
2026-09-09 01:09:20
(8 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-09 01:07:48
(8 hours ago)
(wordpress) Failed wordpress login from 87.229.87.248 (HU/Hungary/Győr-Moson-Sopron/Győrladamér/host ...
show more
(wordpress) Failed wordpress login from 87.229.87.248 (HU/Hungary/Győr-Moson-Sopron/Győrladamér/host-87-229-87-248.wave-net.hu/[redacted]): (CF_ENABLE)
show less
Brute-Force
🇩🇪
AlexEventfahrtenIPDB
2026-09-09 01:06:40
(8 hours ago)
[Wed Sep 09 03:06:40.241473 2026] [authz_core:error] [pid 526602:tid 526622] [remote 87.229.87.248:3 ...
show more
[Wed Sep 09 03:06:40.241473 2026] [authz_core:error] [pid 526602:tid 526622] [remote 87.229.87.248:37292] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/wp-login.php
[Wed Sep 09 03:06:40.397894 2026] [authz_core:error] [pid 526602:tid 526638] [remote 87.229.87.248:37292] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/wp-login.php
...
show less
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-09-09 00:00:48
(9 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 23:43:15
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): ...
show more
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 19:43:08.343760 2026] [security2:error] [pid 20415:tid 20415] [client 87.229.87.248:50986] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||paleopathologist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "paleopathologist.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqCdjDsm0MIhJ5YmpPVCnAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-08 23:07:13
(10 hours ago)
📄 Probes for wp-login.php and other inexistent URLs
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:33:01
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): ...
show more
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:32:52.403144 2026] [security2:error] [pid 24547:tid 24547] [client 87.229.87.248:41772] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||michaelthompson.biz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "michaelthompson.biz"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBw9ILppeX5Pb6_vZwghQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Tripwire
2026-09-08 19:32:20
(13 hours ago)
Wordpress login attempts
Brute-Force
Web App Attack
🇩🇪
london2038.com
2026-09-08 16:45:41
(16 hours ago)
Probing for exploits
87.229.87.248 - - [08/Sep/2026:18:45:34 +0200] "GET /wp-login.php HTTP/2.0" 301 ...
show more
Probing for exploits
87.229.87.248 - - [08/Sep/2026:18:45:34 +0200] "GET /wp-login.php HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
87.229.87.248 - - [08/Sep/2026:18:45:37 +0200] "POST /wp-login.php HTTP/2.0" 301 0 "https://v97746.<REDACTED>/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 16:22:46
(17 hours ago)
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): ...
show more
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:22:39.333665 2026] [security2:error] [pid 32702:tid 32712] [client 87.229.87.248:47544] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||strengthsmatter.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "strengthsmatter.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqA2T7ko9nTiG42FJdkQFwAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:24:30
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): ...
show more
(mod_security) mod_security (id:225170) triggered by 87.229.87.248 (host-87-229-87-248.wave-net.hu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:24:24.686810 2026] [security2:error] [pid 24833:tid 24833] [client 87.229.87.248:50616] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||socialalchemy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "socialalchemy.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAoqMKibTH0ohMTVEj8UwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack