๐บ๐ธ
TPI-Abuse
2026-06-01 20:09:00
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 101.99.79.250 (server1.kamon.la): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 101.99.79.250 (server1.kamon.la): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 16:08:55.560530 2026] [security2:error] [pid 26411:tid 26411] [client 101.99.79.250:49606] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||persnicketyinc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "persnicketyinc.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ah3m19tXOu9wr_cLnSkgCAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marc
2026-06-01 19:46:49
(2 days ago)
101.99.79.250 - - [01/Jun/2026:19:37:26 +0200] "GET /wp-login.php HTTP/2.0" 200 3863 "-" "Mozilla/5. ...
show more
101.99.79.250 - - [01/Jun/2026:19:37:26 +0200] "GET /wp-login.php HTTP/2.0" 200 3863 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 101.99.79.250 - - [01/Jun/2026:19:37:26 +0200] "POST /wp-login.php HTTP/2.0" 200 4617 "https://www.bente-personaldienstleistung.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 101.99.79.250 - - [01/Jun/2026:21:06:47 +0200] "GET /wp-login.php HTTP/2.0" 200 3224 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 101.99.79.250 - - [01/Jun/2026:21:06:48 +0200] "POST /wp-login.php HTTP/2.0" 200 3238 "https://fachanwaelte-iserlohn.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 101.99.79.250 - - [01/Jun/2026:21:46:47 +0200] "GET /wp-login.php HTTP/2.0" 200 3978 "-" "Mozilla/5.0 (Windows
show less
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-06-01 19:18:18
(2 days ago)
101.99.79.250 - - [02/Jun/2026:03:10:46 +0800] "POST /wp-login.php HTTP/1.1" 200 2707 "https://littl ...
show more
101.99.79.250 - - [02/Jun/2026:03:10:46 +0800] "POST /wp-login.php HTTP/1.1" 200 2707 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
101.99.79.250 - - [02/Jun/2026:03:16:26 +0800] "POST /wp-login.php HTTP/1.1" 200 2679 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
101.99.79.250 - - [02/Jun/2026:03:18:17 +0800] "POST /wp-login.php HTTP/1.1" 200 2677 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-06-01 19:16:33
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
F242
2026-06-01 18:44:04
(2 days ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐ฉ๐ช
nyt
2026-06-01 18:43:38
(2 days ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
๐ต๐พ
SecOpsSL
2026-06-01 18:36:39
(2 days ago)
101.99.79.250 - - [01/Jun/2026:14:39:39 -0300] "POST /wp-login.php HTTP/1.1" 200 3119 "https://www.u ...
show more
101.99.79.250 - - [01/Jun/2026:14:39:39 -0300] "POST /wp-login.php HTTP/1.1" 200 3119 "https://www.ucmb.edu.py/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
101.99.79.250 - - [01/Jun/2026:14:51:33 -0300] "POST /wp-login.php HTTP/1.1" 200 3119 "https://ucmb.edu.py/wp-login.php" "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
101.99.79.250 - - [01/Jun/2026:15:36:38 -0300] "POST /wp-login.php HTTP/1.1" 200 3119 "https://ucmb.edu.py/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ฒ๐น
Malta
2026-06-01 18:11:47
(2 days ago)
101.99.79.250 - - [01/Jun/2026:20:11:47 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows N ...
show more
101.99.79.250 - - [01/Jun/2026:20:11:47 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐ซ๐ท
solution.it
2026-06-01 18:05:50
(2 days ago)
[Mon Jun 01 20:05:49.611242 2026] [php7:error] [pid 267557:tid 267557] [client 101.99.79.250:59324] ...
show more
[Mon Jun 01 20:05:49.611242 2026] [php7:error] [pid 267557:tid 267557] [client 101.99.79.250:59324] script '/var/www/html/blog.solution.it/wp-login.php' not found or unable to stat
show less
Web App Attack
๐บ๐ธ
mnsf
2026-06-01 18:05:43
(2 days ago)
Login Too Frequent (7)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 18:04:54
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 101.99.79.250 (server1.kamon.la): 1 in the last ...
show more
(mod_security) mod_security (id:225170) triggered by 101.99.79.250 (server1.kamon.la): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 14:04:46.640578 2026] [security2:error] [pid 30030:tid 30030] [client 101.99.79.250:54496] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.avaliantlife.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ah3JvupA3Qyyy-QJksKT1QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-01 17:51:16
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
BlueWire Hosting
2026-06-01 17:41:02
(2 days ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐บ๐ธ
TAY
2026-06-01 17:38:30
(2 days ago)
101.99.79.250 - - [02/Jun/2026:01:31:58 +0800] "POST /wp-login.php HTTP/1.1" 200 2676 "https://littl ...
show more
101.99.79.250 - - [02/Jun/2026:01:31:58 +0800] "POST /wp-login.php HTTP/1.1" 200 2676 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
101.99.79.250 - - [02/Jun/2026:01:33:01 +0800] "POST /wp-login.php HTTP/1.1" 200 2679 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
101.99.79.250 - - [02/Jun/2026:01:38:29 +0800] "POST /wp-login.php HTTP/1.1" 200 2677 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐ฉ๐ช
Lino Project
2026-06-01 17:33:31
(2 days ago)
101.99.79.250 - - [01/Jun/2026:19:33:27 +0200] "GET /wp-login.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 ...
show more
101.99.79.250 - - [01/Jun/2026:19:33:27 +0200] "GET /wp-login.php HTTP/2.0" 403 285 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack