๐ฉ๐ช
neckaralb-admin.de
2026-09-22 01:30:35
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 01:00:53
(1 week ago)
This address requests our sites over plain http, is answered with a redirect to https, and never fol ...
show more
This address requests our sites over plain http, is answered with a redirect to https, and never follows it โ over and over. A browser follows redirects; a scanner enumerating hosts does not. It reads nothing it asks for and only loads the server; blocked. Please check what runs on this address. | method: GET (+1 more) | path: /wp-login.php | 2026-09-22 01:00 UTC
show less
Bad Web Bot
๐ง๐ช
cmbplf
2026-09-22 00:30:47
(1 week ago)
10.320 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
๐ฉ๐ช
stinpriza
2026-09-21 20:58:59
(1 week ago)
Web App Attack
Web App Attack
๐ฉ๐ช
gadix
2026-09-21 20:55:37
(1 week ago)
2a02:c207:2271:2633::1 - - [21/Sep/2026:22:05:14 +0200] "POST /wp-login.php HTTP/1.1" 200 11020 "htt ...
show more
2a02:c207:2271:2633::1 - - [21/Sep/2026:22:05:14 +0200] "POST /wp-login.php HTTP/1.1" 200 11020 "https://felixgade.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 10:21:41
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2271:2633::1 (vmi2712633.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2271:2633::1 (vmi2712633.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 06:21:37.808146 2026] [security2:error] [pid 9148:tid 9148] [client 2a02:c207:2271:2633::1:45238] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hvacmechanalysis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hvacmechanalysis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arEFMd2dOfhHRZ8FMuJfxwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 09:48:08
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2271:2633::1 (vmi2712633.contaboserve ...
show more
(mod_security) mod_security (id:225170) triggered by 2a02:c207:2271:2633::1 (vmi2712633.contaboserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 05:48:03.190017 2026] [security2:error] [pid 20512:tid 20512] [client 2a02:c207:2271:2633::1:41464] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cubbylure.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cubbylure.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arD9Uys9uqLlXiXMpX65IwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
verlon
2026-09-21 07:26:48
(1 week ago)
2a02:c207:2271:2633::1 - - [21/Sep/2026:09:26:11 +0200] "GET /log.php HTTP/2.0" 404 146 "-" "Mozilla ...
show more
2a02:c207:2271:2633::1 - - [21/Sep/2026:09:26:11 +0200] "GET /log.php HTTP/2.0" 404 146 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Mobile/15E148 Safari/604.1"
2a02:c207:2271:2633::1 - - [21/Sep/2026:09:26:20 +0200] "GET /login.php HTTP/2.0" 404 146 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Mobile/15E148 Safari/604.1"
2a02:c207:2271:2633::1 - - [21/Sep/2026:09:26:22 +0200] "GET /admin.php HTTP/2.0" 404 146 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15"
2a02:c207:2271:2633::1 - - [21/Sep/2026:09:26:23 +0200] "GET /log-in.php HTTP/2.0" 404 146 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15"
2a02:c207:2271:2633::1 - - [21/Sep/2026:09:26:24 +0200] "GET /signin.php HTTP/2.0" 404 146 "-" "Mozilla/5.0 (Macint
...
show less
Hacking
Web App Attack
๐ซ๐ท
Baking333
2026-09-21 07:12:04
(1 week ago)
[redacted] 2a02:c207:2271:2633::1 - - [21/Sep/2026:08:12:01 +0100] "GET /[redacted] HTTP/1.1" 302 67 ...
show more
[redacted] 2a02:c207:2271:2633::1 - - [21/Sep/2026:08:12:01 +0100] "GET /[redacted] HTTP/1.1" 302 6753 0/102511 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15" 443 [redacted] 2a02:c207:2271:2633::1 - - [21/Sep/2026:08:12:02 +0100] "GET /es/[redacted] HTTP/1.1" 302 1534 0/52608 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:130.0) Gecko/20100101 Firefox/130.0" 443
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-09-21 03:31:14
(1 week ago)
[redacted] 2a02:c207:2271:2633::1 - - [21/Sep/2026:04:31:13 +0100] "GET /[redacted] HTTP/1.1" 302 67 ...
show more
[redacted] 2a02:c207:2271:2633::1 - - [21/Sep/2026:04:31:13 +0100] "GET /[redacted] HTTP/1.1" 302 6773 0/48802 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Safari/605.1.15" 443 [redacted] 2a02:c207:2271:2633::1 - - [21/Sep/2026:04:31:13 +0100] "GET /es/[redacted] HTTP/1.1" 302 1554 0/45219 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.0 Mobile/15E148 Safari/604.1" 443
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-20 04:14:21
(1 week ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ณ๐ฑ
Alt255
2026-09-19 06:39:17
(1 week ago)
[ti-24al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpr ...
show more
[ti-24al] WordPress login brute-force: 4 suspicious requests detected by fail2ban jail apache-wordpress. Example: 2a02:c207:2271:2633::1 - - [19/Sep/2026:08:30:13 +0200] "POST /wp-login.php HTTP/1.1" 200 18348 "https://bijenwas-kaart.nl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
2a02:c207:2271:2633::1 - - [19/Sep/2026:08:30:13 +0200] "POST /wp-login.php HTTP/1.1" 200 18348 "https://bijenwas-kaart.nl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36"
2a02:c207:2271:2633::1 - - [19/Sep/2026:08:34:15 +0200] "POST /wp-login.php HTTP/1.1" 200 18348 "https://bijenwas-kaart.nl/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-18 19:56:52
(1 week ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
integrantservices.com
2026-09-18 19:56:22
(1 week ago)
(PERMBLOCK) 2a02:c207:2271:2633::1 (FR/France/-) has had more than 4 temp blocks
Hacking
๐บ๐ธ
integrantservices.com
2026-09-18 18:01:40
(1 week ago)
(wordpress) Failed wordpress login from 2a02:c207:2271:2633::1 (FR/France/-)
Brute-Force