๐ซ๐ท
tecnicorioja
2026-06-26 22:01:24
(1 day ago)
wp-login attack [26/Jun/2026:13:57:24
Brute-Force
Web App Attack
Anonymous
2026-06-26 20:20:02
(1 day ago)
| CMS scanner: 3 domains targeted (CMS (WordPress or Joomla) login attempt.)
Web App Attack
Hacking
SQL Injection
Anonymous
2026-06-26 16:30:45
(1 day ago)
WordPress Brute Force
Brute-Force
๐บ๐ธ
nationaleventpros.com
2026-06-26 16:11:14
(1 day ago)
WordPress login attempt
Brute-Force
๐ซ๐ท
ELYAZ
2026-06-26 16:09:11
(1 day ago)
(y4) Failed scan -byebye- from 91.228.199.235 (PL/Poland/vz17994.dahost.pl): (CF_ENABLE)
Hacking
๐ฉ๐ช
netclix.gr
2026-06-26 15:48:55
(1 day ago)
(wordpress) Failed wordpress login from 91.228.199.235 (PL/Poland/vz17994.dahost.pl): (CF_ENABLE)
Brute-Force
๐ง๐ช
cmbplf
2026-06-26 15:15:37
(1 day ago)
1.910 requests to many distinct domains in 1 hour (3w6d11h)
Brute-Force
Bad Web Bot
Anonymous
2026-06-26 15:02:05
(1 day ago)
[Fri Jun 26 15:14:52.997954 2026] [authz_core:error] [pid 1486:tid 1597] [client 91.228.199.235:5068 ...
show more
[Fri Jun 26 15:14:52.997954 2026] [authz_core:error] [pid 1486:tid 1597] [client 91.228.199.235:50680] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php
[Fri Jun 26 15:14:55.586093 2026] [authz_core:error] [pid 1486:tid 1599] [client 91.228.199.235:50680] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php, referer: https://pre.cimt-precision.de/wp-login.php
[Fri Jun 26 17:02:01.343716 2026] [authz_core:error] [pid 1485:tid 1628] [client 91.228.199.235:49240] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php
[Fri Jun 26 17:02:04.248377 2026] [authz_core:error] [pid 1485:tid 1629] [client 91.228.199.235:49240] AH01630: client denied by server configuration: /var/www/cimt-precision/wp-login.php, referer: https://pre.cimt-precision.de/wp-login.php
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-26 13:45:18
(1 day ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-26 13:18:59
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 91.228.199.235 (vz17994.dahost.pl): 1 in the la ...
show more
(mod_security) mod_security (id:225170) triggered by 91.228.199.235 (vz17994.dahost.pl): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 26 09:18:54.552209 2026] [security2:error] [pid 533:tid 533] [client 91.228.199.235:44344] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mayiasteadman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mayiasteadman.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "aj58PlghRG5J2t0JxjxdAAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-26 13:17:24
(1 day ago)
(modsec_5040) ModSec 5040: API Basic Auth blocked from 91.228.199.235 (PL/Poland/vz17994.dahost.pl): ...
show more
(modsec_5040) ModSec 5040: API Basic Auth blocked from 91.228.199.235 (PL/Poland/vz17994.dahost.pl): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ฉ๐ช
Hazzard
2026-06-26 13:15:06
(1 day ago)
(wordpress) Failed wordpress login from 91.228.199.235 (PL/Poland/-/-/vz17994.dahost.pl/[redacted]): ...
show more
(wordpress) Failed wordpress login from 91.228.199.235 (PL/Poland/-/-/vz17994.dahost.pl/[redacted]): (CF_ENABLE)
show less
Brute-Force
๐ฉ๐ช
Marc
2026-06-26 12:52:24
(1 day ago)
91.228.199.235 - - [26/Jun/2026:14:49:02 +0200] "GET /wp-login.php HTTP/2.0" 200 3346 "-" "Mozilla/5 ...
show more
91.228.199.235 - - [26/Jun/2026:14:49:02 +0200] "GET /wp-login.php HTTP/2.0" 200 3346 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0" 91.228.199.235 - - [26/Jun/2026:14:49:04 +0200] "POST /wp-login.php HTTP/2.0" 200 4029 "https://lostplace.art/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0" 91.228.199.235 - - [26/Jun/2026:14:49:34 +0200] "GET /wp-login.php HTTP/2.0" 200 3456 "-" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 91.228.199.235 - - [26/Jun/2026:14:49:36 +0200] "POST /wp-login.php HTTP/2.0" 200 3293 "https://als-arnsberg.eu/wp-login.php" "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" 91.228.199.235 - - [26/Jun/2026:14:52:23 +0200] "GET /wp-login.php HTTP/2.0" 200 3456 "https://als-arnsberg.de/wp-login.php" "Mozilla/
show less
Brute-Force
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-26 12:46:04
(1 day ago)
Wordfence waf block on fairregistry
Web App Attack
๐จ๐ฟ
ptlab
2026-06-26 12:45:12
(1 day ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack