π¦πΉ
neo72
2026-06-13 14:52:20
(4 hours ago)
Detected malicious activity - bulk block
Brute-Force
Web App Attack
Anonymous
2026-06-13 14:22:31
(4 hours ago)
Web attack blocked by Wordfence on heemkundesjin.nl (1 hit). Reported by CRMON.
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-13 13:49:27
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 138.201.82.103 (mailserver.azbukari.org): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 138.201.82.103 (mailserver.azbukari.org): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 09:49:21.616617 2026] [security2:error] [pid 10766:tid 10766] [client 138.201.82.103:50614] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||riedmannfamily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "riedmannfamily.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ai1f4VVT7MkLht_iRkWrpQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
Origon
2026-06-13 13:45:26
(5 hours ago)
recidive - IP: 138.201.82.103 - 2026-06-13 14:01:05,205 fail2ban.actions [1068196]: NOTICE [plesk-w ...
show more
recidive - IP: 138.201.82.103 - 2026-06-13 14:01:05,205 fail2ban.actions [1068196]: NOTICE [plesk-wordpress] Ban 138.201.82.103 2026-06-13 14:45:01,469 fail2ban.actions [1068196]: NOTICE [plesk-wordpress] Ban 138.201.82.103 2026-06-13 15:45:25,695 fail2ban.actions [1068196]: NOTICE [plesk-wordpress] Ban 138.201.82.103
show less
Web App Attack
π©πͺ
todix
2026-06-13 13:29:59
(5 hours ago)
Wordpress brute force or spam attempt from 138.201.82.103
Brute-Force
π©πͺ
FeG Deutschland
2026-06-13 13:28:24
(5 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2457
Exploited Host
Web App Attack
π«π·
solution.it
2026-06-13 13:15:53
(5 hours ago)
[Sat Jun 13 15:15:52.742893 2026] [php7:error] [pid 3365241:tid 3365241] [client 138.201.82.103:4252 ...
show more
[Sat Jun 13 15:15:52.742893 2026] [php7:error] [pid 3365241:tid 3365241] [client 138.201.82.103:42526] script '/var/www/html/blog.solution.it/wp-login.php' not found or unable to stat
show less
Web App Attack
π³π±
juutis
2026-06-13 13:08:58
(5 hours ago)
138.201.82.103 - - [13/Jun/2026:14:02:06 +0200] "POST /wp-login.php HTTP/1.1" 200 9283 "https://taid ...
show more
138.201.82.103 - - [13/Jun/2026:14:02:06 +0200] "POST /wp-login.php HTTP/1.1" 200 9283 "https://taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
138.201.82.103 - - [13/Jun/2026:15:00:46 +0200] "POST /wp-login.php HTTP/1.1" 200 9299 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
138.201.82.103 - - [13/Jun/2026:15:08:57 +0200] "POST /wp-login.php HTTP/1.1" 200 9283 "https://taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Web App Attack
πΊπΈ
TAY
2026-06-13 13:08:29
(5 hours ago)
138.201.82.103 - - [13/Jun/2026:21:03:57 +0800] "POST /wp-login.php HTTP/1.1" 200 2677 "https://mail ...
show more
138.201.82.103 - - [13/Jun/2026:21:03:57 +0800] "POST /wp-login.php HTTP/1.1" 200 2677 "https://mail.littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_10) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
138.201.82.103 - - [13/Jun/2026:21:07:47 +0800] "POST /wp-login.php HTTP/1.1" 200 2674 "https://mail.littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
138.201.82.103 - - [13/Jun/2026:21:08:28 +0800] "POST /wp-login.php HTTP/1.1" 200 2676 "https://www.littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
...
show less
Brute-Force
πΊπΈ
cwytech
2026-06-13 13:04:34
(5 hours ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/wp-us-login-only-high.
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 12:50:13
(6 hours ago)
Attac
Brute-Force
π©πͺ
Prodscape
2026-06-13 12:47:19
(6 hours ago)
(WPLOGIN) WP Login Attack 138.201.82.103 (DE/Germany/mailserver.azbukari.org): 5 in the last 86400 s ...
show more
(WPLOGIN) WP Login Attack 138.201.82.103 (DE/Germany/mailserver.azbukari.org): 5 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER
show less
Port Scan
π¨πΏ
ptlab
2026-06-13 12:45:14
(6 hours ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
π¬π§
BRHosting
2026-06-13 12:44:02
(6 hours ago)
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack
π«π·
masterguru
2026-06-13 12:37:31
(6 hours ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 138.201.82.103 (DE/Germany/mailserver.azbukar ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 138.201.82.103 (DE/Germany/mailserver.azbukari.org): 1 in the last 3600 secs (0-195)
show less
Hacking