🇩🇪
Marc
2026-08-30 21:03:46
(1 minute ago)
52.207.72.18 - - [30/Aug/2026:21:40:53 +0200] "GET /wp-login.php HTTP/2.0" 200 4307 "-" "52.207.72.1 ...
show more
52.207.72.18 - - [30/Aug/2026:21:40:53 +0200] "GET /wp-login.php HTTP/2.0" 200 4307 "-" "52.207.72.18" 52.207.72.18 - - [30/Aug/2026:21:40:56 +0200] "POST /wp-login.php HTTP/2.0" 200 4974 "https://www.bente-personaldienstleistung.de/wp-login.php" "52.207.72.18" 52.207.72.18 - - [30/Aug/2026:22:17:22 +0200] "GET /wp-login.php HTTP/2.0" 200 3446 "-" "52.207.72.18" 52.207.72.18 - - [30/Aug/2026:22:17:22 +0200] "POST /wp-login.php HTTP/2.0" 200 3260 "https://alsarnsberg.eu/wp-login.php" "52.207.72.18" 52.207.72.18 - - [30/Aug/2026:23:03:45 +0200] "GET /wp-login.php HTTP/2.0" 200 3462 "-" "52.207.72.18"
show less
Brute-Force
Web App Attack
🇫🇮
JimArchon72
2026-08-30 21:00:11
(5 minutes ago)
2026/08/30 20:59:45 "GET /wp-login.php HTTP/2.0"
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 20:56:07
(9 minutes ago)
(mod_security) mod_security (id:225170) triggered by 52.207.72.18 (ec2-52-207-72-18.compute-1.amazon ...
show more
(mod_security) mod_security (id:225170) triggered by 52.207.72.18 (ec2-52-207-72-18.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:56:00.767704 2026] [security2:error] [pid 23581:tid 23581] [client 52.207.72.18:33692] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||peterjohnsonauthor.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "peterjohnsonauthor.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apSY4Fjqcs-z8gxYmvfztgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
spamverify.com
2026-08-30 20:56:04
(9 minutes ago)
Honeypot Hit: WordPress Login
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
🇺🇸
wordpresshosting.solutions
2026-08-30 20:52:31
(12 minutes ago)
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 52.207.72.18 - - [30/Aug/2026:2 ...
show more
WordPress login/xmlrpc abuse or user enumeration detected. Evidence: 52.207.72.18 - - [30/Aug/2026:20:52:26 +0000] "GET /wp-login.php HTTP/1.1" 200 9836 "-" "52.207.72.18"
52.207.72.18 - - [30/Aug/2026:20:52:30 +0000] "POST /wp-login.php HTTP/1.1" 503 26322 "https://[DOMAIN]/wp-login.php" "52.207.72.18"
show less
Brute-Force
Web App Attack
🇬🇧
BRHosting
2026-08-30 20:43:02
(22 minutes ago)
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-08-30 20:38:56
(26 minutes ago)
cloudlinux2 fail2ban: 2026-08-30 22:34:05,902 fail2ban.filter [1459]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-30 22:34:05,902 fail2ban.filter [1459]: INFO [plesk-wordpress] Found 209.42.27.117 - 2026-08-30 22:34:05cloudlinux2 fail2ban: 2026-08-30 22:34:18,639 fail2ban.filter [1459]: INFO [plesk-wordpress] Found 52.207.72.18 - 2026-08-30 22:34:18cloudlinux2 fail2ban: 2026-08-30 22:36:48,379 fail2ban.filter [1459]: INFO [plesk-modsecurity] Found 106.215.151.30 - 2026-08-30 22:36:48cloudlinux2 fail2ban: 2026-08-30 22:36:44,686 fail2ban.filter [1459]: INFO [plesk-modsecurity] Found 18.220.71.225 - 2026-08-30 22:36:44cloudlinux2 fail2ban: 2026-08-30 22:38:01,577 fail2ban.filter [1459]: INFO [plesk-modsecurity] Found 177.241.60.37 - 2026-08-30 22:38:01cloudlinux2 fail2ban: 2026-08-30 22:38:15,106 fail2ban.filter [1459]: INFO [plesk-modsecurity] Found 106.215.151.30 - 2026-08-30 22:38:15cloudlinux2 fail2ban: 2026-08-30 22:38:31,851 fail2ban.filter [1459]: INFO [plesk-modsecurity] Found 104.23.225.57 - 2026-08-30 22:38:
show less
Web App Attack
🇩🇪
london2038.com
2026-08-30 20:35:41
(29 minutes ago)
Attacking WordPress
52.207.72.18 - - [30/Aug/2026:22:35:37 +0200] "POST /wp-login.php HTTP/2.0" 503 ...
show more
Attacking WordPress
52.207.72.18 - - [30/Aug/2026:22:35:37 +0200] "POST /wp-login.php HTTP/2.0" 503 19291 "https://<REDACTED>/wp-login.php" "52.207.72.18"
show less
Brute-Force
Web App Attack
🇩🇪
LRob
2026-08-30 20:34:24
(31 minutes ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /wp-json/wp/v2/users | 2026-08-30 20:34 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 20:32:24
(33 minutes ago)
(mod_security) mod_security (id:225170) triggered by 52.207.72.18 (ec2-52-207-72-18.compute-1.amazon ...
show more
(mod_security) mod_security (id:225170) triggered by 52.207.72.18 (ec2-52-207-72-18.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:32:18.379062 2026] [security2:error] [pid 16095:tid 16095] [client 52.207.72.18:54064] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rwabutazafoundation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rwabutazafoundation.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "apSTUkbtDQdhiNSHlBv8mwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-08-30 20:29:36
(35 minutes ago)
valueaddedpromotions.com.au:443 52.207.72.18 - - [31/Aug/2026:06:29:34 +1000] "GET /?author=2 HTTP/1 ...
show more
valueaddedpromotions.com.au:443 52.207.72.18 - - [31/Aug/2026:06:29:34 +1000] "GET /?author=2 HTTP/1.1" 404 352374 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36, Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇨🇦
KIsmay
2026-08-30 20:27:53
(37 minutes ago)
Aug 30 13:47:45 www4 WPAudit[2111226]: 52.207.72.18 terratherma.com "52.207.72.18" sbd-admin:sbd-adm ...
show more
Aug 30 13:47:45 www4 WPAudit[2111226]: 52.207.72.18 terratherma.com "52.207.72.18" sbd-admin:sbd-admin16 FAIL
Aug 30 14:24:00 www4 WPAudit[2115140]: 52.207.72.18 bcadjuster.com "52.207.72.18" tony:tony17 FAIL
Aug 30 14:41:50 www4 WPAudit[2117199]: 52.207.72.18 lemoncreekcampground.ca "52.207.72.18" lemoncreek:lemoncreek02 FAIL
Aug 30 14:46:28 www4 WPAudit[2117653]: 52.207.72.18 www.cottonwoodc.ca "52.207.72.18" cottonwoodcreek-admin:cottonwoodcreek-admin6 FAIL
Aug 30 16:27:53 www4 WPAudit[2129279]: 52.207.72.18 www.bestnelson.org "52.207.72.18" katietabor-developer:katietabor-developer08 FAIL
...
show less
Brute-Force
Web App Attack
🇩🇪
nyt
2026-08-30 20:25:42
(39 minutes ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
🇳🇱
maxxsense
2026-08-30 20:16:41
(48 minutes ago)
(wordpress) Failed wordpress login from 52.207.72.18 (US/United States/ec2-52-207-72-18.compute-1.am ...
show more
(wordpress) Failed wordpress login from 52.207.72.18 (US/United States/ec2-52-207-72-18.compute-1.amazonaws.com)
show less
Brute-Force
🇩🇪
hero2026
2026-08-30 20:14:17
(51 minutes ago)
Blocked by Fail2ban
Web App Attack