๐ฉ๐ช
Marc
2026-08-26 03:04:05
(1 hour ago)
145.241.159.130 - - [26/Aug/2026:05:04:05 +0200] "GET /wp-login.php HTTP/1.1" 404 4492 "-" "Mozilla/ ...
show more
145.241.159.130 - - [26/Aug/2026:05:04:05 +0200] "GET /wp-login.php HTTP/1.1" 404 4492 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1 Safari/605.1.15" 145.241.159.130 - - [26/Aug/2026:05:04:05 +0200] "GET /wp-admin/ HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36" 145.241.159.130 - - [26/Aug/2026:05:04:05 +0200] "GET /wp-admin/admin-ajax.php HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7; rv:89.0) Gecko/20100101 Firefox/89.0.2"
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-26 02:56:29
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 145.241.159.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 145.241.159.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:56:22.697377 2026] [security2:error] [pid 3164429:tid 3164449] [client 145.241.159.130:51605] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tkfay.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tkfay.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ao5V1vlPLW7E8xMpNScjjQAAAY4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-08-26 02:34:52
(1 hour ago)
(wp_login_try) srv101 WordPress Login Brute Force 145.241.159.130 (SA/Saudi Arabia/-): 20 in the las ...
show more
(wp_login_try) srv101 WordPress Login Brute Force 145.241.159.130 (SA/Saudi Arabia/-): 20 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-26 01:29:22
(2 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
BlueWire Hosting
2026-08-26 01:22:03
(2 hours ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-26 01:05:25
(2 hours ago)
(mod_security) mod_security (id:225170) triggered by 145.241.159.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 145.241.159.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 21:05:20.893774 2026] [security2:error] [pid 22327:tid 22344] [client 145.241.159.130:61958] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||trulyoriginalpurpleoctopus.art|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "trulyoriginalpurpleoctopus.art"] [uri "/wp-json/wp/v2/users"] [unique_id "ao470EsrkVPC9GK6j1rW8wAAAQ0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
on-com
2026-08-26 00:24:24
(3 hours ago)
URL scan
Brute-Force
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-08-25 21:30:22
(6 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
Lino Project
2026-08-25 20:31:17
(7 hours ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-admin-interface-probing
Hacking
Anonymous
2026-08-25 20:22:03
(7 hours ago)
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/1.1, GET /wp-login.php?redirect_to=h ...
show more
Bot / scanning and/or hacking attempts: POST /wp-login.php HTTP/1.1, GET /wp-login.php?redirect_to=https%3A%2F%2Fmountainsholidays.c, GET /wp-admin/index.php HTTP/1.1
show less
Hacking
Web App Attack
๐ซ๐ท
Octopuce
2026-08-25 20:15:35
(7 hours ago)
Aggressive web search of vulnerable pages: /wp-login.php /wp-admin/ /wp-admin/admin-ajax.php /wp-adm ...
show more
Aggressive web search of vulnerable pages: /wp-login.php /wp-admin/ /wp-admin/admin-ajax.php /wp-admin/load-scripts.php /wp-admin/load-styles.p ...
show less
Web App Attack
๐ท๐บ
DZBOT
2026-08-25 19:17:35
(8 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-25 18:28:39
(9 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐ฉ๐ช
wlt-blocker
2026-08-25 18:15:58
(9 hours ago)
Unauthorized access to webpage admin
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 17:52:22
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 145.241.159.130 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 145.241.159.130 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 13:52:17.531299 2026] [security2:error] [pid 15391:tid 15391] [client 145.241.159.130:51680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||radicalchange.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "radicalchange.org"] [uri "/wp-json/wp/v2/users"] [unique_id "ao3WUdBV-EvT1gVyFa1qcwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack