๐ฌ๐ง
BRHosting
2026-09-22 15:29:02
(3 days ago)
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack
Anonymous
2026-09-22 14:36:34
(3 days ago)
Blocked by web application firewall: automated malicious HTTP requests (WordPress xmlrpc.php / wp-lo ...
show more
Blocked by web application firewall: automated malicious HTTP requests (WordPress xmlrpc.php / wp-login brute-force and admin-panel scanning). Distributed botnet / automated tooling. No legitimate use.
show less
Brute-Force
Web App Attack
Anonymous
2026-09-22 02:58:03
(4 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-09-21 15:06:44
(4 days ago)
WordPress login attempt
Brute-Force
๐บ๐ธ
LSPCCU
2026-09-21 14:36:35
(4 days ago)
TSEC Honeypot Network report. Threat score: 80/100. Categories: Hacking, Brute-Force, Web App Attack ...
show more
TSEC Honeypot Network report. Threat score: 80/100. Categories: Hacking, Brute-Force, Web App Attack, SSH. Honeypot: galah. Context: 146.255.96.137 classified as botnet node participating in coordinated attack campaigns (high confidence).
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ฌ๐ง
BRHosting
2026-09-21 14:14:02
(4 days ago)
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-09-21 11:52:04
(4 days ago)
Wordfence waf block on pameganslaw
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:20:52
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 146.255.96.137 (portal.antilasoft.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 146.255.96.137 (portal.antilasoft.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:20:46.639182 2026] [security2:error] [pid 9862:tid 9862] [client 146.255.96.137:35910] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.dixiegeek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.dixiegeek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arB4XlGLUXnRWdQZ7Xs-2wAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:18:57
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 146.255.96.137 (portal.antilasoft.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 146.255.96.137 (portal.antilasoft.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:18:52.164386 2026] [security2:error] [pid 22711:tid 22711] [client 146.255.96.137:41536] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sizefinder.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sizefinder.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arBp3A2Sus5FLPyKIRgViQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-20 22:16:10
(5 days ago)
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-20 10:43:56
(5 days ago)
cloudlinux2 fail2ban: 2026-09-20 12:40:05,307 fail2ban.filter [1597]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-20 12:40:05,307 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 143.198.8.80 - 2026-09-20 12:40:04cloudlinux2 fail2ban: 2026-09-20 12:40:18,519 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 143.110.214.16 - 2026-09-20 12:40:18cloudlinux2 fail2ban: 2026-09-20 12:40:28,322 fail2ban.filter [1597]: INFO [plesk-modsecurity] Found 146.255.96.137 - 2026-09-20 12:40:28cloudlinux2 fail2ban: 2026-09-20 12:40:53,022 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 185.223.152.10 - 2026-09-20 12:40:52cloudlinux2 fail2ban: 2026-09-20 12:40:59,895 fail2ban.filter [1597]: INFO [plesk-wordpress] Found 146.190.70.118 - 2026-09-20 12:40:59cloudlinux2 fail2ban: 2026-09-20 12:41:06,530 fail2ban.actions [1597]: NOTICE [plesk-modsecurity] Unban 34.48.20.178cloudlinux2 fail2ban: 2026-09-20 12:42:06,615 fail2ban.actions [1597]: NOTICE [plesk-modsecurity] Unban 94.129.199.38cloudlinux2 fail2ban: 2026-09-20 12:42:27,250
show less
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-19 22:15:59
(6 days ago)
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-09-19 16:59:35
(6 days ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-201)
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-19 16:35:07
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 146.255.96.137 (portal.antilasoft.com): 1 in th ...
show more
(mod_security) mod_security (id:225170) triggered by 146.255.96.137 (portal.antilasoft.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 12:35:02.104483 2026] [security2:error] [pid 5909:tid 5921] [client 146.255.96.137:55536] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||utahhoaservices.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "utahhoaservices.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aq65tgEb0CouHpxBYiDdCAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-09-19 15:49:09
(6 days ago)
WebAttack or semilar from 146.255.96.137
Web App Attack