Anonymous
2026-06-16 10:07:46
(4 days ago)
Fail2Ban WordPress login brute-force detected
Brute-Force
Web App Attack
๐ฌ๐ง
blik2108
2026-06-15 09:37:26
(5 days ago)
www.blacknellfamilyhistory.co.uk:443 95.216.86.65 - - [15/Jun/2026:10:37:26 +0100] "POST /wp-login.p ...
show more
www.blacknellfamilyhistory.co.uk:443 95.216.86.65 - - [15/Jun/2026:10:37:26 +0100] "POST /wp-login.php HTTP/1.1" 200 7156 "https://www.blacknellfamilyhistory.co.uk/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
www.blacknellfamilyhistory.co.uk:443 95.216.86.65 - - [15/Jun/2026:10:37:26 +0100] "POST /wp-login.php HTTP/1.1" 200 7133 "https://www.blacknellfamilyhistory.co.uk/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
www.blacknellfamilyhistory.co.uk:443 95.216.86.65 - - [15/Jun/2026:10:37:26 +0100] "POST /wp-login.php HTTP/1.1" 200 7156 "https://www.blacknellfamilyhistory.co.uk/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
www.blacknellfamilyhistory.co.uk:443 95.216.86.65 - - [15/Jun/2026:10:37:26 +0100] "POST /wp-login.php HTTP/1.1" 200 7160 "https://www.blacknellfamil
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-14 23:45:08
(6 days ago)
WordPress login brute-force detected by Fail2Ban in plesk-wordpress jail
Brute-Force
Web App Attack
๐บ๐ธ
nyt
2026-06-14 23:41:00
(6 days ago)
Brute-Force, Web App Attack, suspicious: Login brute-force (6/60s)
Brute-Force
Web App Attack
Anonymous
2026-06-14 23:39:38
(6 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack
Anonymous
2026-06-14 23:35:04
(6 days ago)
Fail2Ban WordPress login brute-force detected
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 17:23:26
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 95.216.86.65 (static.65.86.216.95.clients.rack- ...
show more
(mod_security) mod_security (id:225170) triggered by 95.216.86.65 (static.65.86.216.95.clients.rack-oon.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 13:23:17.363397 2026] [security2:error] [pid 16846:tid 16846] [client 95.216.86.65:34360] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||instalatoribucuresti.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "instalatoribucuresti.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai7jhQCzu8VnGGWbO-Ty5wAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 15:50:53
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 95.216.86.65 (static.65.86.216.95.clients.rack- ...
show more
(mod_security) mod_security (id:225170) triggered by 95.216.86.65 (static.65.86.216.95.clients.rack-oon.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 11:50:49.861641 2026] [security2:error] [pid 21336:tid 21336] [client 95.216.86.65:42234] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||automatebi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "automatebi.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai7N2ZpMywKf0GWy1BRfPgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neogenius
2026-06-14 15:43:19
(6 days ago)
Web App Attack
Web App Attack
Brute-Force
๐ช๐ธ
masterguru
2026-06-14 11:13:30
(6 days ago)
(PERMBLOCK) 95.216.86.65 (FI/Finland/static.65.86.216.95.clients.rack-oon.com) has had more than 4 t ...
show more
(PERMBLOCK) 95.216.86.65 (FI/Finland/static.65.86.216.95.clients.rack-oon.com) has had more than 4 temp blocks in the last 86400 secs (0-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-14 10:11:40
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 95.216.86.65 (static.65.86.216.95.clients.rack- ...
show more
(mod_security) mod_security (id:225170) triggered by 95.216.86.65 (static.65.86.216.95.clients.rack-oon.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 06:11:34.681624 2026] [security2:error] [pid 30884:tid 30884] [client 95.216.86.65:55252] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.azdar.am|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.azdar.am"] [uri "/wp-json/wp/v2/users"] [unique_id "ai5-VtwkGjMeB67ydAU39QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WPJoe
2026-06-14 05:27:03
(1 week ago)
95.216.86.65 - - [14/Jun/2026:05:27:02 +0000] "POST /wp-login.php HTTP/1.1" 200 5481 "https://violin ...
show more
95.216.86.65 - - [14/Jun/2026:05:27:02 +0000] "POST /wp-login.php HTTP/1.1" 200 5481 "https://violinbychristine.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" 0s
95.216.86.65 - - [14/Jun/2026:05:27:02 +0000] "POST /wp-login.php HTTP/1.1" 200 5445 "https://violinbychristine.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0" 0s
95.216.86.65 - - [14/Jun/2026:05:27:02 +0000] "POST /wp-login.php HTTP/1.1" 200 5481 "https://violinbychristine.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36" 0s
95.216.86.65 - - [14/Jun/2026:05:27:03 +0000] "POST /wp-login.php HTTP/1.1" 200 5446 "https://violinbychristine.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0" 0s
95.216.86.65 - - [14/Jun/2026:05:27:03 +0000] "POST /wp-login.php HT
...
show less
Web App Attack
Brute-Force
๐ซ๐ท
masterguru
2026-06-14 03:11:34
(1 week ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 95.216.86.65 (FI/Finland/static.65.86.216.95.c ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 95.216.86.65 (FI/Finland/static.65.86.216.95.clients.rack-oon.com): 1 in the last 3600 secs (0-196)
show less
Hacking
๐ช๐ธ
masterguru
2026-06-14 02:37:22
(1 week ago)
(wplogin) Failed WordPress login from 95.216.86.65 (FI/Finland/static.65.86.216.95.clients.rack-oon. ...
show more
(wplogin) Failed WordPress login from 95.216.86.65 (FI/Finland/static.65.86.216.95.clients.rack-oon.com): 5 in the last 3600 secs (0-122)
show less
Hacking
๐บ๐ธ
Victor Lรณpez
2026-06-14 02:18:14
(1 week ago)
vpardilalaw.com 95.216.86.65 - - [13/Jun/2026:21:18:13 -0500] "POST /wp-login.php HTTP/1.1" 200 2063 ...
show more
vpardilalaw.com 95.216.86.65 - - [13/Jun/2026:21:18:13 -0500] "POST /wp-login.php HTTP/1.1" 200 2063 "https://vpardilalaw.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
vpardilalaw.com 95.216.86.65 - - [13/Jun/2026:21:18:13 -0500] "POST /wp-login.php HTTP/1.1" 200 2057 "https://vpardilalaw.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64; rv:121.0) Gecko/20100101 Firefox/121.0"
vpardilalaw.com 95.216.86.65 - - [13/Jun/2026:21:18:13 -0500] "POST /wp-login.php HTTP/1.1" 200 2063 "https://vpardilalaw.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.2 Safari/605.1.15"
...
show less
Hacking
Web App Attack