๐บ๐ธ
xxkodedxx
2026-06-04 16:13:13
(3 hours ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get in 10m window.
Active: 16:12:57โ16:12:59 UTC
Volume: 2 honeypot probe(s)
Bait taken: /wp-login.php
UA: "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐ฒ๐น
Malta
2026-06-04 07:46:57
(12 hours ago)
103.78.97.230 - - [04/Jun/2026:09:46:56 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Linu ...
show more
103.78.97.230 - - [04/Jun/2026:09:46:56 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
๐ฉ๐ช
Martin Lundstrom
2026-06-04 03:40:13
(16 hours ago)
https://www.eagleeye-intelligence.com โ WordPress attack. Automatically detected and blocked.
Web App Attack
๐บ๐ธ
omc
2026-06-03 02:50:26
(1 day ago)
Banned IP [Q%]. GET /wp-json/bbp-api/v1/users [Q4].
Bad Web Bot
Anonymous
2026-06-03 02:30:09
(1 day ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-06-03 01:16:43
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 01:04:11
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 103.78.97.230 (ip-103-78-97-230.moratelindo.net ...
show more
(mod_security) mod_security (id:225170) triggered by 103.78.97.230 (ip-103-78-97-230.moratelindo.net.id): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 21:04:06.060245 2026] [security2:error] [pid 5078:tid 5078] [client 103.78.97.230:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.southernbroadcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.southernbroadcast.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah99hkz5mCWtevVdFmH3LgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-02 19:30:09
(2 days ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐ฎ๐น
eliosbrocchi
2026-06-02 19:27:17
(2 days ago)
2026-06-02T21:27:15.341203+02:00 thunderchild wordpress(vocidallapiazzaliberta.ddns.net)[848239]: Im ...
show more
2026-06-02T21:27:15.341203+02:00 thunderchild wordpress(vocidallapiazzaliberta.ddns.net)[848239]: Immediately block connections from 103.78.97.230
...
show less
VPN IP
๐ฉ๐ช
london2038.com
2026-06-02 14:46:46
(2 days ago)
Attacking WordPress
103.78.97.230 - - [02/Jun/2026:16:46:42 +0200] "POST /wp-login.php HTTP/2.0" 503 ...
show more
Attacking WordPress
103.78.97.230 - - [02/Jun/2026:16:46:42 +0200] "POST /wp-login.php HTTP/2.0" 503 19289 "https://<REDACTED>/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-02 13:16:33
(2 days ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.78.97.230 (ID/Indonesia/ip-103-78-97-230. ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 103.78.97.230 (ID/Indonesia/ip-103-78-97-230.moratelindo.net.id): 1 in the last 3600 secs (0-197)
show less
Hacking
๐ฉ๐ช
FeG Deutschland
2026-06-02 13:06:33
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฒ๐น
Malta
2026-06-02 06:29:01
(2 days ago)
103.78.97.230 - - [02/Jun/2026:08:29:01 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Linu ...
show more
103.78.97.230 - - [02/Jun/2026:08:29:01 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
show less
Hacking
Web App Attack
๐บ๐ธ
Victor Lรณpez
2026-06-02 05:26:11
(2 days ago)
valquintero.com.co 103.78.97.230 - - [02/Jun/2026:00:23:28 -0500] "GET /wp-login.php HTTP/1.1" 200 3 ...
show more
valquintero.com.co 103.78.97.230 - - [02/Jun/2026:00:23:28 -0500] "GET /wp-login.php HTTP/1.1" 200 3011 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
valquintero.com.co 103.78.97.230 - - [02/Jun/2026:00:23:29 -0500] "POST /wp-login.php HTTP/1.1" 200 3189 "https://valquintero.com.co/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
chispa.digitalhypepro.com 103.78.97.230 - - [02/Jun/2026:00:26:10 -0500] "GET /wp-login.php HTTP/2.0" 200 1860 "-" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ซ๐ท
solution.it
2026-06-02 01:29:04
(2 days ago)
[Tue Jun 02 03:29:04.255614 2026] [php7:error] [pid 319052:tid 319052] [client 103.78.97.230:31337] ...
show more
[Tue Jun 02 03:29:04.255614 2026] [php7:error] [pid 319052:tid 319052] [client 103.78.97.230:31337] script '/var/www/html/blog.solution.it/wp-login.php' not found or unable to stat
show less
Web App Attack