Anonymous
2026-06-04 05:03:05
(3 hours ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2026-06-04 04:51:04
(3 hours ago)
[Thu Jun 04 05:17:14.086919 2026] [authz_core:error] [pid 1740:tid 1802] [client 54.36.102.244:40444 ...
show more
[Thu Jun 04 05:17:14.086919 2026] [authz_core:error] [pid 1740:tid 1802] [client 54.36.102.244:40444] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php
[Thu Jun 04 05:17:14.192156 2026] [authz_core:error] [pid 1740:tid 1806] [client 54.36.102.244:40444] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php, referer: https://cimt-precision.de/wp-login.php
[Thu Jun 04 06:51:03.713125 2026] [authz_core:error] [pid 1735:tid 1891] [client 54.36.102.244:56494] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php
[Thu Jun 04 06:51:03.983055 2026] [authz_core:error] [pid 1735:tid 1904] [client 54.36.102.244:56494] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php, referer: https://pre.cimt-precision.de/wp-login.php
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TAY
2026-06-04 04:25:57
(3 hours ago)
54.36.102.244 - - [04/Jun/2026:12:16:29 +0800] "POST /wp-login.php HTTP/1.1" 200 2981 "https://www.a ...
show more
54.36.102.244 - - [04/Jun/2026:12:16:29 +0800] "POST /wp-login.php HTTP/1.1" 200 2981 "https://www.autism-cvc.org/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
54.36.102.244 - - [04/Jun/2026:12:17:58 +0800] "POST /wp-login.php HTTP/1.1" 200 2976 "https://www.autism-cvc.org/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
54.36.102.244 - - [04/Jun/2026:12:25:57 +0800] "POST /wp-login.php HTTP/1.1" 200 2467 "https://aceflora.com/wp-login.php" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐บ๐ธ
Ghost Rider
2026-06-04 03:49:46
(4 hours ago)
RdpGuard detected brute-force attempt on RDP
Brute-Force
๐ฉ๐ช
bsoft.de
2026-06-04 03:30:43
(4 hours ago)
54.36.102.244 - - [04/Jun/2026:04:14:34 +0200] "GET /wp-login.php HTTP/1.1" 404 60724 "-" "Mozilla/5 ...
show more
54.36.102.244 - - [04/Jun/2026:04:14:34 +0200] "GET /wp-login.php HTTP/1.1" 404 60724 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
54.36.102.244 - - [04/Jun/2026:04:40:21 +0200] "GET /wp-login.php HTTP/1.1" 404 60724 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
54.36.102.244 - - [04/Jun/2026:05:30:42 +0200] "POST /xmlrpc.php HTTP/1.1" 200 247 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
mind5t0rm
2026-06-04 03:28:24
(4 hours ago)
(WPLOGIN) WP Login Attack 54.36.102.244 (FR/France/vps-85629346.vps.ovh.net): 3 in the last 3600 sec ...
show more
(WPLOGIN) WP Login Attack 54.36.102.244 (FR/France/vps-85629346.vps.ovh.net): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 54.36.102.244 - - [04/Jun/2026:10:12:34 +0700] "GET /wp-login.php HTTP/2.0" 200 3163 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
54.36.102.244 - - [04/Jun/2026:10:12:36 +0700] "POST /wp-login.php HTTP/2.0" 200 4111 "https://thevasilis.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
54.36.102.244 - - [04/Jun/2026:10:28:21 +0700] "GET /wp-login.php HTTP/2.0" 200 3163 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_10) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Port Scan
๐บ๐ธ
Mundo Bueno
2026-06-04 03:05:11
(5 hours ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /xmlrpc.php | Pays: FR | UA: Mozilla/5.0 (X11; Fedora; L ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /xmlrpc.php | Pays: FR | UA: Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safa
show less
Hacking
Web App Attack
๐ฆ๐บ
aranguren.org
2026-06-04 03:02:17
(5 hours ago)
[Thu Jun 04 12:15:24.471889 2026] [authz_core:error] [pid 2801027:tid 2801050] [remote 54.36.102.244 ...
show more
[Thu Jun 04 12:15:24.471889 2026] [authz_core:error] [pid 2801027:tid 2801050] [remote 54.36.102.244:48640] AH01630: client denied by server configuration: /usr/share/webapps/wordpress/xmlrpc.php
[Thu Jun 04 12:26:17.248694 2026] [authz_core:error] [pid 2806485:tid 2806503] [remote 54.36.102.244:39436] AH01630: client denied by server configuration: /usr/share/webapps/wordpress/xmlrpc.php
[Thu Jun 04 13:02:16.560793 2026] [authz_core:error] [pid 2828264:tid 2828268] [remote 54.36.102.244:49764] AH01630: client denied by server configuration: /usr/share/webapps/wordpress/xmlrpc.php
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
1cyb3rpunk
2026-06-04 03:01:11
(5 hours ago)
Honeypot trap [wordpress_install_probe] on sectrace.org โ path: /wp-login.php stage: recon. Automate ...
show more
Honeypot trap [wordpress_install_probe] on sectrace.org โ path: /wp-login.php stage: recon. Automated scanner/attacker activity.
show less
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-04 03:00:16
(5 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
Mundo Bueno
2026-06-04 02:44:28
(5 hours ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /xmlrpc.php | Pays: FR | UA: Mozilla/5.0 (Macintosh; Int ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /xmlrpc.php | Pays: FR | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.
show less
Hacking
Web App Attack
๐จ๐ฆ
KIsmay
2026-06-04 02:32:41
(5 hours ago)
Jun 3 14:23:37 ismay WPAudit[491973]: 54.36.102.244 ismay.ca "Mozilla/5.0 (X11; Ubuntu; Linux x86_6 ...
show more
Jun 3 14:23:37 ismay WPAudit[491973]: 54.36.102.244 ismay.ca "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" Sir:123456789 FAIL
Jun 3 14:31:56 ismay WPAudit[513880]: 54.36.102.244 christinesutherland.com "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" christine:123456789 FAIL
Jun 3 17:45:47 ismay WPAudit[528603]: 54.36.102.244 christinesutherland.com "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" thomas:thomas4 FAIL
Jun 3 19:05:33 ismay WPAudit[528269]: 54.36.102.244 ismay.ca "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" Sir:Sir9 FAIL
Jun 3 19:32:40 ismay WPAudit[532964]: 54.36.102.244 christinesutherland.com "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" wyatt:wyatt13
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
cwytech
2026-06-04 02:29:54
(5 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/wordpress-login-lockdown-high.
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-06-04 02:04:46
(6 hours ago)
L0ss Honeypot: WordPress login access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐ซ๐ท
Baking333
2026-06-04 01:39:23
(6 hours ago)
[redacted] 54.36.102.244 - - [04/Jun/2026:02:35:09 +0100] "POST /[redacted] HTTP/2.0" 200 364 "-" "M ...
show more
[redacted] 54.36.102.244 - - [04/Jun/2026:02:35:09 +0100] "POST /[redacted] HTTP/2.0" 200 364 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0" [redacted] 54.36.102.244 - - [04/Jun/2026:02:39:21 +0100] "POST /[redacted] HTTP/2.0" 200 364 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack