๐บ๐ธ
mind5t0rm
2026-06-02 14:28:10
(1 day ago)
(WPLOGIN) WP Login Attack 101.99.79.250 (MY/Malaysia/server1.kamon.la): 3 in the last 3600 secs; Por ...
show more
(WPLOGIN) WP Login Attack 101.99.79.250 (MY/Malaysia/server1.kamon.la): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 101.99.79.250 - - [02/Jun/2026:20:56:32 +0700] "GET /wp-login.php HTTP/2.0" 200 3164 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
101.99.79.250 - - [02/Jun/2026:20:56:36 +0700] "POST /wp-login.php HTTP/2.0" 200 4207 "https://thevasilis.com/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
101.99.79.250 - - [02/Jun/2026:21:28:05 +0700] "GET /wp-login.php HTTP/2.0" 200 3164 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Port Scan
๐บ๐ธ
Jason Howell
2026-06-02 13:31:02
(1 day ago)
101.99.79.250 - - [02/Jun/2026:07:05:03 -0500] "GET /wp-login.php HTTP/1.1" 200 4719 "-" "Mozilla/5. ...
show more
101.99.79.250 - - [02/Jun/2026:07:05:03 -0500] "GET /wp-login.php HTTP/1.1" 200 4719 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
101.99.79.250 - - [02/Jun/2026:07:05:04 -0500] "POST /wp-login.php HTTP/1.1" 200 2533 "https://www.tatpl-traffic.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
101.99.79.250 - - [02/Jun/2026:08:31:00 -0500] "GET /wp-login.php HTTP/1.1" 200 4720 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
101.99.79.250 - - [02/Jun/2026:08:31:01 -0500] "GET /wp-login.php HTTP/1.1" 200 4720 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
101.99.79.250 - - [02/Jun/2026:08:31:01 -0500] "POST /wp-login.php HTTP/1.1" 200 2533 "https://www.tatpl-traffic.com/wp-login.php" "Mozilla/5.0 (W
...
show less
Web App Attack
๐ซ๐ท
LRob.fr
2026-06-02 13:30:03
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ฉ๐ช
Marc
2026-06-02 12:37:31
(1 day ago)
101.99.79.250 - - [02/Jun/2026:12:00:05 +0200] "GET /wp-login.php HTTP/2.0" 200 3365 "-" "Mozilla/5. ...
show more
101.99.79.250 - - [02/Jun/2026:12:00:05 +0200] "GET /wp-login.php HTTP/2.0" 200 3365 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 101.99.79.250 - - [02/Jun/2026:12:00:05 +0200] "POST /wp-login.php HTTP/2.0" 403 10679 "https://kurse.tortenatelier-schwanbeck.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 101.99.79.250 - - [02/Jun/2026:14:27:26 +0200] "GET /wp-login.php HTTP/2.0" 200 3979 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0" 101.99.79.250 - - [02/Jun/2026:14:27:28 +0200] "POST /wp-login.php HTTP/2.0" 403 11169 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0" 101.99.79.250 - - [02/Jun/2026:14:37:30 +0200] "GET /wp-login.php HTTP/2.0" 200 3863 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
show less
Brute-Force
Web App Attack
๐บ๐ธ
mind5t0rm
2026-06-02 12:30:23
(1 day ago)
(WPLOGIN) WP Login Attack 101.99.79.250 (MY/Malaysia/server1.kamon.la): 3 in the last 3600 secs; Por ...
show more
(WPLOGIN) WP Login Attack 101.99.79.250 (MY/Malaysia/server1.kamon.la): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 101.99.79.250 - - [02/Jun/2026:18:49:27 +0700] "GET /wp-login.php HTTP/2.0" 200 3163 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
101.99.79.250 - - [02/Jun/2026:18:49:30 +0700] "POST /wp-login.php HTTP/2.0" 200 4114 "https://thevasilis.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
101.99.79.250 - - [02/Jun/2026:19:30:20 +0700] "GET /wp-login.php HTTP/2.0" 200 2343 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
show less
Port Scan
๐จ๐ฆ
KIsmay
2026-06-02 12:21:34
(1 day ago)
Jun 2 04:52:38 www4 WPAudit[365111]: 101.99.79.250 www.katharinedickerson.com "Mozilla/5.0 (Windows ...
