🇺🇸
TPI-Abuse
2026-08-29 10:52:03
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 89.46.108.101 (host101-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:225170) triggered by 89.46.108.101 (host101-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 06:51:56.624969 2026] [security2:error] [pid 17119:tid 17119] [client 89.46.108.101:30070] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||heatherweathers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "heatherweathers.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apK5zMkqeazzu3AsITp4JQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 06:16:33
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 89.46.108.101 (host101-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:225170) triggered by 89.46.108.101 (host101-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 02:16:25.894995 2026] [security2:error] [pid 13501:tid 13522] [client 89.46.108.101:20640] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fastesttrademark.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fastesttrademark.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apJ5OUCm941VI44eYPv7bQAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-29 00:55:55
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 89.46.108.101 (host101-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:225170) triggered by 89.46.108.101 (host101-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:55:49.285098 2026] [security2:error] [pid 503:tid 503] [client 89.46.108.101:20776] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tasteshop.l3l4.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tasteshop.l3l4.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apIuFe-Y-WRE69NNFci1JgAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 22:53:10
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 89.46.108.101 (host101-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:225170) triggered by 89.46.108.101 (host101-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:53:05.383737 2026] [security2:error] [pid 4797:tid 4797] [client 89.46.108.101:32684] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drjasonkolber.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drjasonkolber.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apIRUeuIIx8dNqv0cbu-7gAAAAI"], referer: https://drjasonkolber.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
stinpriza
2026-08-28 21:12:38
(1 day ago)
Web App Attack
Web App Attack
🇩🇪
FeG Deutschland
2026-08-28 13:49:58
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
🇺🇸
xxkodedxx
2026-08-27 23:01:18
(1 day ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1× honeypot-get in 10m window.
Active: 23:00:53 UTC
Volume: 1 honeypot probe(s)
Bait taken: /wp-login.php
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-08-27 06:19:57
(2 days ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 89.46.108.101 (IT/Italy/host101-108-46-89.ser ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 89.46.108.101 (IT/Italy/host101-108-46-89.serverdedicati.aruba.it): 1 in the last 3600 secs (0-196)
show less
Hacking
🇲🇽
octageeks.com
2026-08-27 04:34:02
(2 days ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 07:58:12
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 89.46.108.101 (host101-108-46-89.serverdedicati ...
show more
(mod_security) mod_security (id:225170) triggered by 89.46.108.101 (host101-108-46-89.serverdedicati.aruba.it): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 03:58:06.224124 2026] [security2:error] [pid 31101:tid 31101] [client 89.46.108.101:39550] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rambleandprose.cyberclay.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rambleandprose.cyberclay.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ao6cjokZt_sA64VL1WtifgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-25 00:10:37
(4 days ago)
WordPress Brute Force
Hacking
Brute-Force
Web App Attack
🇩🇪
Hazzard
2026-08-24 17:03:05
(5 days ago)
(wordpress) Failed wordpress login from 89.46.108.101 (IT/Italy/Province of Arezzo/Arezzo/host101-10 ...
show more
(wordpress) Failed wordpress login from 89.46.108.101 (IT/Italy/Province of Arezzo/Arezzo/host101-108-46-89.serverdedicati.aruba.it/[redacted]): (CF_ENABLE)
show less
Brute-Force
🇺🇸
Zandro
2025-08-30 00:10:00
(11 months ago)
ranged TCP flood attack
DDoS Attack
🇫🇷
France Artisanat
2024-08-04 22:24:36
(2 years ago)
By the end of the 15th century, 35
Web Spam
🇩🇪
findlab
2021-11-14 06:00:01
(4 years ago)
Backdrop CMS module - Request: /wordpress/
Bad Web Bot
Web App Attack