🇫🇷
SpaceHost-Server
2026-09-08 22:17:07
(11 hours ago)
Brute-Force
Web App Attack
🇺🇸
IndigoRidge
2026-09-08 16:57:27
(16 hours ago)
185.92.26.52 - - [08/Sep/2026:12:57:22 -0400] "GET /wp-login.php?redirect_to=https%3A%2F%2Fcypressce ...
show more
185.92.26.52 - - [08/Sep/2026:12:57:22 -0400] "GET /wp-login.php?redirect_to=https%3A%2F%2Fcypresscenter.net%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 14654 "https://cypresscenter.net/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1 Safari/605.1.15"
185.92.26.52 - - [08/Sep/2026:12:57:24 -0400] "POST /wp-login.php HTTP/1.1" 200 12954 "https://cypresscenter.net/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Safari/605.1.15"
185.92.26.52 - - [08/Sep/2026:12:57:25 -0400] "GET /wp-login.php?redirect_to=https%3A%2F%2Fcypresscenter.net%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 14654 "https://cypresscenter.net/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1.1 Safari/605.1.15"
185.92.26.52 - - [08/Sep/2026:12:57:25 -0400] "GET /wp-login.php?redirect_to=https%3A%2F%2Fcypresscenter.net%2Fwp-admin%2Fi
...
show less
Web App Attack
🇫🇷
masterguru
2026-09-08 07:09:57
(1 day ago)
(wordpress) Apache: Failed WordPress login from 185.92.26.52 (CA/Canada/-): 10 in the last 3600 secs ...
show more
(wordpress) Apache: Failed WordPress login from 185.92.26.52 (CA/Canada/-): 10 in the last 3600 secs (0-201)
show less
Hacking
🇩🇪
yitzhaq
2026-09-08 05:56:36
(1 day ago)
185.92.26.52 - - [08/Sep/2026:07:56:14 +0200] "POST /wp-login.php HTTP/1.1" 200 6394 "https://[site] ...
show more
185.92.26.52 - - [08/Sep/2026:07:56:14 +0200] "POST /wp-login.php HTTP/1.1" 200 6394 "https://[site]/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1 Safari/605.1.15"
185.92.26.52 - - [08/Sep/2026:07:56:17 +0200] "POST /wp-login.php HTTP/1.1" 200 6394 "https://[site]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/94.0.4606.71 Safari/537.36"
185.92.26.52 - - [08/Sep/2026:07:56:22 +0200] "POST /wp-login.php HTTP/1.1" 200 6387 "https://[site]/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/15.0 Safari/605.1.15"
185.92.26.52 - - [08/Sep/2026:07:56:29 +0200] "POST /wp-login.php HTTP/1.1" 200 6394 "https://[site]/wp-login.php" "Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:93.0) Gecko/20100101 Firefox/93.0"
185.92.26.52 - - [08/Sep/2026:07:56:33 +0200] "POST /wp-login.php HTTP/1.1" 200 6394 "https://[site]/wp-login
show less
Web App Attack
Brute-Force
🇺🇸
IndigoRidge
2026-09-08 02:53:41
(1 day ago)
185.92.26.52 - - [07/Sep/2026:22:53:37 -0400] "GET /wp-login.php?redirect_to=https%3A%2F%2F16daysofm ...
show more
185.92.26.52 - - [07/Sep/2026:22:53:37 -0400] "GET /wp-login.php?redirect_to=https%3A%2F%2F16daysofmylife.com%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 14188 "https://16daysofmylife.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1 Safari/605.1.15"
185.92.26.52 - - [07/Sep/2026:22:53:37 -0400] "POST /wp-login.php HTTP/1.1" 200 12411 "https://16daysofmylife.com/wp-login.php" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.131 Safari/537.36"
185.92.26.52 - - [07/Sep/2026:22:53:38 -0400] "GET /wp-login.php?redirect_to=https%3A%2F%2F16daysofmylife.com%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 14188 "https://16daysofmylife.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/90.0.4430.212 Safari/537.36"
185.92.26.52 - - [07/Sep/2026:22:53:39 -0400] "GET /wp-login.php?redirect_to=https%3A%2F%2F16daysofmylife.com
...
