๐บ๐ธ
Gmtekai
2026-05-18 04:10:34
(4 months ago)
WordPress credential-stuffing attack against wp-login.php and REST API user enumeration (wp-json/wp/ ...
show more
WordPress credential-stuffing attack against wp-login.php and REST API user enumeration (wp-json/wp/v2/users). Distributed botnet hit cantrellmotorsport.com 2026-05-17. One successful breach of admin account (separately contained). Categories 18+21. Reported by GMTek AI.
show less
Brute-Force
Web App Attack
Anonymous
2025-03-31 14:46:53
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐ฉ๐ช
Hazzard
2025-03-30 20:49:26
(1 year ago)
(wordpress) Failed wordpress login from 95.180.58.142 (RS/Serbia/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-03-30 20:33:13
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 95.180.58.142 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 95.180.58.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 30 16:33:09.027550 2025] [security2:error] [pid 3697:tid 3697] [client 95.180.58.142:57040] [client 95.180.58.142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drwolberg.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drwolberg.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z-mqhZiXhQgpOrggyW8vagAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2025-03-30 13:44:02
(1 year ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
Penny Packer
2025-03-30 13:11:16
(1 year ago)
Fail2Ban apache-tripwires
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-30 12:59:21
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 95.180.58.142 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 95.180.58.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 30 08:59:17.348262 2025] [security2:error] [pid 26403:tid 26403] [client 95.180.58.142:55186] [client 95.180.58.142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||btsalesrep.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "btsalesrep.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z-lAJW3Y7iLa6qQwzULXhQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-30 00:41:54
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 95.180.58.142 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 95.180.58.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 29 20:41:49.294781 2025] [security2:error] [pid 15624:tid 15624] [client 95.180.58.142:60446] [client 95.180.58.142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||artbytracyjane.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "artbytracyjane.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z-iTTQUZqZPhPcim2V0NSgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-03-30 00:08:57
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-03-29 16:31:15
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 95.180.58.142 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240335) triggered by 95.180.58.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 29 12:31:08.432914 2025] [security2:error] [pid 26906:tid 26932] [client 95.180.58.142:64184] [client 95.180.58.142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 95.180.58.142 (+1 hits since last alert)|aafminstitute.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "aafminstitute.com"] [uri "/xmlrpc.php"] [unique_id "Z-ggTIaopb6XlAfj66mpSAAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-26 22:07:25
(1 year ago)
(wordpress) Failed wordpress login from 95.180.58.142 (RS/Serbia/-)
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-01-26 19:57:37
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 95.180.58.142 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 95.180.58.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jan 26 14:57:29.943233 2025] [security2:error] [pid 1133735:tid 1133735] [client 95.180.58.142:50983] [client 95.180.58.142] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||agelessoutcomes.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "agelessoutcomes.com"] [uri "/wp-json/wp/v2/users"] [unique_id "Z5aTqVyUgN6OcnZSAIXTFQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-26 16:44:30
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH