๐ฉ๐ช
spam.must.die
2026-06-01 00:35:14
(3 days ago)
IP triggered category <category>
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-01 00:17:28
(3 days ago)
66.116.199.98 - - [01/Jun/2026:02:16:13 +0200] "POST /wp-login.php HTTP/1.1" 200 11434 "https://stag ...
show more
66.116.199.98 - - [01/Jun/2026:02:16:13 +0200] "POST /wp-login.php HTTP/1.1" 200 11434 "https://staging.taxifisch.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
66.116.199.98 - - [01/Jun/2026:02:16:54 +0200] "POST /wp-login.php HTTP/1.1" 200 43003 "https://violinlab.wp-knowhow.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
66.116.199.98 - - [01/Jun/2026:02:17:27 +0200] "POST /wp-login.php HTTP/1.1" 200 16171 "https://www.tierarzt-gellrich.de/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
๐ซ๐ท
Security_Whaller
2026-06-01 00:13:20
(3 days ago)
Malicious activity detected on Honeypot.
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
Vianpyro
2026-06-01 00:09:59
(3 days ago)
Honeypot: 15 request(s) in 2886 min. Paths: /feed/, /wp-json/wp/v2/posts, /wp-json/wp/v2/media, /wp- ...
show more
Honeypot: 15 request(s) in 2886 min. Paths: /feed/, /wp-json/wp/v2/posts, /wp-json/wp/v2/media, /wp-json/wp/v2/comments, /comments/feed/. Method(s): GET. UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/14. ASN: 31898 (P.D.R Solutions FZC).
show less
Web App Attack
Bad Web Bot
Hacking
Brute-Force
๐ฒ๐พ
Rizzy
2026-06-01 00:01:53
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
mind5t0rm
2026-05-31 23:26:54
(3 days ago)
(PERMBLOCK) 66.116.199.98 (IN/India/server.yanavedworld.com) has had more than 10 temp blocks in the ...
show more
(PERMBLOCK) 66.116.199.98 (IN/India/server.yanavedworld.com) has had more than 10 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐บ๐ธ
nyt
2026-05-31 22:20:14
(3 days ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
๐ธ๐ฎ
administrator
2026-05-31 22:02:47
(3 days ago)
2026-05-31 13:09:36,917 fail2ban.actions [47625]: NOTICE [webadmin-badips] Ban 66.116.199.98 ...
show more
2026-05-31 13:09:36,917 fail2ban.actions [47625]: NOTICE [webadmin-badips] Ban 66.116.199.98
2026-05-31 13:09:36,917 fail2ban.actions [47625]: NOTICE [webadmin-badips] Ban 66.116.199.98
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
tecnicorioja
2026-05-31 22:00:54
(3 days ago)
wp-login attack [31/May/2026:07:50:24
Brute-Force
Web App Attack
๐บ๐ธ
Ghost Rider
2026-05-31 21:49:17
(3 days ago)
RdpGuard detected brute-force attempt on RDP
Brute-Force
๐จ๐ฆ
KIsmay
2026-05-31 21:44:36
(3 days ago)
May 31 17:16:24 www4 WPAudit[197795]: 66.116.199.98 amandasrestaurant.ca "Mozilla/5.0 (Macintosh; In ...
show more
May 31 17:16:24 www4 WPAudit[197795]: 66.116.199.98 amandasrestaurant.ca "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:sbd-admin2001 FAIL
May 31 17:18:40 www4 WPAudit[194367]: 66.116.199.98 valhallasafety.com "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0" ron:0192837465z FAIL
May 31 17:24:59 www4 WPAudit[198366]: 66.116.199.98 imaginesalmon.com "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0" se7enoaks:se7enoaks98 FAIL
May 31 17:41:27 www4 WPAudit[189920]: 66.116.199.98 siscobc.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15" sbd-admin:Sbd-admin10 FAIL
May 31 17:44:36 www4 WPAudit[189920]: 66.116.199.98 www.siscobc.com "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0" sbd-admin:Sbd-admin10 FAIL
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mind5t0rm
2026-05-31 21:38:28
(3 days ago)
(WPLOGIN) WP Login Attack 66.116.199.98 (IN/India/server.yanavedworld.com): 3 in the last 3600 secs; ...
show more
(WPLOGIN) WP Login Attack 66.116.199.98 (IN/India/server.yanavedworld.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 66.116.199.98 - - [01/Jun/2026:04:25:57 +0700] "GET /wp-login.php HTTP/2.0" 200 3125 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
66.116.199.98 - - [01/Jun/2026:04:26:00 +0700] "POST /wp-login.php HTTP/2.0" 200 4101 "https://thevasilis.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
66.116.199.98 - - [01/Jun/2026:04:38:27 +0700] "GET /wp-login.php HTTP/2.0" 200 3125 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-31 21:34:53
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 66.116.199.98 (server.yanavedworld.com): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 66.116.199.98 (server.yanavedworld.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 31 17:34:49.701705 2026] [security2:error] [pid 10033:tid 10033] [client 66.116.199.98:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mail.rodrigoaldecoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mail.rodrigoaldecoa.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ahypeWJYOzXdRHOgHfHYzQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-05-31 20:46:56
(3 days ago)
66.116.199.98 - - [31/May/2026:22:39:16 +0200] "POST /wp-login.php HTTP/2.0" 200 17309 "https://www. ...
show more
66.116.199.98 - - [31/May/2026:22:39:16 +0200] "POST /wp-login.php HTTP/2.0" 200 17309 "https://www.bellabeauty.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:133.0) Gecko/20100101 Firefox/133.0"
66.116.199.98 - - [31/May/2026:22:44:11 +0200] "POST /wp-login.php HTTP/2.0" 200 17312 "https://www.bellabeauty.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
66.116.199.98 - - [31/May/2026:22:46:18 +0200] "POST /wp-login.php HTTP/2.0" 200 3780 "https://www.humorbank.de/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
66.116.199.98 - - [31/May/2026:22:46:56 +0200] "POST /wp-login.php HTTP/2.0" 200 18478 "https://cdn.autogarage-erlangen.de/wp-login.php" "Mozilla/5.0 (X11; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mind5t0rm
2026-05-31 20:28:21
(3 days ago)
(WPLOGIN) WP Login Attack 66.116.199.98 (IN/India/server.yanavedworld.com): 3 in the last 3600 secs; ...
show more
(WPLOGIN) WP Login Attack 66.116.199.98 (IN/India/server.yanavedworld.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 66.116.199.98 - - [01/Jun/2026:03:15:41 +0700] "GET /wp-login.php HTTP/2.0" 200 2603 "-" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
66.116.199.98 - - [01/Jun/2026:03:15:45 +0700] "POST /wp-login.php HTTP/2.0" 200 2758 "https://elgrecothailand.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
66.116.199.98 - - [01/Jun/2026:03:28:18 +0700] "GET /wp-login.php HTTP/2.0" 200 2345 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
show less
Port Scan