๐บ๐ธ
ambor
2026-05-25 21:12:05
(1 week ago)
L0ss Honeypot: WordPress login access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-05-25 21:05:37
(1 week ago)
Login Too Frequent (6)
Brute-Force
Web App Attack
๐ฉ๐ช
AlexEventfahrtenIPDB
2026-05-25 21:03:29
(1 week ago)
[Mon May 25 23:03:22.634554 2026] [authz_core:error] [pid 163531:tid 163531] [client 54.36.102.244:4 ...
show more
[Mon May 25 23:03:22.634554 2026] [authz_core:error] [pid 163531:tid 163531] [client 54.36.102.244:41640] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php
[Mon May 25 23:03:28.060295 2026] [authz_core:error] [pid 150205:tid 150205] [client 54.36.102.244:41648] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://alex-eventfahrten.spdns.de/wp-login.php
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-05-25 21:00:52
(1 week ago)
[MonMay2523:00:49.4276622026][security2:error][pid468376:tid468402][client54.36.102.244:0]ModSecurit ...
show more
[MonMay2523:00:49.4276622026][security2:error][pid468376:tid468402][client54.36.102.244:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"ecosuber.com\"][uri\"/wp-login.php\"][unique_id\"ahS4gdN51elNkRLuWQ2BbgAAAA8\"]\,referer:https://ecosuber.com/wp-login.php
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
todix
2026-05-25 20:58:23
(1 week ago)
Wordpress brute force or spam attempt from 54.36.102.244
Brute-Force
Anonymous
2026-05-25 20:50:28
(1 week ago)
54.36.102.244 - - [25/May/2026:22:37:15 +0200] "POST /wp-login.php HTTP/1.1" 200 2893 "https://blueg ...
show more
54.36.102.244 - - [25/May/2026:22:37:15 +0200] "POST /wp-login.php HTTP/1.1" 200 2893 "https://bluegrassschool.site/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
54.36.102.244 - - [25/May/2026:22:46:08 +0200] "POST /wp-login.php HTTP/1.0" 200 3237 "https://chandazinklabsolutions.online/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
54.36.102.244 - - [25/May/2026:22:46:09 +0200] "POST /wp-login.php HTTP/1.1" 200 2711 "https://chandazinklabsolutions.online/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
54.36.102.244 - - [25/May/2026:22:50:27 +0200] "POST /wp-login.php HTTP/1.0" 200 3522 "https://jorasom.org/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
54.36.102.244 -
...
show less
Brute-Force
Web App Attack
Anonymous
2026-05-25 20:33:47
(1 week ago)
54.36.102.244 - - [25/May/2026:22:33:41 +0200] "GET /wp-login.php HTTP/2.0" 200 4002 "-" "Mozilla/5. ...
show more
54.36.102.244 - - [25/May/2026:22:33:41 +0200] "GET /wp-login.php HTTP/2.0" 200 4002 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฆ๐บ
QT
2026-05-25 20:16:53
(1 week ago)
Unauthorised WordPress admin login attempted at 2026-05-26 06:16:52 +1000
Web App Attack
๐บ๐ธ
TAY
2026-05-25 20:10:20
(1 week ago)
54.36.102.244 - - [26/May/2026:04:01:56 +0800] "POST /wp-login.php HTTP/1.1" 200 2977 "https://autis ...
show more
54.36.102.244 - - [26/May/2026:04:01:56 +0800] "POST /wp-login.php HTTP/1.1" 200 2977 "https://autism-cvc.org/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
54.36.102.244 - - [26/May/2026:04:03:15 +0800] "POST /wp-login.php HTTP/1.1" 200 2974 "https://autism-cvc.org/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
54.36.102.244 - - [26/May/2026:04:10:18 +0800] "POST /wp-login.php HTTP/1.1" 200 2639 "https://athenscross.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-05-25 20:01:44
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 2
Exploited Host
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-05-25 19:51:29
(1 week ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-25 19:35:50
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 54.36.102.244 (vps-85629346.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 54.36.102.244 (vps-85629346.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 25 15:35:46.764825 2026] [security2:error] [pid 24356:tid 24356] [client 54.36.102.244:41050] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lysedzija.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lysedzija.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ahSkkv73qfj5rBh87YdlBAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-05-25 19:28:12
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-05-25 19:27:18
(1 week ago)
(wordpress) Apache: Failed WordPress login from 54.36.102.244 (FR/France/vps-85629346.vps.ovh.net): ...
show more
(wordpress) Apache: Failed WordPress login from 54.36.102.244 (FR/France/vps-85629346.vps.ovh.net): 10 in the last 3600 secs (0-195)
show less
Hacking
๐ฉ๐ช
london2038.com
2026-05-25 19:22:00
(1 week ago)
Probing for exploits
54.36.102.244 - - [25/May/2026:21:21:56 +0200] "GET /wp-login.php HTTP/2.0" 301 ...
show more
Probing for exploits
54.36.102.244 - - [25/May/2026:21:21:56 +0200] "GET /wp-login.php HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
54.36.102.244 - - [25/May/2026:21:21:56 +0200] "POST /wp-login.php HTTP/2.0" 301 0 "https://v97746.<REDACTED>/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack