🇬🇧
Apache
2026-09-09 07:43:46
(9 hours ago)
(wplogin) WordPress login brute-force 136.144.17.52 (CA/Canada/-): 5 in the last 300 secs
Brute-Force
🇨🇦
KIsmay
2026-09-09 07:02:28
(10 hours ago)
Sep 9 03:01:59 www4 WPAudit[3477137]: 136.144.17.52 lemoncreekcampground.ca "Mozilla/5.0 (Macintosh ...
show more
Sep 9 03:01:59 www4 WPAudit[3477137]: 136.144.17.52 lemoncreekcampground.ca "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.71 Safari/537.36" itadmin:Xo*9PQcmcAN0 FAIL
Sep 9 03:02:06 www4 WPAudit[3476754]: 136.144.17.52 lemoncreekcampground.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Safari/605.1.15" [email protected] :u6j#QBWsBPE64i8!h FAIL
Sep 9 03:02:14 www4 WPAudit[3477137]: 136.144.17.52 lemoncreekcampground.ca "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Safari/605.1.15" carefored_adm:LetGin0@#$4123 FAIL
Sep 9 03:02:21 www4 WPAudit[3476754]: 136.144.17.52 lemoncreekcampground.ca "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.71 Safari/537.36" admin:Letmein00#g FAIL
Sep 9 03:02:28 www4 WPAudit[3477137]: 136.144.17.52 lemoncreekcampground.ca
...
show less
Brute-Force
Web App Attack
🇫🇷
Sysadmin Peter
2026-09-09 06:15:33
(11 hours ago)
136.144.17.52 - - [09/Sep/2026:08:15:29 +0200] "POST /wp-login.php HTTP/1.1" 200 11137 "https://ja-s ...
show more
136.144.17.52 - - [09/Sep/2026:08:15:29 +0200] "POST /wp-login.php HTTP/1.1" 200 11137 "https://ja-solar.nz/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:90.0) Gecko/20100101 Firefox/90.0.1"
136.144.17.52 - - [09/Sep/2026:08:15:33 +0200] "POST /wp-login.php HTTP/1.1" 200 11265 "https://ja-solar.nz/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:90.0) Gecko/20100101 Firefox/90.0.1"
...
show less
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-09 03:15:03
(14 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-09 01:50:53
(15 hours ago)
(wordpress) Apache: Failed WordPress login from 136.144.17.52 (CA/Canada/-): 10 in the last 3600 sec ...
show more
(wordpress) Apache: Failed WordPress login from 136.144.17.52 (CA/Canada/-): 10 in the last 3600 secs (0-196)
show less
Hacking
🇫🇷
masterguru
2026-09-09 00:56:46
(16 hours ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (88020-197)
Hacking
🇫🇷
SpaceHost-Server
2026-09-08 22:15:08
(19 hours ago)
Brute-Force
Web App Attack
🇩🇪
FD-IX
2026-09-08 21:39:13
(19 hours ago)
Fail2Ban: WordPress brute-force attack detected.
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-06-20 13:58:08
(2 months ago)
136.144.17.52 - - [20/Jun/2026:16:58:07 +0300] "GET /wp-includes/ID3/index.php HTTP/1.1" 404 4680 "h ...
show more
136.144.17.52 - - [20/Jun/2026:16:58:07 +0300] "GET /wp-includes/ID3/index.php HTTP/1.1" 404 4680 "http://pharmed.zsmu.edu.ua/wp-includes/ID3/index.php" "Go-http-client/1.1"
136.144.17.52 - - [20/Jun/2026:16:58:07 +0300] "GET /wp-includes/js/index.php HTTP/1.1" 404 733 "http://pharmed.zsmu.edu.ua/wp-includes/js/index.php" "Go-http-client/1.1"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-05-13 23:32:28
(3 months ago)
(mod_security) mod_security (id:240000) triggered by 136.144.17.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 136.144.17.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 19:32:23.839332 2026] [security2:error] [pid 23927:tid 23927] [client 136.144.17.52:39097] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||traditionalamericanvaluesbooks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "traditionalamericanvaluesbooks.com"] [uri "/images/stories/themes.php"] [unique_id "agUKBzNUflICbLpQ9xR9UQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-13 21:47:08
(3 months ago)
(mod_security) mod_security (id:240000) triggered by 136.144.17.52 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 136.144.17.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 17:47:01.697444 2026] [security2:error] [pid 28385:tid 28385] [client 136.144.17.52:56617] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||healthycaregiving.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "healthycaregiving.com"] [uri "/images/stories/themes.php"] [unique_id "agTxVRVmmaPQ-5gnamQ3nQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-05-12 23:05:24
(3 months ago)
Request Overload (239)
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-05-12 01:44:38
(3 months ago)
Excessive 404/403 errors
Brute-Force
🇫🇷
masterguru
2026-05-11 11:30:53
(3 months ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 136.144.17.52 (CA/Canada/-): 1 in the ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 136.144.17.52 (CA/Canada/-): 1 in the last 3600 secs (0-195)
show less
Hacking
🇺🇸
mnsf
2026-05-11 08:05:45
(3 months ago)
Request Overload (120)
Brute-Force
Web App Attack