๐จ๐ญ
barateza
2026-06-16 09:00:05
(9 hours ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ฉ๐ช
AlexEventfahrtenIPDB
2026-06-16 06:10:43
(11 hours ago)
[Tue Jun 16 08:10:42.651000 2026] [authz_core:error] [pid 577229:tid 577229] [client 149.50.143.80:5 ...
show more
[Tue Jun 16 08:10:42.651000 2026] [authz_core:error] [pid 577229:tid 577229] [client 149.50.143.80:58440] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://alex-eventfahrten.de/wp-login.php
[Tue Jun 16 08:10:42.651111 2026] [authz_core:error] [pid 570725:tid 570725] [client 149.50.143.80:58448] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://alex-eventfahrten.de/wp-login.php
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-16 05:11:38
(12 hours ago)
Try to access /xmlrpc.php
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-15 22:06:43
(19 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐ฌ๐ง
blik2108
2026-06-15 19:09:14
(22 hours ago)
www.blacknellfamilyhistory.co.uk:443 149.50.143.80 - - [15/Jun/2026:20:09:14 +0100] "POST /wp-login. ...
show more
www.blacknellfamilyhistory.co.uk:443 149.50.143.80 - - [15/Jun/2026:20:09:14 +0100] "POST /wp-login.php HTTP/1.1" 200 7133 "https://www.blacknellfamilyhistory.co.uk/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
www.blacknellfamilyhistory.co.uk:443 149.50.143.80 - - [15/Jun/2026:20:09:14 +0100] "POST /wp-login.php HTTP/1.1" 200 7156 "https://www.blacknellfamilyhistory.co.uk/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
www.blacknellfamilyhistory.co.uk:443 149.50.143.80 - - [15/Jun/2026:20:09:14 +0100] "POST /wp-login.php HTTP/1.1" 200 7160 "https://www.blacknellfamilyhistory.co.uk/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
www.blacknellfamilyhistory.co.uk:443 149.50.143.80 - - [15/Jun/2026:20:09:14 +0100] "POST /wp-login.php HTTP/1.1" 200 7156 "h
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
WPJoe
2026-06-15 17:08:10
(1 day ago)
149.50.143.80 - - [15/Jun/2026:17:08:08 +0000] "POST /wp-login.php HTTP/1.1" 200 5483 "https://violi ...
show more
149.50.143.80 - - [15/Jun/2026:17:08:08 +0000] "POST /wp-login.php HTTP/1.1" 200 5483 "https://violinbychristine.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15" 0s
149.50.143.80 - - [15/Jun/2026:17:08:08 +0000] "POST /wp-login.php HTTP/1.1" 200 5449 "https://violinbychristine.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:121.0) Gecko/20100101 Firefox/121.0" 0s
149.50.143.80 - - [15/Jun/2026:17:08:09 +0000] "POST /wp-login.php HTTP/1.1" 200 5447 "https://violinbychristine.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:121.0) Gecko/20100101 Firefox/121.0" 0s
149.50.143.80 - - [15/Jun/2026:17:08:09 +0000] "POST /wp-login.php HTTP/1.1" 200 5482 "https://violinbychristine.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0" 0s
149.50.143.80 - - [15/Jun/2026:17:08:09 +0000] "POST /wp-login.php HTTP/1.1" 200 2880 "https://violinbychristine.co
...
show less
Web App Attack
Brute-Force
Anonymous
2026-06-15 05:42:44
(1 day ago)
Fail2Ban WordPress login brute-force detected
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 17:02:16
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 149.50.143.80 (vps-4317127-x.dattaweb.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 149.50.143.80 (vps-4317127-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 13:02:13.474576 2026] [security2:error] [pid 2236:tid 2236] [client 149.50.143.80:45146] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||magacine.tv|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "magacine.tv"] [uri "/wp-json/wp/v2/users"] [unique_id "ai7eleVbKcq-CjYEbAqMvQAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 16:04:16
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 149.50.143.80 (vps-4317127-x.dattaweb.com): 1 i ...
show more
(mod_security) mod_security (id:225170) triggered by 149.50.143.80 (vps-4317127-x.dattaweb.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 12:04:10.966545 2026] [security2:error] [pid 5612:tid 5612] [client 149.50.143.80:58290] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||churchbehindthewalls.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "churchbehindthewalls.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai7Q-qLI8oTRaojJRGQyUAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2026-06-14 11:34:47
(2 days ago)
149.50.143.80 - - [14/Jun/2026:06:34:43 -0500] "POST /wp-login.php HTTP/1.1" 200 5219 "https://67.21 ...
show more
149.50.143.80 - - [14/Jun/2026:06:34:43 -0500] "POST /wp-login.php HTTP/1.1" 200 5219 "https://67.217.59.131/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
149.50.143.80 - - [14/Jun/2026:06:34:44 -0500] "POST /wp-login.php HTTP/1.1" 200 2637 "https://67.217.59.131/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
149.50.143.80 - - [14/Jun/2026:06:34:45 -0500] "POST /wp-login.php HTTP/1.1" 200 2637 "https://67.217.59.131/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
149.50.143.80 - - [14/Jun/2026:06:34:45 -0500] "POST /wp-login.php HTTP/1.1" 200 2637 "https://67.217.59.131/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:121.0) Gecko/20100101 Firefox/121.0"
149.50.143.80 - - [14/Jun/2026:06:34:46 -0500] "POST /wp-login.php HTTP/1.1" 200 2637 "
...
show less
Web App Attack
๐ฉ๐ช
neogenius
2026-06-14 11:25:32
(2 days ago)
Web App Attack
Web App Attack
Brute-Force
Anonymous
2026-06-14 09:25:25
(2 days ago)
Several WordPress login access pages and/or authentication failures
Web App Attack
๐ซ๐ท
masterguru
2026-06-14 08:43:30
(2 days ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 149.50.143.80 (AR/Argentina/vps-4317127-x.datt ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 149.50.143.80 (AR/Argentina/vps-4317127-x.dattaweb.com): 1 in the last 3600 secs (0-196)
show less
Hacking
๐ซ๐ท
masterguru
2026-06-14 07:58:59
(2 days ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-193)
Hacking
๐ซ๐ท
solution.it
2026-06-14 05:58:39
(2 days ago)
[Sun Jun 14 07:58:39.249979 2026] [php7:error] [pid 3600987:tid 3600987] [client 149.50.143.80:48760 ...
show more
[Sun Jun 14 07:58:39.249979 2026] [php7:error] [pid 3600987:tid 3600987] [client 149.50.143.80:48760] script '/var/www/html/blog.solution.it/wp-login.php' not found or unable to stat, referer: https://51.77.194.251/wp-login.php
show less
Web App Attack