π©πͺ
ger-stg-sifi1
2026-06-28 03:07:55
(13 minutes ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
π©πͺ
LRob.fr
2026-06-28 02:15:04
(1 hour ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
π©πͺ
neckaralb-admin.de
2026-06-27 23:29:27
(3 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-06-27 22:31:19
(4 hours ago)
[27/Jun/2026:22:31:19 +0000] host=lovelyrender.app server=lovelyrender.app ip=204.197.172.142 method ...
show more
[27/Jun/2026:22:31:19 +0000] host=lovelyrender.app server=lovelyrender.app ip=204.197.172.142 method=GET req=/wp-json/wp/v2/users/me uri=/index.php status=302 bytes=0 rt=0.044 urt=0.045 ref="-" ua="Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot
π«π·
tecnicorioja
2026-06-27 22:01:44
(5 hours ago)
wp-login attack [27/Jun/2026:06:54:05
Brute-Force
Web App Attack
π©πͺ
nyt
2026-06-27 19:54:52
(7 hours ago)
Brute-Force, Web App Attack, 503 on login page
Brute-Force
Web App Attack
π©πͺ
AlexEventfahrtenIPDB
2026-06-27 17:56:50
(9 hours ago)
[Sat Jun 27 19:56:49.526118 2026] [authz_core:error] [pid 1639498:tid 1639498] [client 204.197.172.1 ...
show more
[Sat Jun 27 19:56:49.526118 2026] [authz_core:error] [pid 1639498:tid 1639498] [client 204.197.172.142:53966] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php
...
show less
Brute-Force
Web App Attack
π©πͺ
Marc
2026-06-27 17:33:36
(9 hours ago)
204.197.172.142 - - [27/Jun/2026:16:10:03 +0200] "GET /wp-login.php HTTP/2.0" 200 3924 "-" "Mozilla/ ...
show more
204.197.172.142 - - [27/Jun/2026:16:10:03 +0200] "GET /wp-login.php HTTP/2.0" 200 3924 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 204.197.172.142 - - [27/Jun/2026:17:58:34 +0200] "GET /wp-login.php HTTP/2.0" 200 3899 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_10) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 204.197.172.142 - - [27/Jun/2026:17:58:34 +0200] "POST /wp-login.php HTTP/2.0" 403 10795 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_10) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 204.197.172.142 - - [27/Jun/2026:19:33:34 +0200] "GET /wp-login.php HTTP/2.0" 200 3899 "-" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 204.197.172.142 - - [27/Jun/2026:19:33:35 +0200] "POST /wp-login.php HTTP/2.0" 403 10809 "https://saatschule.de/wp-login.php" "Mozilla/5.0 (X11; CrOS x86_64 145
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-27 16:59:26
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 204.197.172.142 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 204.197.172.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 12:59:17.161259 2026] [security2:error] [pid 26835:tid 26835] [client 204.197.172.142:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.local639.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.local639.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "akABZdfQvQXha0DTtn_mqwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
solution.it
2026-06-27 16:11:31
(11 hours ago)
[Sat Jun 27 18:11:30.925094 2026] [php7:error] [pid 3261240:tid 3261240] [client 204.197.172.142:555 ...
show more
[Sat Jun 27 18:11:30.925094 2026] [php7:error] [pid 3261240:tid 3261240] [client 204.197.172.142:55520] script '/var/www/html/blog.solution.it/wp-login.php' not found or unable to stat
show less
Web App Attack
π©πͺ
F242
2026-06-27 13:45:57
(13 hours ago)
Wordpress Login or XMLRPC abuse
Web App Attack
Anonymous
2026-06-27 12:45:16
(14 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-27 11:39:55
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 204.197.172.142 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 204.197.172.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 27 07:39:47.806133 2026] [security2:error] [pid 31199:tid 31199] [client 204.197.172.142:57782] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||natickvillagerentals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "natickvillagerentals.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aj-2g-w68UdFUSJoXn3nbgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Hazzard
2026-06-27 11:28:57
(15 hours ago)
(PERMBLOCK) 204.197.172.142 (US/United States/-/-/-/[redacted]) has had more than 4 temp blocks
Hacking
πΊπΈ
etu brutus
2026-06-27 11:22:50
(15 hours ago)
204.197.172.142 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host