🇩🇪
FeG Deutschland
2026-08-30 08:16:35
(20 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇵🇱
Budyn
2026-08-29 03:05:28
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: definitelynotahoneypot.xyz | URI: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇫🇷
tecnicorioja
2026-08-28 22:01:44
(2 days ago)
wp-login attack [28/Aug/2026:09:37:57
Brute-Force
Web App Attack
🇺🇸
ipblock.com
2026-08-28 13:19:00
(2 days ago)
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 02:41:56
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:41:29.569633 2026] [security2:error] [pid 14404:tid 14404] [client 136.144.42.157:22495] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.103"] [uri "/local/.env"] [unique_id "ao5SWVJ8Nohy0ioFYeNlhQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 02:25:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 136.144.42.157 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 136.144.42.157 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 22:25:16.453589 2026] [security2:error] [pid 14519:tid 14519] [client 136.144.42.157:47013] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.196"] [uri "/conf/.env"] [unique_id "aokIjFaQvzFoVaLwCE0iOQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-08-03 03:17:03
(4 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇮🇹
CoreTech srl
2026-07-31 16:09:46
(4 weeks ago)
[DC: IP:151.1.252.27] ntopng alert: blacklisted_server_contact,ndpi_suspicious_entropy
Hacking
🇩🇪
tall1oN
2026-07-29 19:24:43
(1 month ago)
136.144.42.157 - - [29/Jul/2026:21:24:38 +0200] "POST /wp-login.php HTTP/2.0" 405 157 "-" "Mozilla/5 ...
show more
136.144.42.157 - - [29/Jul/2026:21:24:38 +0200] "POST /wp-login.php HTTP/2.0" 405 157 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15" "exatek.de"
136.144.42.157 - - [29/Jul/2026:21:24:38 +0200] "POST /wp-login.php HTTP/2.0" 405 559 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/123.0.0.0 Safari/537.36" "exatek.de"
...
show less
Web App Attack
Port Scan
Hacking
🇫🇮
dcomsystems
2026-07-29 17:42:30
(1 month ago)
136.144.42.157 - - [29/Jul/2026:19:42:29 +0200] "POST /wp-login.php HTTP/1.1" 200 4615 "-" "Mozilla/ ...
show more
136.144.42.157 - - [29/Jul/2026:19:42:29 +0200] "POST /wp-login.php HTTP/1.1" 200 4615 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:125.0) Gecko/20100101 Firefox/125.0"
136.144.42.157 - - [29/Jul/2026:19:42:29 +0200] "POST /wp-login.php HTTP/1.1" 200 4615 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:125.0) Gecko/20100101 Firefox/125.0"
136.144.42.157 - - [29/Jul/2026:19:42:29 +0200] "POST /wp-login.php HTTP/1.1" 200 520 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_3) AppleWebKit/601.4.4 (KHTML, like Gecko) Version/9.0.3 Safari/601.4.4"
136.144.42.157 - - [29/Jul/2026:19:42:29 +0200] "POST /wp-login.php HTTP/1.1" 200 520 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_3) AppleWebKit/601.4.4 (KHTML, like Gecko) Version/9.0.3 Safari/601.4.4"
136.144.42.157 - - [29/Jul/2026:19:42:29 +0200] "POST /wp-login.php HTTP/1.1" 200 520 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; MAARJS; rv:11.0) like Gecko"
...
show less
Brute-Force
Web App Attack
🇲🇹
Malta
2026-07-29 13:36:30
(1 month ago)
136.144.42.157 - - [29/Jul/2026:15:36:30 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (X11; Linux ...
show more
136.144.42.157 - - [29/Jul/2026:15:36:30 +0200] "POST /xmlrpc.php HTTP/1.1" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
🇫🇮
YF
2026-07-29 13:00:36
(1 month ago)
WordPress author enumeration
Web App Attack
🇫🇷
masterguru
2026-07-29 11:55:34
(1 month ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (88020-201)
Hacking
🇩🇪
FD-IX
2026-07-29 08:20:33
(1 month ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
🇺🇸
integrantservices.com
2026-07-29 07:27:17
(1 month ago)
(wordpress) Failed wordpress login from 136.144.42.157 (US/United States/-)
Brute-Force