🇹🇷
oalver
2026-08-02 14:26:53
(1 month ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-08-02. Risk score: 30/100.
show less
Web App Attack
🇩🇪
FeG Deutschland
2026-08-02 11:13:17
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-02 00:06:12
(1 month ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
ger-stg-sifi1
2026-07-30 07:54:33
(1 month ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
FeG Deutschland
2026-07-30 06:11:36
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-07-28 08:11:44
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 04:11:41.370191 2026] [security2:error] [pid 1988340:tid 1988340] [client 92.113.19.180:61516] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tigerpathteam.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tigerpathteam.org"] [uri "/wp-json/wp/v2/users"] [unique_id "amhkPSnY0WH3DihkkcUNMgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-28 07:48:21
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 03:48:16.082949 2026] [security2:error] [pid 1213180:tid 1213180] [client 92.113.19.180:63086] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||snowrideadventures.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "snowrideadventures.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amhewGXlTYuc8INLSLk4fQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 07:22:58
(1 month ago)
2026-07-28T09:22:56.959675+02:00 aion wordpress[689675]: Blocked user enumeration attempt from 92.11 ...
show more
2026-07-28T09:22:56.959675+02:00 aion wordpress[689675]: Blocked user enumeration attempt from 92.113.19.180
...
show less
Hacking
Brute-Force
🇺🇸
TPI-Abuse
2026-07-28 05:36:53
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 01:36:45.254011 2026] [security2:error] [pid 3200292:tid 3200292] [client 92.113.19.180:24462] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||texascottagebakers.org.texascottagebakers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "texascottagebakers.org.texascottagebakers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amg_7Z4pN_As3xo84U4h4wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-28 01:40:17
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 21:40:14.633389 2026] [security2:error] [pid 180959:tid 180959] [client 92.113.19.180:21154] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||achildsspace.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "achildsspace.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "amgIfupJXSD_l7MtfG5DgQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-28 00:10:02
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 20:09:57.119558 2026] [security2:error] [pid 354410:tid 354410] [client 92.113.19.180:51338] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blacktieokc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blacktieokc.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amfzVdp5hYEYSJqsXXcAnwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
Progetto1
2026-07-27 20:20:07
(1 month ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 20:01:21
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 16:01:17.149373 2026] [security2:error] [pid 102449:tid 102549] [client 92.113.19.180:42402] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||koalacogs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "koalacogs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ame5DapjC5rFxz_BFhx-GAAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 19:38:52
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 15:38:45.887961 2026] [security2:error] [pid 2026558:tid 2026558] [client 92.113.19.180:40694] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||earthtwoworkshop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "earthtwoworkshop.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "amezxaQFaMFJNh05iiQnvgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 18:46:08
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 92.113.19.180 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 14:46:04.077533 2026] [security2:error] [pid 803997:tid 803997] [client 92.113.19.180:21182] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stationrestaurant.ca|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stationrestaurant.ca"] [uri "/wp-json/wp/v2/users"] [unique_id "amenbFQr_mdbGGqXI4tyfAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack