π²π½
octageeks.com
2026-06-10 04:51:40
(27 minutes ago)
Wordpress malicious attack:[octawp]
Web App Attack
π¨π¦
KIsmay
2026-06-10 04:44:12
(35 minutes ago)
Jun 9 21:56:09 www4 WPAudit[1193106]: 145.239.79.139 siscobc.com "Mozilla/5.0 (Macintosh; Intel Mac ...
show more
Jun 9 21:56:09 www4 WPAudit[1193106]: 145.239.79.139 siscobc.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_10) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:sbd-admin123@@ FAIL
Jun 9 23:00:58 www4 WPAudit[1202243]: 145.239.79.139 siscobc.com "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:sbd-admin@12 FAIL
Jun 9 23:05:45 www4 WPAudit[1202243]: 145.239.79.139 siscobc.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sisco:sisco91 FAIL
Jun 9 23:09:17 www4 WPAudit[1205367]: 145.239.79.139 hvrhaulers.com "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0" sbd-admin:sbd-admin1997 FAIL
Jun 10 00:44:11 www4 WPAudit[1206373]: 145.239.79.139 www.servicesfyi.ca "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" jody:jody
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-10 04:44:10
(35 minutes ago)
Attac
Brute-Force
π«π·
SpaceHost-Server
2026-06-10 04:36:53
(42 minutes ago)
145.239.79.139 - - [10/Jun/2026:06:34:58 +0200] "POST /wp-login.php HTTP/1.1" 200 14549 "https://aut ...
show more
145.239.79.139 - - [10/Jun/2026:06:34:58 +0200] "POST /wp-login.php HTTP/1.1" 200 14549 "https://auto-kraul.de/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
145.239.79.139 - - [10/Jun/2026:06:36:21 +0200] "POST /wp-login.php HTTP/1.1" 200 14294 "https://wethinking.org/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
145.239.79.139 - - [10/Jun/2026:06:36:50 +0200] "POST /xmlrpc.php HTTP/1.1" 200 4867 "-" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
πΊπΈ
TAY
2026-06-10 04:16:54
(1 hour ago)
145.239.79.139 - - [10/Jun/2026:12:09:35 +0800] "POST /wp-login.php HTTP/1.1" 200 2980 "https://mail ...
show more
145.239.79.139 - - [10/Jun/2026:12:09:35 +0800] "POST /wp-login.php HTTP/1.1" 200 2980 "https://mail.autism-cvc.org/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
145.239.79.139 - - [10/Jun/2026:12:13:21 +0800] "POST /xmlrpc.php HTTP/1.1" 200 6215 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
145.239.79.139 - - [10/Jun/2026:12:16:54 +0800] "POST /xmlrpc.php HTTP/1.1" 200 6279 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Brute-Force
π©πͺ
FeG Deutschland
2026-06-10 03:46:33
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π©πͺ
Hazzard
2026-06-10 03:45:42
(1 hour ago)
(PERMBLOCK) 145.239.79.139 (FR/France/-/-/139.ip-145-239-79.eu/[redacted]) has had more than 4 temp ...
show more
(PERMBLOCK) 145.239.79.139 (FR/France/-/-/139.ip-145-239-79.eu/[redacted]) has had more than 4 temp blocks
show less
Hacking
πΊπΈ
TPI-Abuse
2026-06-10 03:30:21
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 145.239.79.139 (139.ip-145-239-79.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 145.239.79.139 (139.ip-145-239-79.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 23:30:15.498872 2026] [security2:error] [pid 4627:tid 4627] [client 145.239.79.139:35378] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||exhaustthelimits.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "exhaustthelimits.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aijaRyNNF-Ihizkgpg2ETQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Mundo Bueno
2026-06-10 03:20:52
(1 hour ago)
[ISILIA Protection v2.1] Tentative d'accès: /xmlrpc.php | Pays: FR | UA: Mozilla/5.0 (Macintosh; Int ...
show more
[ISILIA Protection v2.1] Tentative d'accès: /xmlrpc.php | Pays: FR | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.
show less
Hacking
Web App Attack
πΊπΈ
factor1
2026-06-10 03:01:50
(2 hours ago)
Fail2ban at churndash Reports Abuse.
Brute-Force
Web App Attack
π«π·
Yepngo
2026-06-10 03:01:32
(2 hours ago)
145.239.79.139 - - [10/Jun/2026:05:01:31 +0200] "POST /xmlrpc.php HTTP/2.0" 200 408 "-" "Mozilla/5.0 ...
show more
145.239.79.139 - - [10/Jun/2026:05:01:31 +0200] "POST /xmlrpc.php HTTP/2.0" 200 408 "-" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
π³π±
juutis
2026-06-10 02:25:58
(2 hours ago)
145.239.79.139 - - [09/Jun/2026:20:27:12 +0200] "POST /wp-login.php HTTP/1.1" 200 7793 "https://taid ...
show more
145.239.79.139 - - [09/Jun/2026:20:27:12 +0200] "POST /wp-login.php HTTP/1.1" 200 7793 "https://taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
145.239.79.139 - - [09/Jun/2026:21:35:51 +0200] "POST /wp-login.php HTTP/1.1" 200 7789 "https://taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_10) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
145.239.79.139 - - [10/Jun/2026:04:25:57 +0200] "POST /wp-login.php HTTP/1.1" 200 7809 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-10 01:45:38
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 145.239.79.139 (139.ip-145-239-79.eu): 1 in the ...
show more
(mod_security) mod_security (id:225170) triggered by 145.239.79.139 (139.ip-145-239-79.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 21:45:32.133753 2026] [security2:error] [pid 9718:tid 9718] [client 145.239.79.139:36322] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.benkatkin.passy.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.benkatkin.passy.us"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aijBvJYVgUYOr6OAhZeOjgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨πΏ
huginet
2026-06-10 01:40:59
(3 hours ago)
145.239.79.139 - - [10/Jun/2026:03:40:58 +0200] "GET /wp-login.php HTTP/1.1" 200 9112 "-" "Mozilla/5 ...
show more
145.239.79.139 - - [10/Jun/2026:03:40:58 +0200] "GET /wp-login.php HTTP/1.1" 200 9112 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
145.239.79.139 - - [10/Jun/2026:03:40:58 +0200] "POST /wp-login.php HTTP/1.1" 200 9549 "https://centrum-eko-likvidace.org/wp-login.php" "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web Spam
Blog Spam
Hacking
Bad Web Bot
Web App Attack
π¬π§
andypiper
2026-06-10 01:00:51
(4 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack