πΊπΈ
mind5t0rm
2026-06-02 06:07:23
(1 day ago)
(WPLOGIN) WP Login Attack 46.105.252.3 (FR/France/ip3.ip-46-105-252.eu): 3 in the last 3600 secs; Po ...
show more
(WPLOGIN) WP Login Attack 46.105.252.3 (FR/France/ip3.ip-46-105-252.eu): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 46.105.252.3 - - [02/Jun/2026:12:36:03 +0700] "GET /wp-login.php HTTP/2.0" 200 3163 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
46.105.252.3 - - [02/Jun/2026:12:36:07 +0700] "POST /wp-login.php HTTP/2.0" 200 4209 "https://thevasilis.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
46.105.252.3 - - [02/Jun/2026:13:07:19 +0700] "GET /wp-login.php HTTP/2.0" 200 3163 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
show less
Port Scan
π©πͺ
FeG Deutschland
2026-06-02 06:06:33
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
πΈπ¬
abuseipreport.darajati
2026-06-02 06:05:16
(1 day ago)
46.105.252.3 - - [2026-06-02T14:05:16+08:00] "POST /wp-login.php HTTP/1.1" 200 2120 "https://hestiai ...
show more
46.105.252.3 - - [2026-06-02T14:05:16+08:00] "POST /wp-login.php HTTP/1.1" 200 2120 "https://hestiaistiviani.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
...
show less
Web App Attack
π©πͺ
Prodscape
2026-06-02 05:57:08
(1 day ago)
(WPLOGIN) WP Login Attack 46.105.252.3 (ES/Spain/ip3.ip-46-105-252.eu): 5 in the last 86400 secs; Po ...
show more
(WPLOGIN) WP Login Attack 46.105.252.3 (ES/Spain/ip3.ip-46-105-252.eu): 5 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-06-02 05:40:09
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 46.105.252.3 (ip3.ip-46-105-252.eu): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 46.105.252.3 (ip3.ip-46-105-252.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 01:40:01.066839 2026] [security2:error] [pid 9952:tid 9952] [client 46.105.252.3:40188] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theyoungstrategist.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theyoungstrategist.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ah5sscxsUmtRvTEVgdYJmAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-02 05:32:31
(1 day ago)
2026-06-02T07:32:30.077574+02:00 aion wordpress[131510]: Blocked user enumeration attempt from 46.10 ...
show more
2026-06-02T07:32:30.077574+02:00 aion wordpress[131510]: Blocked user enumeration attempt from 46.105.252.3
...
show less
Hacking
Brute-Force
ππΊ
bcsaba
2026-06-02 05:08:48
(1 day ago)
CMS (WordPress or Joomla) login attempt.
46.105.252.3 - - [02/Jun/2026:07:08:46 +0200] "POST /wp-log ...
show more
CMS (WordPress or Joomla) login attempt.
46.105.252.3 - - [02/Jun/2026:07:08:46 +0200] "POST /wp-login.php HTTP/2.0" 200 4044 "https://*REDACTED*/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 05:02:54
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 46.105.252.3 (ip3.ip-46-105-252.eu): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 46.105.252.3 (ip3.ip-46-105-252.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 01:02:51.013003 2026] [security2:error] [pid 18049:tid 18049] [client 46.105.252.3:47084] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||anthonyanimalclinic.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "anthonyanimalclinic.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ah5j-woaQngFS2bWhWJF5QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TAY
2026-06-02 04:49:31
(1 day ago)
46.105.252.3 - - [02/Jun/2026:12:47:49 +0800] "POST /wp-login.php HTTP/1.1" 200 2677 "https://little ...
show more
46.105.252.3 - - [02/Jun/2026:12:47:49 +0800] "POST /wp-login.php HTTP/1.1" 200 2677 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
46.105.252.3 - - [02/Jun/2026:12:48:20 +0800] "POST /wp-login.php HTTP/1.1" 200 2705 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
46.105.252.3 - - [02/Jun/2026:12:49:29 +0800] "POST /wp-login.php HTTP/1.1" 200 2674 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-02 04:40:24
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 46.105.252.3 (ip3.ip-46-105-252.eu): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 46.105.252.3 (ip3.ip-46-105-252.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 00:40:17.243811 2026] [security2:error] [pid 14426:tid 14426] [client 46.105.252.3:55028] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tracytappan.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tracytappan.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ah5esdtMCcxohHYP_6UDLgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Hazzard
2026-06-02 04:18:54
(1 day ago)
(PERMBLOCK) 46.105.252.3 (FR/France/-/-/ip3.ip-46-105-252.eu/[redacted]) has had more than 4 temp bl ...
show more
(PERMBLOCK) 46.105.252.3 (FR/France/-/-/ip3.ip-46-105-252.eu/[redacted]) has had more than 4 temp blocks
show less
Hacking
πΊπΈ
TPI-Abuse
2026-06-02 04:17:01
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 46.105.252.3 (ip3.ip-46-105-252.eu): 1 in the l ...
show more
(mod_security) mod_security (id:225170) triggered by 46.105.252.3 (ip3.ip-46-105-252.eu): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 00:16:57.138844 2026] [security2:error] [pid 14004:tid 14004] [client 46.105.252.3:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||avaliantlife.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "avaliantlife.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ah5ZOWcYrVg0HygmNnw6AAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
octageeks.com
2026-06-02 04:06:56
(1 day ago)
Wordpress malicious attack:[octawp]
Web App Attack
πΈπ¬
abuseipreport.darajati
2026-06-02 04:05:20
(1 day ago)
46.105.252.3 - - [2026-06-02T12:05:20+08:00] "POST /wp-login.php HTTP/1.1" 200 2115 "https://hestiai ...
show more
46.105.252.3 - - [2026-06-02T12:05:20+08:00] "POST /wp-login.php HTTP/1.1" 200 2115 "https://hestiaistiviani.com/wp-login.php" "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
π³π±
juutis
2026-06-02 04:04:34
(1 day ago)
46.105.252.3 - - [01/Jun/2026:19:13:06 +0200] "POST /wp-login.php HTTP/1.1" 200 7803 "https://www.ta ...
show more
46.105.252.3 - - [01/Jun/2026:19:13:06 +0200] "POST /wp-login.php HTTP/1.1" 200 7803 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
46.105.252.3 - - [01/Jun/2026:19:22:24 +0200] "POST /wp-login.php HTTP/1.1" 200 7825 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
46.105.252.3 - - [02/Jun/2026:06:04:33 +0200] "POST /wp-login.php HTTP/1.1" 200 7807 "https://www.taidesuunnistus.net/wp-login.php" "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Web App Attack