Anonymous
2026-09-05 08:28:10
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇧🇪
cmbplf
2026-09-05 03:25:44
(1 day ago)
4.986 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
🇮🇹
CoreTech srl
2026-09-05 02:58:56
(1 day ago)
cloudlinux2 fail2ban: 2026-09-05 04:54:06,390 fail2ban.actions [1594]: NOTICE [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-05 04:54:06,390 fail2ban.actions [1594]: NOTICE [plesk-wordpress] Ban 45.146.55.181cloudlinux2 fail2ban: 2026-09-05 04:54:05,893 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 45.146.55.181 - 2026-09-05 04:54:05cloudlinux2 fail2ban: 2026-09-05 04:54:06,395 fail2ban.filter [1594]: INFO [recidive] Found 45.146.55.181 - 2026-09-05 04:54:06cloudlinux2 fail2ban: 2026-09-05 04:54:40,246 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.56.116.95 - 2026-09-05 04:54:39cloudlinux2 fail2ban: 2026-09-05 04:54:44,777 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.56.116.95 - 2026-09-05 04:54:44cloudlinux2 fail2ban: 2026-09-05 04:55:07,561 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 155.2.215.29 - 2026-09-05 04:55:07cloudlinux2 fail2ban: 2026-09-05 04:56:07,443 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 23.94.155.128 - 2026-09-05 04:56:06cloudlinux2 fail2ban: 2026-09-05 04:56:59
show less
FTP Brute-Force
Web App Attack
🇩🇪
Blexyel
2026-09-04 18:30:24
(1 day ago)
155.2.215.29 - - [04/Sep/2026:20:30:24 +0200] "GET /wp-login.php HTTP/1.1" 404 153 "-" "Mozilla/5.0" ...
show more
155.2.215.29 - - [04/Sep/2026:20:30:24 +0200] "GET /wp-login.php HTTP/1.1" 404 153 "-" "Mozilla/5.0" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-03 20:39:43
(2 days ago)
wp admin page access attempt
...
Hacking
Web App Attack
Anonymous
2026-09-02 22:15:04
(3 days ago)
Web attack blocked by Wordfence on heemkundesjin.nl (1 hit). Reported by CRMON.
Web App Attack
🇬🇧
Apache
2026-08-30 13:51:10
(6 days ago)
(wplogin) WordPress login brute-force 155.2.215.29 (US/United States/-): 5 in the last 300 secs
Brute-Force
🇳🇱
MyGlobalFlowers
2026-08-28 22:41:52
(1 week ago)
Multiple WAF Violations
Web App Attack
🇷🇸
Smel
2026-08-27 00:23:18
(1 week ago)
HTTP/80/443/8080 Unauthorized Probe, Hack -
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 23:14:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 155.2.215.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 155.2.215.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:13:34.677269 2026] [security2:error] [pid 13314:tid 13314] [client 155.2.215.29:20253] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.43"] [uri "/www/.env"] [unique_id "ao9zHqTNJPJ32YOlZaJRRQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 16:49:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 155.2.215.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 155.2.215.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 12:48:41.331699 2026] [security2:error] [pid 4415:tid 4424] [client 155.2.215.29:29209] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.129"] [uri "/new/.env"] [unique_id "ao8Y6RC_uvzrkU5Ph4VGEQAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
Halux
2026-08-26 15:35:17
(1 week ago)
155.2.215.29 Probing protected path or service
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 08:07:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 155.2.215.29 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 155.2.215.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:06:55.549973 2026] [security2:error] [pid 32074:tid 32158] [client 155.2.215.29:59023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.24"] [uri "/app/.env"] [unique_id "ao6enw7t6CTk0OK653MGSQAAAc8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
masterguru
2026-08-24 11:09:22
(1 week ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (5001900-122)
Web App Attack
🇩🇪
LRob
2026-08-23 09:37:07
(2 weeks ago)
WordPress login brute-force | path: /wp-login.php
Brute-Force
Web App Attack