๐ต๐ฑ
tomkolp
2026-05-20 02:00:04
(2 weeks ago)
CSF/LFD block: WPLOGIN - WP Login Attack 91.134.89.60 (FR/France/vps-fa8d7aab.vps.ovh.net): 5 in the ...
show more
CSF/LFD block: WPLOGIN - WP Login Attack 91.134.89.60 (FR/France/vps-fa8d7aab.vps.ovh.net): 5 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ฉ๐ช
nyt
2026-05-20 01:39:33
(2 weeks ago)
Repeated WordPress login POSTs blocked by WAF (3 in 6h)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 00:26:39
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.134.89.60 (vps-fa8d7aab.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 91.134.89.60 (vps-fa8d7aab.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 20:26:33.214049 2026] [security2:error] [pid 25410:tid 25410] [client 91.134.89.60:55318] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wealthsec.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wealthsec.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agz_uZY_O7VSV3IUNS_kpQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-05-19 23:30:05
(2 weeks ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐ฉ๐ช
Marc
2026-05-19 23:05:27
(2 weeks ago)
Brute-Force
๐ซ๐ท
tecnicorioja
2026-05-19 22:01:17
(2 weeks ago)
wp-login attack [19/May/2026:19:10:14
Brute-Force
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-05-19 20:54:25
(2 weeks ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TAY
2026-05-19 20:47:15
(2 weeks ago)
91.134.89.60 - - [20/May/2026:04:42:04 +0800] "POST /wp-login.php HTTP/1.1" 200 2677 "https://www.li ...
show more
91.134.89.60 - - [20/May/2026:04:42:04 +0800] "POST /wp-login.php HTTP/1.1" 200 2677 "https://www.littleprairie.com.my/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
91.134.89.60 - - [20/May/2026:04:45:37 +0800] "POST /wp-login.php HTTP/1.1" 200 2679 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64; rv:133.0) Gecko/20100101 Firefox/133.0"
91.134.89.60 - - [20/May/2026:04:47:14 +0800] "POST /wp-login.php HTTP/1.1" 200 2675 "https://www.littleprairie.com.my/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐ณ๐ฑ
MatStef132
2026-05-19 20:24:53
(2 weeks ago)
MatShield L7: blocked on chat.justchat.icu (ua-quarantined)
Bad Web Bot
๐ฉ๐ช
BlueWire Hosting
2026-05-19 20:17:03
(2 weeks ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐บ๐ธ
RLDD
2026-05-19 20:16:10
(2 weeks ago)
WP login attempts -nov
Brute-Force
๐บ๐ธ
integrantservices.com
2026-05-19 20:16:02
(2 weeks ago)
(PERMBLOCK) 91.134.89.60 (FR/France/vps-fa8d7aab.vps.ovh.net) has had more than 4 temp blocks
Hacking
๐บ๐ธ
lostswordfish.com
2026-05-19 20:08:03
(2 weeks ago)
Wordfence waf block on registrymatters
Web App Attack
๐ฉ๐ช
AlexEventfahrtenIPDB
2026-05-19 20:05:31
(2 weeks ago)
[Tue May 19 22:05:30.711690 2026] [authz_core:error] [pid 2145304:tid 2145304] [client 91.134.89.60: ...
show more
[Tue May 19 22:05:30.711690 2026] [authz_core:error] [pid 2145304:tid 2145304] [client 91.134.89.60:50290] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php
[Tue May 19 22:05:31.000642 2026] [authz_core:error] [pid 2145307:tid 2145307] [client 91.134.89.60:50304] AH01630: client denied by server configuration: /var/www/std-sites/cadillac/wp-login.php, referer: https://powerstar.spdns.de/wp-login.php
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-19 19:46:45
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 91.134.89.60 (vps-fa8d7aab.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:225170) triggered by 91.134.89.60 (vps-fa8d7aab.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 15:46:37.341803 2026] [security2:error] [pid 28139:tid 28139] [client 91.134.89.60:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.upskirtcrazy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.upskirtcrazy.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "agy-HUlkzK79JMqQa5sCBAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack