๐บ๐ธ
agenciahypelab.com.br
2026-08-23 02:14:02
(43 minutes ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐ฎ๐น
๐ท๐ท๐ท
2026-08-23 01:46:18
(1 hour ago)
Multiple WordPress unauthorized access attempts
...
Brute-Force
Bad Web Bot
๐ฉ๐ช
LRob
2026-08-22 19:49:53
(7 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: //wp-json/wp/v2/users/
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-22 18:08:01
(8 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ณ๐ฑ
GabrielJST
2026-08-22 17:54:34
(9 hours ago)
(wordpress) Failed wordpress login from 146.70.92.60 (DK/Denmark/-)
Brute-Force
Anonymous
2026-08-22 17:50:59
(9 hours ago)
[redacted] 146.70.92.60 - - [22/Aug/2026:19:50:51 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "M ...
show more
[redacted] 146.70.92.60 - - [22/Aug/2026:19:50:51 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 146.70.92.60 - - [22/Aug/2026:19:50:52 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 146.70.92.60 - - [22/Aug/2026:19:50:52 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 146.70.92.60 - - [22/Aug/2026:19:50:53 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 146.70.92.60 - - [22/Aug/2026:19:50:54 +0200] "POST //xmlrpc.
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 17:49:21
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 146.70.92.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.92.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:49:14.767571 2026] [security2:error] [pid 24579:tid 24579] [client 146.70.92.60:45850] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.wallawallafirearmstraining.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.wallawallafirearmstraining.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aonhGhWkP2KG_1XeZTAdgAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 17:37:05
(9 hours ago)
146.70.92.60 - - [22/Aug/2026:17:37:05 +0000] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 11939 ...
show more
146.70.92.60 - - [22/Aug/2026:17:37:05 +0000] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 11939 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "-" "newpage.schmittel-it.de"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
largo-it.net
2026-08-22 17:35:29
(9 hours ago)
Aug 22 19:35:24 vps-9f3cdc33 haproxy[3223961]: 146.70.92.60:58704 [22/Aug/2026:19:35:23.646] www_fro ...
show more
Aug 22 19:35:24 vps-9f3cdc33 haproxy[3223961]: 146.70.92.60:58704 [22/Aug/2026:19:35:23.646] www_frontend~ imei1_cluster/imei1_https 80/0/5/468/553 404 1196 - - ---- 69/24/0/0/0 0/0 "GET //wp-includes/wlwmanifest.xml HTTP/1.1"
Aug 22 19:35:24 vps-9f3cdc33 haproxy[3223961]: 146.70.92.60:58704 [22/Aug/2026:19:35:24.199] www_frontend~ imei1_cluster/imei1_https 74/0/4/483/561 404 1196 - - ---- 69/24/0/0/0 0/0 "GET //xmlrpc.php?rsd HTTP/1.1"
Aug 22 19:35:25 vps-9f3cdc33 haproxy[3223961]: 146.70.92.60:58704 [22/Aug/2026:19:35:24.844] www_frontend~ imei1_cluster/imei1_https 66/0/5/480/551 404 1196 - - ---- 69/24/0/0/0 0/0 "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1"
Aug 22 19:35:26 vps-9f3cdc33 haproxy[3223961]: 146.70.92.60:58704 [22/Aug/2026:19:35:25.395] www_frontend~ imei1_cluster/imei1_https 69/0/4/545/618 404 1196 - - ---- 69/24/0/0/0 0/0 "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1"
Aug 22 19:35:26 vps-9f3cdc33 haproxy[3223961]: 146.70.92.60:58704 [22/Aug/2026:19:35:26.014] www
...
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 17:34:46
(9 hours ago)
[redacted] 146.70.92.60 - - [22/Aug/2026:19:34:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Mo ...
show more
[redacted] 146.70.92.60 - - [22/Aug/2026:19:34:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 146.70.92.60 - - [22/Aug/2026:19:34:41 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 146.70.92.60 - - [22/Aug/2026:19:34:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 146.70.92.60 - - [22/Aug/2026:19:34:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 146.70.92.60 - - [22/Aug/2026:19:34:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT
...
show less
Hacking
Web App Attack
๐ง๐ช
cmbplf
2026-08-22 17:28:24
(9 hours ago)
3.042 requests with url.path //xmlrpc.php
1.882 requests with url.path */wp-includes/wlwmanifest.x ...
show more
3.042 requests with url.path //xmlrpc.php
1.882 requests with url.path */wp-includes/wlwmanifest.xml
show less
Brute-Force
Bad Web Bot
๐ฌ๐ง
gigatech
2026-08-22 17:20:03
(9 hours ago)
Webserver Probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 16:16:35
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 146.70.92.60 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 146.70.92.60 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 12:16:27.025336 2026] [security2:error] [pid 11170:tid 11170] [client 146.70.92.60:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cloudex.click|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cloudex.click"] [uri "/wp-json/wp/v2/users/"] [unique_id "aonLW8wmelvsN4qQh-LpKgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-22 16:12:53
(10 hours ago)
[Sat Aug 22 18:12:53.225269 2026] [authz_core:error] [pid 15922] [client 146.70.92.60:38480] AH01630 ...
show more
[Sat Aug 22 18:12:53.225269 2026] [authz_core:error] [pid 15922] [client 146.70.92.60:38480] AH01630: client denied by server configuration: /var/www/html/portfolio/public/
[Sat Aug 22 18:12:53.268296 2026] [authz_core:error] [pid 15922] [client 146.70.92.60:38480] AH01630: client denied by server configuration: /var/www/html/portfolio/public/wp-includes
[Sat Aug 22 18:12:53.311399 2026] [authz_core:error] [pid 15922] [client 146.70.92.60:38480] AH01630: client denied by server configuration: /var/www/html/portfolio/public/xmlrpc.php
[Sat Aug 22 18:12:53.354442 2026] [authz_core:error] [pid 15922] [client 146.70.92.60:38480] AH01630: client denied by server configuration: /var/www/html/portfolio/public/
[Sat Aug 22 18:12:53.399717 2026] [authz_core:error] [pid 15922] [client 146.70.92.60:38480] AH01630: client denied by server configuration: /var/www/html/portfolio/public/blog
...
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-22 15:59:40
(10 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 146.70.92.60 (DK/Denmark/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 146.70.92.60 (DK/Denmark/-): 1 in the last 3600 secs
show less
Web App Attack