🇩🇪
neckaralb-admin.de
2026-09-10 20:43:20
(13 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇵🇱
Budyn
2026-09-10 19:58:55
(14 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.tech | URI: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 12:01:41
(22 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇹🇷
oalver
2026-09-04 03:17:14
(1 week ago)
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signa ...
show more
Detected by SiberKapan threat intelligence platform (siberkapan.org). Attack types: nginx_path_signature. Sources: nginx. Details: path_signature: request to /wp-login.php (HTTP 200). First seen: 2026-09-03. Risk score: 60/100.
show less
Web App Attack
🇩🇪
gadix
2026-09-04 02:38:46
(1 week ago)
45.132.227.166 - - [04/Sep/2026:02:26:33 +0200] "POST /wp-login.php HTTP/1.1" 200 44792 "-" "Mozilla ...
show more
45.132.227.166 - - [04/Sep/2026:02:26:33 +0200] "POST /wp-login.php HTTP/1.1" 200 44792 "-" "Mozilla/5.0"
45.132.227.166 - - [04/Sep/2026:03:23:07 +0200] "POST /wp-login.php HTTP/1.1" 200 44792 "-" "Mozilla/5.0"
45.132.227.166 - - [04/Sep/2026:04:38:45 +0200] "POST /wp-login.php HTTP/1.1" 200 44792 "-" "Mozilla/5.0"
...
show less
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-01 22:00:30
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
🇦🇺
afleventoffice.com.au
2026-08-31 20:15:26
(1 week ago)
GET /wp-login.php HTTP/1.1
Web App Attack
🇩🇪
neckaralb-admin.de
2026-08-31 19:21:45
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
FeG Deutschland
2026-08-31 15:44:46
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇫🇷
tecnicorioja
2026-08-28 22:02:12
(1 week ago)
wp-login attack [28/Aug/2026:09:37:57
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-08-28 10:33:56
(1 week ago)
cloudlinux2 fail2ban: 2026-08-28 12:28:55,795 fail2ban.actions [1478]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-28 12:28:55,795 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Unban 34.56.9.227cloudlinux2 fail2ban: 2026-08-28 12:29:06,426 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 91.193.232.61 - 2026-08-28 12:29:04cloudlinux2 fail2ban: 2026-08-28 12:29:05,302 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 136.144.43.18 - 2026-08-28 12:29:05cloudlinux2 fail2ban: 2026-08-28 12:29:06,259 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 45.146.55.228 - 2026-08-28 12:29:04cloudlinux2 fail2ban: 2026-08-28 12:29:06,358 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 91.193.232.73 - 2026-08-28 12:29:04cloudlinux2 fail2ban: 2026-08-28 12:29:27,044 fail2ban.actions [1478]: NOTICE [plesk-modsecurity] Unban 34.45.142.75cloudlinux2 fail2ban: 2026-08-28 12:30:24,234 fail2ban.filter [1478]: INFO [plesk-wordpress] Found 45.132.227.166 - 2026-08-28 12:30:23cloudlinux2 fail2ban: 2026-08-28 12:30:32,988 fail2
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 02:41:53
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 22:41:28.032716 2026] [security2:error] [pid 14404:tid 14404] [client 45.132.227.166:50145] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.103"] [uri "/.env"] [unique_id "ao5SWFJ8Nohy0ioFYeNlgwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-22 02:25:37
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 45.132.227.166 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.132.227.166 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 22:25:24.118377 2026] [security2:error] [pid 22093:tid 22093] [client 45.132.227.166:20851] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.196"] [uri "/sites/all/libraries/mailchimp/.env"] [unique_id "aokIlGFVBqohlqE5mrsrngAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-07-31 11:48:21
(1 month ago)
CrowdSec: crowdsecurity/http-bf-wordpress_bf | req: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0 ...
show more
CrowdSec: crowdsecurity/http-bf-wordpress_bf | req: /wp-login.php | UA: Mozilla/5.0 (Windows NT 10.0; WOW64; Trident/7.0; MAARJS; rv:11.0) like Gecko
show less
Brute-Force
Web App Attack
🇩🇪
todix
2026-07-29 17:50:03
(1 month ago)
Wordpress brute force or spam attempt from 45.132.227.166
Brute-Force