๐บ๐ธ
wordpresshosting.solutions
2026-09-16 10:20:30
(2 weeks ago)
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: [IP] - - [16/Sep/2026:10:20:18 ...
show more
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: [IP] - - [16/Sep/2026:10:20:18 +0000] "GET /wp-json/wp/v2/users?_fields=slug&per_page=100&page=1 HTTP/1.1" 401 2531 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[IP] Safari/537.36"
[IP] - - [16/Sep/2026:10:20:30 +0000] "GET /wp-json/wp/v2/users?_jsonp=callback&per_page=100&_fields=id,slug HTTP/1.1" 401 2531 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[IP] Safari/537.36"
show less
Brute-Force
Web App Attack
๐ซ๐ท
EvoX
2026-09-15 10:24:40
(2 weeks ago)
๐ก๏ธ Honeypot [bsts-tpot-sensor]: Brute-force attack detected on 22/SSH
โข Credential used: ubnt:ubnt
โข ...
show more
๐ก๏ธ Honeypot [bsts-tpot-sensor]: Brute-force attack detected on 22/SSH
โข Credential used: ubnt:ubnt
โข Number of login attempts: 1
โข Client: SSH-2.0-Go
show less
SSH
๐ฌ๐ง
consul.to
2026-09-15 09:47:14
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
consul.to
2026-09-13 12:59:44
(3 weeks ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-12 01:35:29
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.86.176.249 (vivid.herosite.pro): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 103.86.176.249 (vivid.herosite.pro): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 21:35:24.431067 2026] [security2:error] [pid 23638:tid 23638] [client 103.86.176.249:40564] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||convtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "convtek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqSsXEutYQXaU0ndg2pzugAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 20:38:49
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 103.86.176.249 (vivid.herosite.pro): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 103.86.176.249 (vivid.herosite.pro): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 16:38:45.740063 2026] [security2:error] [pid 22908:tid 22908] [client 103.86.176.249:39414] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||churchbehindthewalls.bridgital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "churchbehindthewalls.bridgital.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aqRm1VzoFpks4k0cTcnn-wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-09 01:47:35
(3 weeks ago)
SSH Honeypot detected multiple failed login attempts
Brute-Force
SSH
Anonymous
2026-09-02 09:05:25
(1 month ago)
Attacks websites by trying to access known vulnerables of plugins, brute-force of backends or probin ...
show more
Attacks websites by trying to access known vulnerables of plugins, brute-force of backends or probing of administrative tools
show less
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-01 04:28:57
(1 month ago)
cloudlinux2 fail2ban: 2026-09-01 06:24:31,558 fail2ban.filter [1605]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-01 06:24:31,558 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 41.185.8.187 - 2026-09-01 06:24:31cloudlinux2 fail2ban: 2026-09-01 06:25:36,133 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 66.116.232.29 - 2026-09-01 06:25:36cloudlinux2 fail2ban: 2026-09-01 06:25:42,806 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 103.86.176.249 - 2026-09-01 06:25:42cloudlinux2 fail2ban: 2026-09-01 06:25:53,476 fail2ban.filter [1605]: INFO [plesk-wordpress] Found 46.101.115.233 - 2026-09-01 06:25:53cloudlinux2 fail2ban: 2026-09-01 06:25:53,189 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 46.101.115.233 - 2026-09-01 06:25:53cloudlinux2 fail2ban: 2026-09-01 06:26:01,474 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.186.206.107 - 2026-09-01 06:26:01cloudlinux2 fail2ban: 2026-09-01 06:26:01,502 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 34.186.206.107 - 2026-09-01 06:26:0
show less
Web App Attack
๐บ๐ธ
posicionarte.cl
2026-09-01 02:46:03
(1 month ago)
Intento fallido de inicio de sesiรณn en WordPress
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 01:52:17
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 103.86.176.249 (vivid.herosite.pro): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 103.86.176.249 (vivid.herosite.pro): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:52:13.090576 2026] [security2:error] [pid 32719:tid 32719] [client 103.86.176.249:37918] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kaldaragroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kaldaragroup.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apYvzWsIxWaa4g-z2EVg7gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-09-01 00:47:19
(1 month ago)
(wordpress) Failed wordpress login from 103.86.176.249 (IN/India/vivid.herosite.pro): (CF_ENABLE)
Brute-Force
๐ฎ๐น
VHosting
2026-08-31 19:10:03
(1 month ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 15:16:20
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 103.86.176.249 (vivid.herosite.pro): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 103.86.176.249 (vivid.herosite.pro): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:16:14.277077 2026] [security2:error] [pid 7233:tid 7233] [client 103.86.176.249:40022] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stalbansparish.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stalbansparish.org"] [uri "/wp-json/wp/v2/users"] [unique_id "apWavh8Mxd5utIva5oANzQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 14:43:33
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 103.86.176.249 (vivid.herosite.pro): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 103.86.176.249 (vivid.herosite.pro): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 10:43:26.544210 2026] [security2:error] [pid 31661:tid 31661] [client 103.86.176.249:58864] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||calvarycavaliers.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "calvarycavaliers.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apWTDhULFpZKIaoYAeMIxwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack