πΊπΈ
xxkodedxx
2026-06-03 22:04:58
(23 minutes ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1Γ honeypot-get in 10m window.
...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1Γ honeypot-get in 10m window.
Active: 22:04:33 UTC
Volume: 1 honeypot probe(s)
Bait taken: /wp-login.php
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-06-03 19:31:25
(2 hours ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 169.150.1.36 (BR/Brazil/169-150-1-36.br-se-1. ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 169.150.1.36 (BR/Brazil/169-150-1-36.br-se-1.user-content.mgc-public.net): 1 in the last 3600 secs (0-193)
show less
Hacking
Anonymous
2026-06-03 19:24:07
(3 hours ago)
169.150.1.36 - - [03/Jun/2026:21:21:27 +0200] "POST /wp-login.php HTTP/1.1" 200 2906 "https://matrix ...
show more
169.150.1.36 - - [03/Jun/2026:21:21:27 +0200] "POST /wp-login.php HTTP/1.1" 200 2906 "https://matrixventures.co.zm/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
169.150.1.36 - - [03/Jun/2026:21:21:27 +0200] "POST /wp-login.php HTTP/1.1" 200 2387 "https://matrixventures.co.zm/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
169.150.1.36 - - [03/Jun/2026:21:23:21 +0200] "POST /wp-login.php HTTP/1.1" 200 2946 "https://franlinetechnologies.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
169.150.1.36 - - [03/Jun/2026:21:23:21 +0200] "POST /wp-login.php HTTP/1.1" 200 2427 "https://franlinetechnologies.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
169.150.1.36 - - [03
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-03 17:21:13
(5 hours ago)
[03/Jun/2026:17:21:12 +0000] host=lovelyrender.app server=lovelyrender.app ip=169.150.1.36 method=PO ...
show more
[03/Jun/2026:17:21:12 +0000] host=lovelyrender.app server=lovelyrender.app ip=169.150.1.36 method=POST req=/xmlrpc.php uri=/index.php status=302 bytes=0 rt=0.056 urt=0.056 ref="-" ua="Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
...
show less
Web App Attack
Bad Web Bot
π©πͺ
LRob.fr
2026-06-03 15:00:04
(7 hours ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
π©πͺ
Martin Lundstrom
2026-06-03 12:44:47
(9 hours ago)
https://www.eagleeye-intelligence.com β WordPress attack. Automatically detected and blocked.
Web App Attack
π©πͺ
Hazzard
2026-06-03 11:29:02
(10 hours ago)
(wordpress) Failed wordpress login from 169.150.1.36 (BR/Brazil/-/-/169-150-1-36.br-se-1.user-conten ...
show more
(wordpress) Failed wordpress login from 169.150.1.36 (BR/Brazil/-/-/169-150-1-36.br-se-1.user-content.mgc-public.net/[redacted]): (CF_ENABLE)
show less
Brute-Force
π¬π§
spamverify.com
2026-06-03 10:54:59
(11 hours ago)
Honeypot Hit: WordPress Users
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
π²πΉ
Malta
2026-06-03 10:47:51
(11 hours ago)
169.150.1.36 - - [03/Jun/2026:12:47:51 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
169.150.1.36 - - [03/Jun/2026:12:47:51 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
Brute-force password attempt
show less
Hacking
Web App Attack
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-03 05:35:09
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 169.150.1.36 (169-150-1-36.br-se-1.user-content ...
show more
(mod_security) mod_security (id:225170) triggered by 169.150.1.36 (169-150-1-36.br-se-1.user-content.mgc-public.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 01:35:05.490307 2026] [security2:error] [pid 16288:tid 16288] [client 169.150.1.36:36914] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cms2020.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cms2020.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah-9Cb2WWUUT4rGTZzt31gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-03 02:30:12
(19 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
π«π·
ELYAZ
2026-06-03 01:54:27
(20 hours ago)
(y4) Failed scan -byebye- from 169.150.1.36 (BR/Brazil/169-150-1-36.br-se-1.user-content.mgc-public. ...
show more
(y4) Failed scan -byebye- from 169.150.1.36 (BR/Brazil/169-150-1-36.br-se-1.user-content.mgc-public.net): (CF_ENABLE)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-06-02 22:08:52
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 169.150.1.36 (169-150-1-36.br-se-1.user-content ...
show more
(mod_security) mod_security (id:225170) triggered by 169.150.1.36 (169-150-1-36.br-se-1.user-content.mgc-public.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 18:08:47.165532 2026] [security2:error] [pid 20418:tid 20418] [client 169.150.1.36:49398] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flatchestedmama.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flatchestedmama.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah9Ub9UWfPjn2WIezSQGogAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-06-02 16:40:32
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π©πͺ
LRob.fr
2026-06-02 06:00:03
(1 day ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack