Anonymous
2026-08-30 18:46:16
(21 hours ago)
Failed Wordpress Logins
Web App Attack
๐บ๐ธ
integrantservices.com
2026-08-30 05:16:34
(1 day ago)
(wordpress) Failed wordpress login from 178.79.154.219 (GB/United Kingdom/178-79-154-219.ip.linodeus ...
show more
(wordpress) Failed wordpress login from 178.79.154.219 (GB/United Kingdom/178-79-154-219.ip.linodeusercontent.com)
show less
Brute-Force
๐ฉ๐ช
neckaralb-admin.de
2026-08-30 01:30:00
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-08-29 09:46:16
(2 days ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2026-08-28 07:01:40
(3 days ago)
2026-08-28 00:00:17,252 fail2ban.actions [242592]: NOTICE [tor] Ban 178.79.154.219
2026-08-2 ...
show more
2026-08-28 00:00:17,252 fail2ban.actions [242592]: NOTICE [tor] Ban 178.79.154.219
2026-08-28 03:00:12,602 fail2ban.actions [242592]: NOTICE [tor] Ban 178.79.154.219
2026-08-28 06:00:26,135 fail2ban.actions [242592]: NOTICE [tor] Ban 178.79.154.219
2026-08-28 09:00:10,280 fail2ban.actions [242592]: NOTICE [tor] Ban 178.79.154.219
2026-08-28 10:01:39,033 fail2ban.actions [242592]: NOTICE [tor] Ban 178.79.154.219
show less
Brute-Force
Anonymous
2026-08-28 00:21:31
(3 days ago)
Failed Wordpress Logins
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 21:37:14
(1 week ago)
(mod_security) mod_security (id:240335) triggered by 178.79.154.219 (178-79-154-219.ip.linodeusercon ...
show more
(mod_security) mod_security (id:240335) triggered by 178.79.154.219 (178-79-154-219.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 17:37:07.704810 2026] [security2:error] [pid 31198:tid 31198] [client 178.79.154.219:34854] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 178.79.154.219 (+1 hits since last alert)|riedmannfamily.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "riedmannfamily.com"] [uri "/xmlrpc.php"] [unique_id "aotoA2aMnH8UHIvkCdxF7gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-19 02:00:30
(1 week ago)
2026-08-18 17:00:18,797 fail2ban.actions [39175]: NOTICE [tor] Ban 178.79.154.219
2026-08-18 ...
show more
2026-08-18 17:00:18,797 fail2ban.actions [39175]: NOTICE [tor] Ban 178.79.154.219
2026-08-18 20:00:16,951 fail2ban.actions [39175]: NOTICE [tor] Ban 178.79.154.219
2026-08-18 23:00:12,308 fail2ban.actions [39175]: NOTICE [tor] Ban 178.79.154.219
2026-08-19 02:00:29,038 fail2ban.actions [39175]: NOTICE [tor] Ban 178.79.154.219
2026-08-19 05:00:27,431 fail2ban.actions [39175]: NOTICE [tor] Ban 178.79.154.219
show less
Brute-Force
๐ฉ๐ช
ger-stg-sifi1
2026-08-17 17:14:03
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐น๐ท
neron
2026-08-15 23:06:48
(2 weeks ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
Anonymous
2026-08-14 10:04:57
(2 weeks ago)
[redacted] 178.79.154.219 - - [14/Aug/2026:12:04:53 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" " ...
show more
[redacted] 178.79.154.219 - - [14/Aug/2026:12:04:53 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
[redacted] 178.79.154.219 - - [14/Aug/2026:12:04:54 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
[redacted] 178.79.154.219 - - [14/Aug/2026:12:04:55 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
[redacted] 178.79.154.219 - - [14/Aug/2026:12:04:56 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_4_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.4.1 Safari/605.1.15"
[redacted] 178.79.154.219 - - [14/Aug/2026:12:04:56 +0200] "POST /xmlrpc.php HTTP/1.1" 403 239 "-" "Mozill
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-11 23:59:43
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 178.79.154.219 (178-79-154-219.ip.linodeusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 178.79.154.219 (178-79-154-219.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 11 19:59:36.978734 2026] [security2:error] [pid 27011:tid 27011] [client 178.79.154.219:38150] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wp.hotpay.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wp.hotpay.co"] [uri "/wp-json/wp/v2/users"] [unique_id "anu3aBFRy4KhB7tGCKOjTgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-07 23:09:28
(3 weeks ago)
Try to access /xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 19:11:54
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 178.79.154.219 (178-79-154-219.ip.linodeusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 178.79.154.219 (178-79-154-219.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 15:11:46.362108 2026] [security2:error] [pid 2751469:tid 2751469] [client 178.79.154.219:39284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "victorvictorloft.com"] [uri "/.git/config"] [unique_id "anTccr4Z9Vx-gVICTVKtmAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-06 08:32:26
(3 weeks ago)
(mod_security) mod_security (id:225170) triggered by 178.79.154.219 (178-79-154-219.ip.linodeusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 178.79.154.219 (178-79-154-219.ip.linodeusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 06 04:32:19.487378 2026] [security2:error] [pid 7501:tid 7501] [client 178.79.154.219:51766] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||michelehoop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "michelehoop.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "anRGk0fwg13UFIBzVyhFnwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack