🇩🇪
maxpower
2026-09-10 10:24:09
(23 hours ago)
(PERMBLOCK) 164.90.154.19 (US/United States/-) has had more than 4 temp blocks in the last 86400 sec ...
show more
(PERMBLOCK) 164.90.154.19 (US/United States/-) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
🇩🇪
maxpower
2026-09-10 09:38:17
(1 day ago)
(wp_login) REGOLA 1 - WP Login Attack 164.90.154.19 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(wp_login) REGOLA 1 - WP Login Attack 164.90.154.19 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 164.90.154.19 - - [10/Sep/2026:11:01:52 +0200] "POST /wp-login.php HTTP/1.1" 200 12106 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:11:10:55 +0200] "POST /wp-login.php HTTP/1.1" 200 12077 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:11:20:07 +0200] "POST /wp-login.php HTTP/1.1" 200 12075 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:11:29:09 +0200] "POST /wp-login.php HTTP/1.1" 200 12127 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:11:38:16 +0200] "POST /wp-login.php HTTP/1.1" 200 12142 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
show less
Port Scan
🇩🇪
maxpower
2026-09-10 08:52:58
(1 day ago)
(wp_login) REGOLA 1 - WP Login Attack 164.90.154.19 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(wp_login) REGOLA 1 - WP Login Attack 164.90.154.19 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 164.90.154.19 - - [10/Sep/2026:10:16:47 +0200] "POST /wp-login.php HTTP/1.1" 200 12166 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:10:25:56 +0200] "POST /wp-login.php HTTP/1.1" 200 12156 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:10:34:57 +0200] "POST /wp-login.php HTTP/1.1" 200 12221 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:10:43:54 +0200] "POST /wp-login.php HTTP/1.1" 200 12197 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:10:52:53 +0200] "POST /wp-login.php HTTP/1.1" 200 12157 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
show less
Port Scan
🇳🇿
Tripwire
2026-09-10 08:27:26
(1 day ago)
Scanning for exploits - /wp-json/batch/v1
Web App Attack
🇩🇪
maxpower
2026-09-10 08:07:35
(1 day ago)
(wp_login) REGOLA 1 - WP Login Attack 164.90.154.19 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(wp_login) REGOLA 1 - WP Login Attack 164.90.154.19 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 164.90.154.19 - - [10/Sep/2026:09:31:25 +0200] "POST /wp-login.php HTTP/1.1" 200 12146 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:09:40:06 +0200] "POST /wp-login.php HTTP/1.1" 200 12157 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:09:49:09 +0200] "POST /wp-login.php HTTP/1.1" 200 12081 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:09:58:18 +0200] "POST /wp-login.php HTTP/1.1" 200 12150 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:10:07:29 +0200] "POST /wp-login.php HTTP/1.1" 200 12060 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
show less
Port Scan
🇩🇪
maxpower
2026-09-10 07:23:01
(1 day ago)
(wp_login) REGOLA 1 - WP Login Attack 164.90.154.19 (US/United States/-): 5 in the last 3600 secs; P ...
show more
(wp_login) REGOLA 1 - WP Login Attack 164.90.154.19 (US/United States/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 164.90.154.19 - - [10/Sep/2026:08:24:49 +0200] "GET /?author=1 HTTP/1.1" 403 146 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
2026/09/10 08:24:49 [error] 3027868#3027868: *672265 access forbidden by rule, client: 164.90.154.19, server: gadget.circuitografico.it, request: "GET /?author=1 HTTP/1.1", host: "gadget.circuitografico.it"
164.90.154.19 - - [10/Sep/2026:09:14:12 +0200] "POST /wp-login.php HTTP/1.1" 200 12104 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:09:16:31 +0200] "POST /wp-login.php HTTP/1.1" 200 12145 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
164.90.154.19 - - [10/Sep/2026:09:22:58 +0200] "POST /wp-login.php HTTP/1.1" 200 12112 "-" "Mozilla/5.0" "-" host=gadget.circuitografico.it
show less
Port Scan
🇩🇪
bescared
2026-09-10 07:04:12
(1 day ago)
F2B - Malicious activity detected. URL Probing. -c0423ad6-
Hacking
Web App Attack
🇩🇪
FeG Deutschland
2026-09-10 06:59:52
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇩🇪
EGP Abuse Dept
2026-09-10 06:52:41
(1 day ago)
Scanning for web/db/file exploits on meubelcity.tafelconfigurator.nl
SQL Injection
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-10 06:28:07
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: metrics.astropot.site | URI: /wp-login.php | UA: Mozilla/5.0 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇺🇸
wteiken
2026-08-07 03:36:47
(1 month ago)
2026-08-06T23:36:40.202703-04:00 nostromo.teiken.net kernel: [302842.115036] syn_limit:IN=en-wan OUT ...
show more
2026-08-06T23:36:40.202703-04:00 nostromo.teiken.net kernel: [302842.115036] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=164.90.154.19 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=23328 DF PROTO=TCP SPT=59174 DPT=443 WINDOW=64240 RES=0x00 SYN URGP=0
2026-08-06T23:36:41.207416-04:00 nostromo.teiken.net kernel: [302843.117906] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=164.90.154.19 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=23329 DF PROTO=TCP SPT=59174 DPT=443 WINDOW=64240 RES=0x00 SYN URGP=0
2026-08-06T23:36:42.229335-04:00 nostromo.teiken.net kernel: [302844.141648] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:88:a2:5e:1c:98:0c:08:00 SRC=164.90.154.19 DST=173.52.106.128 LEN=60 TOS=0x00 PREC=0x00 TTL=56 ID=23330 DF PROTO=TCP SPT=59174 DPT=443 WINDOW=64240 RES=0x00 SYN URGP=0
2026-08-06T23:36:43.204238-04:00 nostromo.teiken.net kernel: [302845.116545] syn_limit:IN=en-wan OUT= MAC=00:50:43:37:c2:00:
...
show less
Port Scan
Anonymous
2026-08-06 17:57:56
(1 month ago)
2026-08-06T19:57:55.372602+02:00 vps kernel: [2409917.554206] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=f ...
show more
2026-08-06T19:57:55.372602+02:00 vps kernel: [2409917.554206] [PORTSCAN DETECTED] IN=ens3 OUT= MAC=fa:16:3e:66:f6:24:02:37:19:0d:c2:f3:08:00 SRC=164.90.154.19 DST=54.37.14.118 LEN=44 TOS=0x00 PREC=0x00 TTL=233 ID=30622 PROTO=TCP SPT=61013 DPT=3333 WINDOW=1025 RES=0x00 SYN URGP=0
...
show less
Port Scan
Brute-Force
🇺🇸
MPL
2026-08-06 17:30:58
(1 month ago)
tcp ports: 22222,3232 (2 or more attempts)
Port Scan
🇺🇸
xmission.com
2026-08-06 17:29:53
(1 month ago)
Blocked by UFW (TCP on 85)
Source port: 61000
TTL: 245
Packet length: 44
TOS: 0x08
This report (for ...
show more
Blocked by UFW (TCP on 85)
Source port: 61000
TTL: 245
Packet length: 44
TOS: 0x08
This report (for 164.90.154.19) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
🇩🇪
iNetWorker
2026-08-06 17:03:48
(1 month ago)
trying to access non-authorized port
Port Scan