show less
Web App Attack
🇪🇸
masterguru
2026-09-08 01:55:28
(1 day ago)
(wplogin) Failed WordPress login from 185.92.26.52 (CA/Canada/-): 5 in the last 3600 secs (0-122)
Hacking
Anonymous
2026-09-08 00:59:46
(1 day ago)
Failed Wordpress Logins
Web App Attack
🇩🇪
Marc
2026-06-11 19:41:06
(2 months ago)
185.92.26.52 - - [11/Jun/2026:21:28:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3456 "-" "Jetpack by W ...
show more
185.92.26.52 - - [11/Jun/2026:21:28:17 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3456 "-" "Jetpack by WordPress.com (Jetpack 13.0; WordPress 6.3)" 185.92.26.52 - - [11/Jun/2026:21:36:27 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3455 "-" "WordPress.com; https://wordpress.com" 185.92.26.52 - - [11/Jun/2026:21:41:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 3456 "-" "WordPress.com; https://wordpress.com"
show less
Brute-Force
Web App Attack
🇩🇪
maxpower
2026-06-11 11:31:24
(2 months ago)
(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 185.92.26.52 (CA/Canada/-): 1 in the last 360 ...
show more
(aggressive_scanner) REGOLA 9 - Aggressive Web Scanner 185.92.26.52 (CA/Canada/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 185.92.26.52 - - [11/Jun/2026:13:31:15 +0200] "GET /wp-content/plugins/file-upload-types/assets/css/403.php HTTP/1.1" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3" "185.92.26.52" host=www.abruzzotour.it
show less
Port Scan
🇮🇹
Inartis
2026-06-11 11:25:14
(2 months ago)
[Thu Jun 11 13:25:08.912872 2026] [autoindex:error] [pid 1442778:tid 1442778] [client 185.92.26.52:3 ...
show more
[Thu Jun 11 13:25:08.912872 2026] [autoindex:error] [pid 1442778:tid 1442778] [client 185.92.26.52:30789] AH01276: Cannot serve directory /home/viniborin.it/public_html/wp-includes/Text/Diff/Renderer/: No matching DirectoryIndex (index.php,index.php4,index.php5,index.htm,index.html) found, and server-generated directory index forbidden by Options directive
[Thu Jun 11 13:25:13.886785 2026] [autoindex:error] [pid 1442778:tid 1442778] [client 185.92.26.52:30789] AH01276: Cannot serve directory /home/viniborin.it/public_html/wp-content/languages/: No matching DirectoryIndex (index.php,index.php4,index.php5,index.htm,index.html) found, and server-generated directory index forbidden by Options directive
[Thu Jun 11 13:25:14.262604 2026] [autoindex:error] [pid 1442778:tid 1442778] [client 185.92.26.52:30789] AH01276: Cannot serve directory /home/viniborin.it/public_html/wp-admin/images/: No matching DirectoryIndex (index.php,index.php4,index.php5,index.htm,index.html) found, and server-gener
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-05-26 10:20:14
(3 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-05-25 21:05:04
(3 months ago)
Request Overload (122)
Brute-Force
Web App Attack
🇬🇧
Mendip_Defender
2026-05-20 00:24:15
(3 months ago)
185.92.26.52 - - [20/May/2026:01:24:12 +0100] "GET /bless.php HTTP/1.1" 404 237 "-" "Mozilla/5.0 (Wi ...
show more
185.92.26.52 - - [20/May/2026:01:24:12 +0100] "GET /bless.php HTTP/1.1" 404 237 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:67.0) Gecko/20100101 Firefox/67.0"
185.92.26.52 - - [20/May/2026:01:24:13 +0100] "GET /O-Simple.php HTTP/1.1" 404 237 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:75.0) Gecko/20100101 Firefox/75.0"
185.92.26.52 - - [20/May/2026:01:24:13 +0100] "GET /lock360.php HTTP/1.1" 404 237 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.61 Safari/537.36"
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-05-18 20:44:08
(3 months ago)
(mod_security) mod_security (id:240000) triggered by 185.92.26.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 185.92.26.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 16:44:01.001870 2026] [security2:error] [pid 28267:tid 28267] [client 185.92.26.52:44113] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||hazardvillefire.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "hazardvillefire.org"] [uri "/images/stories/themes.php"] [unique_id "agt6EN6wANuy97f3KcVYaQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-05-17 10:22:33
(3 months ago)
Multiple WAF Violations
Web App Attack