๐บ๐ธ
nyt
2026-06-03 20:21:28
(11 hours ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
๐ฆ๐บ
aranguren.org
2026-06-03 20:20:06
(11 hours ago)
[Thu Jun 04 05:40:01.900408 2026] [authz_core:error] [pid 2648306:tid 2648322] [remote 68.178.160.25 ...
show more
[Thu Jun 04 05:40:01.900408 2026] [authz_core:error] [pid 2648306:tid 2648322] [remote 68.178.160.25:35788] AH01630: client denied by server configuration: /usr/share/webapps/wordpress/xmlrpc.php
[Thu Jun 04 06:00:21.942589 2026] [authz_core:error] [pid 2661414:tid 2661444] [remote 68.178.160.25:38982] AH01630: client denied by server configuration: /usr/share/webapps/wordpress/xmlrpc.php
[Thu Jun 04 06:20:05.472765 2026] [authz_core:error] [pid 2661414:tid 2661433] [remote 68.178.160.25:37454] AH01630: client denied by server configuration: /usr/share/webapps/wordpress/xmlrpc.php
...
show less
Brute-Force
Web App Attack
Anonymous
2026-06-03 19:50:41
(11 hours ago)
[Wed Jun 03 20:34:53.982348 2026] [authz_core:error] [pid 3073:tid 3107] [client 68.178.160.25:36598 ...
show more
[Wed Jun 03 20:34:53.982348 2026] [authz_core:error] [pid 3073:tid 3107] [client 68.178.160.25:36598] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php
[Wed Jun 03 20:34:56.733203 2026] [authz_core:error] [pid 3073:tid 3129] [client 68.178.160.25:36598] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php, referer: https://pre.cimt-precision.de/wp-login.php
[Wed Jun 03 21:41:36.915208 2026] [authz_core:error] [pid 3073:tid 3128] [client 68.178.160.25:36302] AH01630: client denied by server configuration: /var/www/wordp/wp-login.php
[Wed Jun 03 21:50:40.381743 2026] [authz_core:error] [pid 26011:tid 26058] [client 68.178.160.25:45548] AH01630: client denied by server configuration: /var/www/wordp/wp-login.php
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 19:48:37
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 68.178.160.25 (25.160.178.68.host.secureserver. ...
show more
(mod_security) mod_security (id:225170) triggered by 68.178.160.25 (25.160.178.68.host.secureserver.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 15:48:30.592416 2026] [security2:error] [pid 29458:tid 29458] [client 68.178.160.25:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.upskirtcrazy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.upskirtcrazy.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aiCFDnYNsS5oibV0JB1MRAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-03 19:34:34
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
AlexEventfahrtenIPDB
2026-06-03 19:10:21
(12 hours ago)
[Wed Jun 03 21:10:20.634896 2026] [authz_core:error] [pid 840517:tid 840517] [client 68.178.160.25:4 ...
show more
[Wed Jun 03 21:10:20.634896 2026] [authz_core:error] [pid 840517:tid 840517] [client 68.178.160.25:47754] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Click-Networks
2026-06-03 19:09:04
(12 hours ago)
Web Spam
Brute-Force
Exploited Host
๐ซ๐ท
ELYAZ
2026-06-03 19:05:44
(12 hours ago)
(wordpress) Failed wordpress login from 68.178.160.25 (US/United States/25.160.178.68.host.secureser ...
show more
(wordpress) Failed wordpress login from 68.178.160.25 (US/United States/25.160.178.68.host.secureserver.net): (CF_ENABLE)
show less
Brute-Force
๐บ๐ธ
n2nguyenn2nguyen
2026-06-03 18:49:58
(12 hours ago)
Blocked by YFC Security on https://brixzly.com โ type: xmlrpc_attempts
Brute-Force
Web App Attack
๐ซ๐ท
Sysadmin Peter
2026-06-03 18:42:31
(13 hours ago)
68.178.160.25 - - [03/Jun/2026:20:25:50 +0200] "POST /wp-login.php HTTP/2.0" 200 3088 "https://ja-so ...
show more
68.178.160.25 - - [03/Jun/2026:20:25:50 +0200] "POST /wp-login.php HTTP/2.0" 200 3088 "https://ja-solar.nz/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
68.178.160.25 - - [03/Jun/2026:20:42:30 +0200] "POST /wp-login.php HTTP/2.0" 200 3088 "https://ja-solar.nz/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Viveronese
2026-06-03 18:17:19
(13 hours ago)
Wordpress vulnerability scanning
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-03 18:15:17
(13 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 25
Exploited Host
Web App Attack
๐บ๐ธ
Jason Howell
2026-06-03 17:56:12
(13 hours ago)
68.178.160.25 - - [03/Jun/2026:11:52:37 -0500] "GET /wp-login.php HTTP/1.1" 200 5107 "-" "Mozilla/5. ...
show more
68.178.160.25 - - [03/Jun/2026:11:52:37 -0500] "GET /wp-login.php HTTP/1.1" 200 5107 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
68.178.160.25 - - [03/Jun/2026:11:52:38 -0500] "POST /wp-login.php HTTP/1.1" 200 2645 "https://mcgivernappraisal.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
68.178.160.25 - - [03/Jun/2026:12:07:53 -0500] "GET /wp-login.php HTTP/1.1" 200 5109 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
68.178.160.25 - - [03/Jun/2026:12:07:54 -0500] "POST /wp-login.php HTTP/1.1" 200 2645 "https://mcgivernappraisal.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
68.178.160.25 - - [03/Jun/2026:12:56:11 -0500] "GET /wp-login.php HTTP/1.1" 200 5108 "-" "Mozilla/5.0 (W
...
show less
Web App Attack
๐ช๐ธ
SweetHoneyPress
2026-06-03 17:51:14
(13 hours ago)
WordPress honeypot: POST to /xmlrpc.php | event_id=705797 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; ...
show more
WordPress honeypot: POST to /xmlrpc.php | event_id=705797 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36
show less
Web App Attack
Brute-Force
๐ท๐ด
SpamStoper
2026-06-03 17:44:39
(13 hours ago)
Fail2Ban - WordPress Hard - Repeated attempts to force authentication and privilege escalation
Brute-Force
Web App Attack