๐ง๐ช
Saec
2026-06-12 17:15:03
(5 days ago)
Jarvis auto-ban: CF honeypot path /wp-login.php (1ร on saec.me)
Port Scan
Web App Attack
๐จ๐ฆ
electronico
2026-06-12 16:06:20
(5 days ago)
136.144.19.94 - - [13/Jun/2026:03:06:16 +1100] "POST /wp-login.php HTTP/1.1" 403 5922 "http://cttmd. ...
show more
136.144.19.94 - - [13/Jun/2026:03:06:16 +1100] "POST /wp-login.php HTTP/1.1" 403 5922 "http://cttmd.nc/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36"
136.144.19.94 - - [13/Jun/2026:03:06:16 +1100] "GET /wp-admin/ HTTP/1.1" 302 443 "http://cttmd.nc/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36"
136.144.19.94 - - [13/Jun/2026:03:06:19 +1100] "POST /wp-login.php HTTP/1.1" 403 5922 "https://cttmd.nc/wp-admin/" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.85 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฆ๐บ
wysu
2026-04-21 04:30:00
(1 month ago)
Observed malicious scanning and brute-force activity from 136.144.19.94
Brute-Force
Hacking
๐ฌ๐ง
blik2108
2026-01-22 16:09:32
(4 months ago)
blog.blacknellsatsea.co.uk:443 136.144.19.94 - - [22/Jan/2026:16:09:30 +0000] "POST //wp-login.php H ...
show more
blog.blacknellsatsea.co.uk:443 136.144.19.94 - - [22/Jan/2026:16:09:30 +0000] "POST //wp-login.php HTTP/1.1" 200 14501 "https://blog.blacknellsatsea.co.uk//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
blog.blacknellsatsea.co.uk:443 136.144.19.94 - - [22/Jan/2026:16:09:31 +0000] "POST //wp-login.php HTTP/1.1" 200 11395 "https://blog.blacknellsatsea.co.uk//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
blog.blacknellsatsea.co.uk:443 136.144.19.94 - - [22/Jan/2026:16:09:31 +0000] "POST //wp-login.php HTTP/1.1" 200 11397 "https://blog.blacknellsatsea.co.uk//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
blog.blacknellsatsea.co.uk:443 136.144.19.94 - - [22/Jan/2026:16:09:31 +0000] "POST //wp-login.php HTTP/1.1" 200 11395 "https://blog.blackn
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
LRob.fr
2026-01-22 14:50:19
(4 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-01-22 05:30:50
(4 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /feed/ (Rule ID: 920170) - GET or HEAD Request with Body Content
show less
Web App Attack
๐ช๐ธ
masterguru
2026-01-22 04:42:18
(4 months ago)
(xmlrpc) Failed xmlrpc access from 136.144.19.94 (US/United States/-): 5 in the last 3600 secs (0-12 ...
show more
(xmlrpc) Failed xmlrpc access from 136.144.19.94 (US/United States/-): 5 in the last 3600 secs (0-122)
show less
Hacking
Anonymous
2026-01-22 04:29:27
(4 months ago)
wordpress-trap
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-01-21 23:31:12
(4 months ago)
Brute-Force
Web App Attack
Anonymous
2026-01-21 19:14:25
(4 months ago)
Excessive request and web scraping
Bad Web Bot
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-01-21 18:36:47
(4 months ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/-
Web App Attack
๐ซ๐ฎ
Rexikon
2026-01-21 16:05:18
(4 months ago)
136.144.19.94 - - [21/Jan/2026:17:05:15 +0100] "POST //wp-login.php HTTP/1.0" 200 14194 "https://ani ...
show more
136.144.19.94 - - [21/Jan/2026:17:05:15 +0100] "POST //wp-login.php HTTP/1.0" 200 14194 "https://anitra.pl//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.144.19.94 - - [21/Jan/2026:17:05:15 +0100] "POST //wp-login.php HTTP/1.0" 200 14194 "https://anitra.pl//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.144.19.94 - - [21/Jan/2026:17:05:16 +0100] "POST //wp-login.php HTTP/1.0" 200 14194 "https://anitra.pl//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.144.19.94 - - [21/Jan/2026:17:05:16 +0100] "POST //wp-login.php HTTP/1.0" 200 14194 "https://anitra.pl//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.144.19.94 - - [21/Jan/2026:17:05:17 +010
...
show less
Brute-Force
๐ณ๐ฑ
Savvii
2026-01-21 10:51:32
(4 months ago)
10 attempts against mh-misc-ban on frost
Web App Attack
๐บ๐ธ
Jason Howell
2026-01-21 08:40:04
(4 months ago)
136.144.19.94 - - [21/Jan/2026:02:40:03 -0600] "POST //wp-login.php HTTP/1.1" 200 8265 "https://abst ...
show more
136.144.19.94 - - [21/Jan/2026:02:40:03 -0600] "POST //wp-login.php HTTP/1.1" 200 8265 "https://abstractco.com//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.144.19.94 - - [21/Jan/2026:02:40:03 -0600] "POST //wp-login.php HTTP/1.1" 200 5883 "https://abstractco.com//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.144.19.94 - - [21/Jan/2026:02:40:04 -0600] "POST //wp-login.php HTTP/1.1" 200 5883 "https://abstractco.com//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.144.19.94 - - [21/Jan/2026:02:40:04 -0600] "POST //wp-login.php HTTP/1.1" 200 5883 "https://abstractco.com//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.144.19.94 - - [21/Jan/20
...
show less
Web App Attack
๐ซ๐ท
giulio gorobey
2026-01-21 02:44:10
(4 months ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-includes/id3/license.txt/feed
Web App Attack