π©πͺ
tentwentyfour
2026-10-08 10:59:09
(18 hours ago)
Blocked for brute-forcing WordPress log-in
Brute-Force
Web App Attack
π³π±
Alt255
2026-10-08 10:56:17
(18 hours ago)
[ti-01sc] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpr ...
show more
[ti-01sc] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpress. Example: 135.136.22.229 - - [08/Oct/2026:12:55:39 +0200] "POST /wp-login.php HTTP/1.1" 200 10322 "https://www.nieuwsvoordietisten.nl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
135.136.22.229 - - [08/Oct/2026:12:55:56 +0200] "POST /wp-login.php HTTP/1.1" 200 4978 "https://www.nieuwsvoordietisten.nl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:120.0) Gecko/20100101 Firefox/120.0"
135.136.22.229 - - [08/Oct/2026:12:56:05 +0200] "POST /wp-login.php HTTP/1.1" 200 4978 "https://www.nieuwsvoordietisten.nl/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/1
...
show less
Brute-Force
Web App Attack
π³π±
Site.eu
2026-10-08 08:47:51
(20 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
π³π±
debestelapp
2026-10-08 08:25:02
(21 hours ago)
Exploited Host
πΊπΈ
TPI-Abuse
2026-10-08 08:24:39
(21 hours ago)
(mod_security) mod_security (id:225170) triggered by 135.136.22.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 135.136.22.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 04:24:35.884747 2026] [security2:error] [pid 2046:tid 2176] [client 135.136.22.229:65061] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ward-bergerhouse.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ward-bergerhouse.org"] [uri "/wp-json/wp/v2/users"] [unique_id "asdTQ0MrXa9GWWo1yvmoRwAAARI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
neckaralb-admin.de
2026-10-08 06:36:10
(22 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 06:35:50
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 135.136.22.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 135.136.22.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:35:46.303537 2026] [security2:error] [pid 31288:tid 31288] [client 135.136.22.229:61639] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tcit.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tcit.org"] [uri "/wp-json/wp/v2/users"] [unique_id "asc5wvKjkjn6ZrJ7IraQnAAAAAM"], referer: https://www.bing.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 06:02:29
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 135.136.22.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 135.136.22.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:02:23.411919 2026] [security2:error] [pid 13139:tid 13139] [client 135.136.22.229:54033] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wpcoc.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wpcoc.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ascx74bDxAVCAB8ZFM44rQAAABE"], referer: https://www.google.com/search?q=wordpress
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
SpaceHost-Server
2026-10-07 22:15:23
(1 day ago)
Brute-Force
Web App Attack
π©πͺ
Prepaid-Host.com
2026-10-07 08:17:53
(1 day ago)
Web Exploit: 1 event(s), last 2026-10-07 08:17 UTC
135.136.22.229 - - [07/Oct/2026:10:17:39 +0200] " ...
show more
Web Exploit: 1 event(s), last 2026-10-07 08:17 UTC
135.136.22.229 - - [07/Oct/2026:10:17:39 +0200] "GET /wp-admin/index.php HTTP/1.1" 302 5715 "https://[site]/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:121.0) Gecko/20100101 Firefox/121.0"
135.136.22.229 - - [07/Oct/2026:10:17:41 +0200] "GET /wp-login.php?redirect_to=https%3A%2F%[domain]%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 11473 "https://[site]/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:121.0)
135.136.22.229 - - [07/Oct/2026:10:17:41 +0200] "POST /wp-login.php HTTP/1.1" 200 9588 "https://[site]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:118.0) Gecko/20100101 Firefox/118.0"
show less
Brute-Force
Web App Attack
π¨π¦
DRI
2026-10-07 06:28:39
(1 day ago)
Web attack/Malicious activity detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 03:33:17
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 135.136.22.229 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 135.136.22.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 23:33:11.551193 2026] [security2:error] [pid 11914:tid 11914] [client 135.136.22.229:56006] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.amywoodruff.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.amywoodruff.com"] [uri "/wp-json/wp/v2/users"] [unique_id "asW9dx7HiGJg0wRUTDGAaQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
taivas.nl
2026-10-07 03:02:09
(2 days ago)
Bad_requests
Bad Web Bot
π©πͺ
palzer.IT
2026-10-07 02:51:37
(2 days ago)
Fail2ban automatic report for plesk-wordpress: 135.136.22.229 - - [07/Oct/2026:04:51:02 +0200] POST ...
show more
Fail2ban automatic report for plesk-wordpress: 135.136.22.229 - - [07/Oct/2026:04:51:02 +0200] POST /wp-login.php [DOMAIN_REMOVED] 200 9841 [DOMAIN_REMOVED] Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.1 Safari/605.1.15 135.136.22.229 - - [07/Oct/2026:04:51:04 +0200] POST /wp-login.php [DOMAIN_REMOVED] 200 9861 [DOMAIN_REMOVED] Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36 135.136.22.229 - - [07/Oct/2026:04:51:06 +0200] POST /wp-login.php [DOMAIN_REMOVED] 200 9861 [DOMAIN_REMOVED] Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FD-IX
2026-10-07 02:49:58
(2 days ago)
Fail2Ban: WordPress brute-force attack detected.
Bad Web Bot
Web App Attack