🇺🇸
lostswordfish.com
2026-09-09 11:10:04
(40 minutes ago)
Wordfence waf block on decarcerationnation
Web App Attack
🇩🇪
Hazzard
2026-09-09 04:06:15
(7 hours ago)
(wordpress) Failed wordpress login from 91.176.62.188 (BE/Belgium/Brussels Capital/Brussels/188.62-1 ...
show more
(wordpress) Failed wordpress login from 91.176.62.188 (BE/Belgium/Brussels Capital/Brussels/188.62-176-91.adsl-dyn.isp.belgacom.be/[redacted]): (CF_ENABLE)
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-09 04:02:30
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belga ...
show more
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belgacom.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 00:02:23.427616 2026] [security2:error] [pid 28844:tid 28844] [client 91.176.62.188:47428] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tedharris.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tedharris.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqDaT936TS0n3V-lOAEPJQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-09 01:23:06
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇫🇮
JRID
2026-09-08 22:48:37
(13 hours ago)
Detected by CrowdSec + Suricata IDS: automated attack/scan against web servers.
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-09-08 20:13:57
(15 hours ago)
cloudlinux2 fail2ban: 2026-09-08 22:09:21,085 fail2ban.actions [1794]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-08 22:09:21,085 fail2ban.actions [1794]: NOTICE [plesk-modsecurity] Unban 34.146.108.178cloudlinux2 fail2ban: 2026-09-08 22:09:20,888 fail2ban.filter [1794]: INFO [plesk-proftpd] Found 46.62.209.187 - 2026-09-08 22:09:20cloudlinux2 fail2ban: 2026-09-08 22:09:48,585 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 62.4.45.14 - 2026-09-08 22:09:48cloudlinux2 fail2ban: 2026-09-08 22:10:34,795 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 23.94.155.21 - 2026-09-08 22:10:33cloudlinux2 fail2ban: 2026-09-08 22:10:34,802 fail2ban.filter [1794]: INFO [plesk-wordpress] Found 23.94.155.35 - 2026-09-08 22:10:33cloudlinux2 fail2ban: 2026-09-08 22:10:37,257 fail2ban.actions [1794]: NOTICE [plesk-proftpd] Unban 125.111.47.184cloudlinux2 fail2ban: 2026-09-08 22:11:00,035 fail2ban.filter [1794]: INFO [plesk-modsecurity] Found 91.176.62.188 - 2026-09-08 22:11:00cloudlinux2 fail2ban: 2026-09-08 22:11:15,246 fail2ban
show less
FTP Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 20:13:36
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belga ...
show more
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belgacom.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 16:13:29.677184 2026] [security2:error] [pid 11073:tid 11073] [client 91.176.62.188:45788] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||waterjetsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "waterjetsolutions.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBsaY_7D9-8rtNjOqMIJAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-08 19:50:29
(16 hours ago)
WordPress login brute-force | path: /wp-login.php | 2026-09-08 19:50 UTC
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:21:44
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belga ...
show more
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belgacom.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:21:37.625446 2026] [security2:error] [pid 12358:tid 12358] [client 91.176.62.188:41382] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||texascottagebakers.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "texascottagebakers.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqBEIb1kJcroPFMlWzYAPwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
brechtr
2026-09-08 16:04:36
(19 hours ago)
[Press84-BanHammer] bad username — Sourced from: brechtryckaert.com — Request: POST /wp-login.php
Brute-Force
🇺🇸
TPI-Abuse
2026-09-08 14:41:07
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belga ...
show more
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belgacom.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:40:59.528007 2026] [security2:error] [pid 22710:tid 22710] [client 91.176.62.188:59128] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rohanbyles.com.au|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rohanbyles.com.au"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aqAee8LtMAmUW_CbtTj1PgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 10:17:59
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belga ...
show more
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belgacom.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:17:54.738516 2026] [security2:error] [pid 10387:tid 10387] [client 91.176.62.188:48082] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||peterjohnsonauthor.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "peterjohnsonauthor.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_g0jZEw-Xs_S_XjdiFUwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 08:35:44
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belga ...
show more
(mod_security) mod_security (id:225170) triggered by 91.176.62.188 (188.62-176-91.adsl-dyn.isp.belgacom.be): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:35:37.228528 2026] [security2:error] [pid 12854:tid 12854] [client 91.176.62.188:45592] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gasoilliquidsdaily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gasoilliquidsdaily.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ap_I2Zr8INLJogDKN-MO7AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack