๐ณ๐ฑ
juutis
2026-06-01 13:01:05
(2 days ago)
148.72.247.18 - - [31/May/2026:17:56:04 +0200] "POST /wp-login.php HTTP/1.1" 200 7827 "https://www.t ...
show more
148.72.247.18 - - [31/May/2026:17:56:04 +0200] "POST /wp-login.php HTTP/1.1" 200 7827 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_10) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
148.72.247.18 - - [01/Jun/2026:06:34:13 +0200] "POST /wp-login.php HTTP/1.1" 200 7809 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
148.72.247.18 - - [01/Jun/2026:15:01:04 +0200] "POST /wp-login.php HTTP/1.1" 200 7803 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
jormaster3k
2026-06-01 12:13:56
(2 days ago)
Attack against WordPress
Web App Attack
๐ฉ๐ช
Viveronese
2026-06-01 12:09:56
(2 days ago)
Wordpress vulnerability scanning
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-01 12:00:05
(2 days ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-01 11:34:33
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
๐บ๐ธ
mind5t0rm
2026-06-01 10:08:26
(2 days ago)
(WPLOGIN) WP Login Attack 148.72.247.18 (SG/Singapore/18.247.72.148.host.secureserver.net): 3 in the ...
show more
(WPLOGIN) WP Login Attack 148.72.247.18 (SG/Singapore/18.247.72.148.host.secureserver.net): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 148.72.247.18 - - [01/Jun/2026:16:34:56 +0700] "GET /wp-login.php HTTP/2.0" 200 2603 "-" "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
148.72.247.18 - - [01/Jun/2026:16:34:59 +0700] "POST /wp-login.php HTTP/2.0" 200 2758 "https://elgrecothailand.com/wp-login.php" "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
148.72.247.18 - - [01/Jun/2026:17:08:23 +0700] "GET /wp-login.php HTTP/2.0" 200 3126 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Port Scan
๐ซ๐ท
ELYAZ
2026-06-01 09:21:59
(2 days ago)
(y4) Failed scan -byebye- from 148.72.247.18 (SG/Singapore/18.247.72.148.host.secureserver.net): (C ...
show more
(y4) Failed scan -byebye- from 148.72.247.18 (SG/Singapore/18.247.72.148.host.secureserver.net): (CF_ENABLE)
show less
Hacking
๐จ๐ฆ
KIsmay
2026-06-01 05:56:09
(2 days ago)
May 31 23:49:11 www4 WPAudit[226538]: 148.72.247.18 www.siscobc.com "Mozilla/5.0 (X11; CrOS x86_64 1 ...
show more
May 31 23:49:11 www4 WPAudit[226538]: 148.72.247.18 www.siscobc.com "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:sbd-admin1993 FAIL
May 31 23:50:06 www4 WPAudit[226994]: 148.72.247.18 dev.siscobc.com "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:Sbd-admin@12345 FAIL
May 31 23:57:11 www4 WPAudit[227640]: 148.72.247.18 www.lemoncreekcampground.ca "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:sbd-admin92 FAIL
Jun 1 01:53:24 www4 WPAudit[236205]: 148.72.247.18 www.katharinedickerson.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:sbd-admin81 FAIL
Jun 1 01:56:09 www4 WPAudit[236526]: 148.72.247.18 www.siscobc.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KH
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-06-01 05:14:17
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
mind5t0rm
2026-06-01 04:31:17
(2 days ago)
(WPLOGIN) WP Login Attack 148.72.247.18 (SG/Singapore/18.247.72.148.host.secureserver.net): 3 in the ...
show more
(WPLOGIN) WP Login Attack 148.72.247.18 (SG/Singapore/18.247.72.148.host.secureserver.net): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 148.72.247.18 - - [01/Jun/2026:11:30:33 +0700] "GET /wp-login.php HTTP/2.0" 200 3126 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
148.72.247.18 - - [01/Jun/2026:11:30:35 +0700] "POST /wp-login.php HTTP/2.0" 200 4167 "https://thevasilis.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
148.72.247.18 - - [01/Jun/2026:11:31:15 +0700] "GET /wp-login.php HTTP/2.0" 200 3126 "-" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Port Scan
๐ฒ๐ฝ
octageeks.com
2026-06-01 04:16:13
(2 days ago)
Wordpress malicious attack:[octawp]
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-01 03:45:10
(2 days ago)
Repeated attacks detected by Fail2Ban in recidive jail
Hacking
๐บ๐ธ
mind5t0rm
2026-06-01 03:03:28
(2 days ago)
(WPLOGIN) WP Login Attack 148.72.247.18 (SG/Singapore/18.247.72.148.host.secureserver.net): 3 in the ...
show more
(WPLOGIN) WP Login Attack 148.72.247.18 (SG/Singapore/18.247.72.148.host.secureserver.net): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 148.72.247.18 - - [01/Jun/2026:09:07:08 +0700] "GET /wp-login.php HTTP/2.0" 200 3126 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
148.72.247.18 - - [01/Jun/2026:09:07:11 +0700] "POST /wp-login.php HTTP/2.0" 200 4167 "https://thevasilis.com/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
148.72.247.18 - - [01/Jun/2026:10:03:25 +0700] "GET /wp-login.php HTTP/2.0" 200 3126 "-" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Port Scan
๐จ๐ฆ
1gz
2026-06-01 02:38:50
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (POST method ...
show more
Triggered Cloudflare WAF (firewallCustom) from SG.
Action taken: BLOCK
Protocol: HTTP/2 (POST method)
Endpoint: /wp-login.php
UA: Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ซ๐ท
tecnicorioja
2026-05-31 22:00:50
(3 days ago)
wp-login attack [31/May/2026:07:50:52
Brute-Force
Web App Attack