π«π·
dynamix
2026-06-20 20:13:16
(4 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-06-20 13:32:01
(11 hours ago)
Blocked by CSF 13 firewall - Rule: WPLOGIN
CN/China/-
Web App Attack
π§π·
Peregrine
2026-06-19 22:17:03
(1 day ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 142.111.152.171 172.71.167.50 - - [19/Jun/2026:19:1 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 142.111.152.171 172.71.167.50 - - [19/Jun/2026:19:16:54 -0300] "GET /wp-login.php HTTP/1.1" 404 18193
show less
Bad Web Bot
πΊπΈ
lostswordfish.com
2026-06-17 15:20:13
(3 days ago)
Wordfence waf block on parsol
Web App Attack
πΊπΈ
Charlesiv
2026-06-12 10:00:47
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 212238 (Datacamp Limited ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 212238 (Datacamp Limited)
Protocol: HTTP/1.1 (GET method)
Endpoint: /wp-content/themes/service-finder/admin/
Timestamp: 2026-06-12T08:19:30Z
Ray ID: a0a76e5258a8e530
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:74.0) Gecko/20100101 Firefox/74.0
show less
Bad Web Bot
π¬π§
consul.to
2026-06-12 07:24:20
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
πΊπ¦
URAN Publishing Service
2026-06-12 04:28:00
(1 week ago)
142.111.152.171 - - [12/Jun/2026:07:27:58 +0300] "GET /wp-admin/function.php HTTP/1.1" 404 705 "-" " ...
show more
142.111.152.171 - - [12/Jun/2026:07:27:58 +0300] "GET /wp-admin/function.php HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
142.111.152.171 - - [12/Jun/2026:07:27:59 +0300] "GET /wp-admin/js/wp-login.php HTTP/1.1" 404 705 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:79.0) Gecko/20100101 Firefox/79.0"
...
show less
Web App Attack
Anonymous
2026-06-12 02:35:55
(1 week ago)
142.111.152.171 - - [12/Jun/2026:04:35:31 +0200] "GET /wp-includes/sodium_compat/ HTTP/1.1" 404 500 ...
show more
142.111.152.171 - - [12/Jun/2026:04:35:31 +0200] "GET /wp-includes/sodium_compat/ HTTP/1.1" 404 500 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36"
142.111.152.171 - - [12/Jun/2026:04:35:31 +0200] "GET /wp-includes/js/dist/ HTTP/1.1" 404 500 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36"
142.111.152.171 - - [12/Jun/2026:04:35:32 +0200] "GET /wp-includes/sodium_compat/src/ HTTP/1.1" 404 500 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36"
142.111.152.171 - - [12/Jun/2026:04:35:32 +0200] "GET /wp-content/plugins/erinyani/ HTTP/1.1" 404 500 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/69.0.3497.100 Safari/537.36"
142.111.152.171 - - [12/Jun/2026:04:35:32 +0200] "GET /wp-includes/SimplePie/Parse/ HTTP/1.1" 404 500 "-" "
...
show less
DDoS Attack
π©πͺ
LRob.fr
2026-06-09 14:15:12
(1 week ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
π¨π
filou812
2026-06-09 06:12:36
(1 week ago)
url tried is "/wp-login.php"
Web App Attack
πΊπΈ
Starburst SysOp Team
2026-06-08 17:13:43
(1 week ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-mnz6-1)
Hacking
Bad Web Bot
ππΊ
bcsaba
2026-04-13 19:52:15
(2 months ago)
CMS (WordPress or Joomla) login attempt.
142.111.152.171 - - [13/Apr/2026:21:52:12 +0200] "POST /wp- ...
show more
CMS (WordPress or Joomla) login attempt.
142.111.152.171 - - [13/Apr/2026:21:52:12 +0200] "POST /wp-login.php HTTP/1.1" 200 11414 "-" "Mozilla/5.0"
show less
Hacking
Brute-Force
Web App Attack
ππΊ
bcsaba
2026-04-13 06:38:00
(2 months ago)
CMS (WordPress or Joomla) login attempt.
142.111.152.171 - - [13/Apr/2026:08:37:58 +0200] "POST /wp- ...
show more
CMS (WordPress or Joomla) login attempt.
142.111.152.171 - - [13/Apr/2026:08:37:58 +0200] "POST /wp-login.php HTTP/1.1" 200 11414 "-" "Mozilla/5.0"
show less
Hacking
Brute-Force
Web App Attack
π¦πΊ
oncord
2026-04-02 01:54:36
(2 months ago)
Form spam
Web Spam
π«π·
Octopuce
2026-03-03 19:09:01
(3 months ago)
Aggressive web search of vulnerable pages: /wp-includes/ID3/wp-work.php /alfa.php /wp-admin/css/colo ...
show more
Aggressive web search of vulnerable pages: /wp-includes/ID3/wp-work.php /alfa.php /wp-admin/css/colors/blue/admin.php /wp-includes/click.php /. ...
show less
Web App Attack