๐ฌ๐ท
setupgr
2026-06-16 08:39:46
(28 seconds ago)
(mod_security) mod_security (id:900001) triggered by 74.208.140.41: 1 in the last 86400 secs; Ports: ...
show more
(mod_security) mod_security (id:900001) triggered by 74.208.140.41: 1 in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: [Tue Jun 16 11:39:45.422660 2026] [security2:error] [pid 2280080:tid 2280089] [remote 74.208.140.41:40520] ModSecurity: Access denied with code 403 (phase 1). Match of "rx ^(www\\\\.)?(pankoskal\\\\.gr|sea-sound\\\\.com)$" against "REQUEST_HEADERS:Host" required. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "75"] [id "900001"] [msg "Blocked WP Login attempt on domain: ftiaxtomonosou.gr"] [severity "CRITICAL"] [tag "security"] [hostname "ftiaxtomonosou.gr"] [uri "/wp-login.php"] [unique_id "ajEL0csskNLCXd8cDXRBWwAACAg"]
show less
Port Scan
๐ซ๐ท
Campus France
2026-06-16 08:39:38
(36 seconds ago)
74.208.140.41 - - [15/Jun/2026:20:56:11 +0200] "POST /wp-login.php HTTP/1.1" 200 2495 "https://perpi ...
show more
74.208.140.41 - - [15/Jun/2026:20:56:11 +0200] "POST /wp-login.php HTTP/1.1" 200 2495 "https://perpignan.radio-campus.org/wp-login.php" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
74.208.140.41 - - [15/Jun/2026:23:30:57 +0200] "POST /wp-login.php HTTP/1.1" 200 2495 "https://perpignan.radiocampus.org/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
74.208.140.41 - - [15/Jun/2026:23:53:06 +0200] "POST /wp-login.php HTTP/1.1" 200 2495 "https://perpignan.radiocampus.org/wp-login.php" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
74.208.140.41 - - [16/Jun/2026:07:03:34 +0200] "POST /wp-login.php HTTP/1.1" 200 2495 "https://perpignan.radiocampus.org/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-06-16 08:39:00
(1 minute ago)
74.208.140.41 - - [16/Jun/2026:09:38:53 +0100] "GET /wp-login.php HTTP/1.1" 200 7827 "https://wessex ...
show more
74.208.140.41 - - [16/Jun/2026:09:38:53 +0100] "GET /wp-login.php HTTP/1.1" 200 7827 "https://wessex4x4response.org.uk/wp-login.php" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
74.208.140.41 - - [16/Jun/2026:09:38:54 +0100] "GET /wp-login.php HTTP/1.1" 200 7827 "https://wessex4x4response.org.uk/wp-login.php" "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-16 08:36:54
(3 minutes ago)
(mod_security) mod_security (id:225170) triggered by 74.208.140.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.140.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 04:36:50.100624 2026] [security2:error] [pid 5461:tid 5461] [client 74.208.140.41:45148] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dennisangellismusic.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dennisangellismusic.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajELInnLRO2eEQ7f4GD6kAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
plzenskypruvodce.cz
2026-06-16 08:33:54
(6 minutes ago)
2026-06-16T10:33:54.679134+02:00 web wordpress(varhanykolin.cz)[3244377]: Immediately block connecti ...
show more
2026-06-16T10:33:54.679134+02:00 web wordpress(varhanykolin.cz)[3244377]: Immediately block connections from 74.208.140.41
...
show less
Brute-Force
๐ฉ๐ช
reznekcs
2026-06-16 08:30:31
(9 minutes ago)
F2B wordpress ban. Logs: 74.208.140.41 - - [16/Jun/2026:10:22:19 +0200] "POST /wp-login.php HTTP/1.1 ...
show more
F2B wordpress ban. Logs: 74.208.140.41 - - [16/Jun/2026:10:22:19 +0200] "POST /wp-login.php HTTP/1.1" 200 3816 "https://reznekcsalad.hu/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
74.208.140.41 - - [16/Jun/2026:10:30:30 +0200] "POST /wp-login.php HTTP/1.1" 200 3816 "https://reznekcsalad.hu/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-06-16 08:28:11
(12 minutes ago)
(wordpress,mod_security) Login failure/trigger from 74.208.140.41 (US/United States/-)
SQL Injection
Brute-Force
๐จ๐ฆ
KIsmay
2026-06-16 08:27:52
(12 minutes ago)
Jun 15 21:48:24 ismay WPAudit[1891182]: 74.208.140.41 www.ismay.ca "Mozilla/5.0 (X11; Linux x86_64; ...
show more
Jun 15 21:48:24 ismay WPAudit[1891182]: 74.208.140.41 www.ismay.ca "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0" admin:Admin@1122 FAIL
Jun 15 23:20:51 ismay WPAudit[1891182]: 74.208.140.41 ismay.ca "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15" admin:Admin123@@ FAIL
Jun 15 23:56:27 ismay WPAudit[1949260]: 74.208.140.41 christinesutherland.com "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" christine:Christine123456 FAIL
Jun 16 00:02:10 ismay WPAudit[1891177]: 74.208.140.41 ismay.ca "Mozilla/5.0 (X11; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0" kirk:kirk31 FAIL
Jun 16 01:27:51 ismay WPAudit[1891189]: 74.208.140.41 www.ismay.ca "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" kirk:kirk45 FAIL
...
show less
Brute-Force
Web App Attack
๐ท๐บ
DZBOT
2026-06-16 08:21:49
(18 minutes ago)
DZBOT: Brute-force users IMAP/POP3
Brute-Force
๐ฉ๐ช
tvipper.com
2026-06-16 08:05:22
(34 minutes ago)
Auto reported by IDS
Web App Attack
๐บ๐ธ
TAY
2026-06-16 07:57:03
(43 minutes ago)
74.208.140.41 - - [16/Jun/2026:15:52:20 +0800] "POST /wp-login.php HTTP/1.1" 200 2750 "https://kacsb ...
show more
74.208.140.41 - - [16/Jun/2026:15:52:20 +0800] "POST /wp-login.php HTTP/1.1" 200 2750 "https://kacsb.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
74.208.140.41 - - [16/Jun/2026:15:54:20 +0800] "POST /wp-login.php HTTP/1.1" 200 2982 "https://autism-cvc.org/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
74.208.140.41 - - [16/Jun/2026:15:57:02 +0800] "POST /wp-login.php HTTP/1.1" 200 2678 "https://mail.littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 11_7_10) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Brute-Force
Anonymous
2026-06-16 07:24:52
(1 hour ago)
(PERMBLOCK) 74.208.140.41 (US/United States/-) has had more than 4 temp blocks
Hacking
๐ฉ๐ช
Marc
2026-06-16 07:04:38
(1 hour ago)
74.208.140.41 - - [16/Jun/2026:08:39:21 +0200] "GET /wp-login.php HTTP/2.0" 200 3329 "-" "Mozilla/5. ...
show more
74.208.140.41 - - [16/Jun/2026:08:39:21 +0200] "GET /wp-login.php HTTP/2.0" 200 3329 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 74.208.140.41 - - [16/Jun/2026:08:39:23 +0200] "POST /wp-login.php HTTP/2.0" 200 3241 "https://fachanwaelte-iserlohn.de/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 74.208.140.41 - - [16/Jun/2026:08:59:42 +0200] "GET /wp-login.php HTTP/2.0" 200 4080 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0" 74.208.140.41 - - [16/Jun/2026:08:59:43 +0200] "POST /wp-login.php HTTP/2.0" 403 11162 "https://www.saatschule.de/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0" 74.208.140.41 - - [16/Jun/2026:09:04:37 +0200] "GET /wp-login.php HTTP/2.0"
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 06:54:19
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 74.208.140.41 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 74.208.140.41 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 02:54:13.742875 2026] [security2:error] [pid 1506:tid 1506] [client 74.208.140.41:40476] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tracytappan.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tracytappan.net"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ajDzFSXLGi7wOPeKl7N5yAAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Yepngo
2026-06-16 06:48:18
(1 hour ago)
74.208.140.41 - - [16/Jun/2026:08:48:17 +0200] "POST /wp-login.php HTTP/2.0" 200 12100 "https://dev. ...
show more
74.208.140.41 - - [16/Jun/2026:08:48:17 +0200] "POST /wp-login.php HTTP/2.0" 200 12100 "https://dev.yepngo.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
...
show less
Brute-Force
Web App Attack