show more
Jun 2 04:52:38 www4 WPAudit[365111]: 101.99.79.250 www.katharinedickerson.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:Katharinedickerson12 FAIL
Jun 2 06:40:46 www4 WPAudit[373500]: 101.99.79.250 www.katharinedickerson.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0" sbd-admin:com2018 FAIL
Jun 2 07:08:11 www4 WPAudit[375278]: 101.99.79.250 www.katharinedickerson.com "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0" katharine:com2022 FAIL
Jun 2 08:11:28 www4 WPAudit[375776]: 101.99.79.250 servicesfyi.ca "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" jody:servicesfyi17 FAIL
Jun 2 08:21:34 www4 WPAudit[366522]: 101.99.79.250 valhallasafety.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15" sbd-admin:valhall
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-06-02 12:11:04
(1 day ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ฉ๐ช
Prodscape
2026-06-02 10:40:09
(1 day ago)
(WPLOGIN) WP Login Attack 101.99.79.250 (MY/Malaysia/server1.kamon.la): 5 in the last 86400 secs; Po ...
show more
(WPLOGIN) WP Login Attack 101.99.79.250 (MY/Malaysia/server1.kamon.la): 5 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER
show less
Port Scan
๐บ๐ธ
mind5t0rm
2026-06-02 09:43:02
(1 day ago)
(WPLOGIN) WP Login Attack 101.99.79.250 (MY/Malaysia/server1.kamon.la): 3 in the last 3600 secs; Por ...
show more
(WPLOGIN) WP Login Attack 101.99.79.250 (MY/Malaysia/server1.kamon.la): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 101.99.79.250 - - [02/Jun/2026:16:05:40 +0700] "GET /wp-login.php HTTP/2.0" 200 2757 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
101.99.79.250 - - [02/Jun/2026:16:05:45 +0700] "POST /wp-login.php HTTP/2.0" 200 2924 "https://greekthai.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
101.99.79.250 - - [02/Jun/2026:16:43:00 +0700] "GET /wp-login.php HTTP/2.0" 200 3163 "-" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Port Scan
๐ฉ๐ช
bsoft.de
2026-06-02 08:56:53
(2 days ago)
101.99.79.250 - - [02/Jun/2026:07:24:19 +0200] "GET /wp-login.php HTTP/1.1" 404 70028 "https://b-kit ...
show more
101.99.79.250 - - [02/Jun/2026:07:24:19 +0200] "GET /wp-login.php HTTP/1.1" 404 70028 "https://b-kits.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
101.99.79.250 - - [02/Jun/2026:10:56:49 +0200] "GET /wp-login.php HTTP/1.1" 200 2976 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
101.99.79.250 - - [02/Jun/2026:10:56:51 +0200] "POST /wp-login.php HTTP/1.1" 200 3135 "https://kgsjw-freunde.de/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
show less
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-06-02 08:13:25
(2 days ago)
Malware host detected by rbl.malware.expert. RBL lookup of 250.79.99.101.rbl.malware.expert succeede ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 250.79.99.101.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-mnz6-3)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-02 07:06:35
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 101.99.79.250 (server1.kamon.la): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 101.99.79.250 (server1.kamon.la): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 03:06:28.595753 2026] [security2:error] [pid 18976:tid 18976] [client 101.99.79.250:59428] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||johncyphers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "johncyphers.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ah6A9OjL5y3Ku9LFc8tDkAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ctidrv
2026-06-02 07:04:47
(2 days ago)
Honeypot detection. Threat score: 70/100. Collector: honeypot. | Request: GET /wp-json/oembed/1.0/em ...
show more
Honeypot detection. Threat score: 70/100. Collector: honeypot. | Request: GET /wp-json/oembed/1.0/embed?url=https%3A%2F%2Fsaunacom.com&format=json | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36 | rDNS: server1.kamon.la | Attacks detected: rfi, open_redirect | Reasons: no_cookies, attack:rfi, attack:open_redirect
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-02 06:38:36
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 101.99.79.250 (server1.kamon.la): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 101.99.79.250 (server1.kamon.la): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 02:38:30.002594 2026] [security2:error] [pid 29867:tid 29867] [client 101.99.79.250:37970] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arsenalfordemocracy.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ah56ZRS6Wvj9yJsCFCqnAgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
AWW-Admin
2026-06-02 06:17:57
(2 days ago)
(wordpress) Failed wordpress login from 101.99.79.250 (MY/Malaysia/server1.kamon.la)
Brute-Force