π©πͺ
LRob
2026-09-30 00:30:47
(19 hours ago)
WordPress login brute force | path: /wp-login.php | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/ ...
show more
WordPress login brute force | path: /wp-login.php | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/147.0.0.0 Safari/537.36, Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36 | 2026-09-30 00:30 UTC
show less
Brute-Force
Web App Attack
πΊπΈ
mnsf
2026-09-28 20:05:13
(1 day ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-28 14:55:45
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 79.168.244.136 (a79-168-244-136.cpe.netcabo.pt) ...
show more
(mod_security) mod_security (id:225170) triggered by 79.168.244.136 (a79-168-244-136.cpe.netcabo.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 10:55:41.442796 2026] [security2:error] [pid 28254:tid 28254] [client 79.168.244.136:43950] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.crystaljohns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.crystaljohns.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arp_7cpaUYaeK7_UMMjoHQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
ππΊ
bcsaba
2026-09-28 02:08:34
(2 days ago)
CMS (WordPress or Joomla) login attempt.
79.168.244.136 - - [28/Sep/2026:04:08:31 +0200] "POST /wp-l ...
show more
CMS (WordPress or Joomla) login attempt.
79.168.244.136 - - [28/Sep/2026:04:08:31 +0200] "POST /wp-login.php HTTP/2.0" 200 3241 "https://*REDACTED*.*REDACTED*/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/146.0.0.0 Safari/537.36"
show less
Hacking
Brute-Force
Web App Attack
π©πͺ
LRob
2026-09-27 22:47:40
(2 days ago)
This address requests our sites over plain http, is answered with a redirect to https, and never fol ...
show more
This address requests our sites over plain http, is answered with a redirect to https, and never follows it β over and over. A browser follows redirects; a scanner enumerating hosts does not. It reads nothing it asks for and only loads the server; blocked. Please check what runs on this address. | method: GET | path: /wp-login.php | 2026-09-27 22:47 UTC
show less
Bad Web Bot
Anonymous
2026-09-26 00:21:05
(4 days ago)
Web App Attack, Hacking
Hacking
Web App Attack
π©πͺ
FeG Deutschland
2026-09-25 12:18:46
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
π¬π§
gigatech
2026-09-24 19:50:05
(6 days ago)
Webserver Probing
Web App Attack
Anonymous
2026-09-22 17:15:31
(1 week ago)
Web attack blocked by Wordfence on www.museumvalkenburg.nl (2 hits). Reported by CRMON.
Web App Attack
π©πͺ
AlexEventfahrtenIPDB
2026-09-22 16:27:07
(1 week ago)
[Tue Sep 22 18:27:06.145985 2026] [authz_core:error] [pid 1465667:tid 1465692] [remote 79.168.244.13 ...
show more
[Tue Sep 22 18:27:06.145985 2026] [authz_core:error] [pid 1465667:tid 1465692] [remote 79.168.244.136:55358] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://alex-eventfahrten.de/wp-login.php
[Tue Sep 22 18:27:06.278214 2026] [authz_core:error] [pid 1465667:tid 1465678] [remote 79.168.244.136:55358] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://alex-eventfahrten.de/wp-login.php
...
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 00:48:08
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 79.168.244.136 (a79-168-244-136.cpe.netcabo.pt) ...
show more
(mod_security) mod_security (id:225170) triggered by 79.168.244.136 (a79-168-244-136.cpe.netcabo.pt): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:48:02.566922 2026] [security2:error] [pid 7599:tid 7599] [client 79.168.244.136:43286] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||instalatoribucuresti.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "instalatoribucuresti.com"] [uri "/wp-json/wp/v2/users"] [unique_id "arHQQlCOEHG1iHJMBqWH6gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-09-21 06:05:24
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
π©πͺ
FeG Deutschland
2026-09-20 05:11:25
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
Anonymous
2026-09-19 18:28:30
(1 week ago)
1789842510 - 09/19/2026 20:28:30 Host: 79.168.244.136/79.168.244.136 Port: 443 UDP Blocked
...
Port Scan
π²π½
octageeks.com
2026-09-16 04:16:57
(2 weeks ago)
Wordpress malicious attack:[octaflood]
Web App Attack