๐น๐ท
neron
2026-08-13 05:06:48
(4 days ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-12 01:15:11
(5 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
ArturShelby
2026-08-04 04:12:44
(1 week ago)
Suspicious path access: /wp-includes/css/buttons.css
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-03 23:58:58
(1 week ago)
cloudlinux2 fail2ban: 2026-08-04 01:54:32,132 fail2ban.actions [1475]: NOTICE [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-08-04 01:54:32,132 fail2ban.actions [1475]: NOTICE [plesk-wordpress] Ban 45.131.195.29cloudlinux2 fail2ban: 2026-08-04 01:54:27,692 fail2ban.filter [1475]: INFO [plesk-wordpress] Found 45.131.195.5 - 2026-08-04 01:54:26cloudlinux2 fail2ban: 2026-08-04 01:54:32,095 fail2ban.filter [1475]: INFO [plesk-wordpress] Found 45.131.195.29 - 2026-08-04 01:54:31cloudlinux2 fail2ban: 2026-08-04 01:54:27,625 fail2ban.filter [1475]: INFO [plesk-wordpress] Found 45.131.195.29 - 2026-08-04 01:54:26cloudlinux2 fail2ban: 2026-08-04 01:54:27,882 fail2ban.filter [1475]: INFO [plesk-wordpress] Found 45.131.195.29 - 2026-08-04 01:54:26cloudlinux2 fail2ban: 2026-08-04 01:54:32,138 fail2ban.filter [1475]: INFO [recidive] Found 45.131.195.29 - 2026-08-04 01:54:32cloudlinux2 fail2ban: 2026-08-04 01:55:43,508 fail2ban.filter [1475]: INFO [plesk-wordpress] Found 185.198.240.251 - 2026-08-04 01:55:43cloudlinux2 fail2ban: 2026-08-04 01:55:
show less
Web App Attack
๐จ๐ฆ
KIsmay
2026-08-03 03:06:46
(2 weeks ago)
Aug 2 23:06:25 www4 WPAudit[397287]: 45.131.195.29 terencegower.com "Mozilla/5.0 (Windows NT 11.0; ...
show more
Aug 2 23:06:25 www4 WPAudit[397287]: 45.131.195.29 terencegower.com "Mozilla/5.0 (Windows NT 11.0; Win64; x64; rv:120.0) Gecko/20100101 Firefox/120.0" Carezaike:Enjf!p1t23GJ FAIL
Aug 2 23:06:32 www4 WPAudit[396974]: 45.131.195.29 terencegower.com "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/121.0.0.0 Safari/537.36" xtw18387a1af:DH!bYsRn6573$3uk FAIL
Aug 2 23:06:34 www4 WPAudit[397287]: 45.131.195.29 terencegower.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safari/605.1.15" xtw183873cec:DH!bYsRn6573$3uk FAIL
Aug 2 23:06:38 www4 WPAudit[396974]: 45.131.195.29 terencegower.com "Mozilla/5.0 (X11; Ubuntu; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" admin:Admin2025@@ FAIL
Aug 2 23:06:45 www4 WPAudit[396974]: 45.131.195.29 terencegower.com "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.6 Safa
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
wbsouza
2026-08-02 03:23:30
(2 weeks ago)
CrowdSec: infra/bad-path-probe โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ฉ๐ช
neckaralb-admin.de
2026-08-02 01:24:41
(2 weeks ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ท
dynamix
2026-08-01 09:22:02
(2 weeks ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐ซ๐ฎ
KnightIndustries
2026-08-01 05:33:46
(2 weeks ago)
2026-08-01T06:54:56.546793+02:00 milkyway wordpress(learncryptography.pw)[1455612]: Authentication a ...
show more
2026-08-01T06:54:56.546793+02:00 milkyway wordpress(learncryptography.pw)[1455612]: Authentication attempt for unknown user [email protected] from 45.131.195.29
2026-08-01T06:55:00.005538+02:00 milkyway wordpress(learncryptography.pw)[1455612]: Authentication attempt for unknown user Marco from 45.131.195.29
2026-08-01T07:33:45.412009+02:00 milkyway wordpress(learncryptography.pw)[1455782]: Authentication attempt for unknown user mysticknightuk from 45.131.195.29
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-08-01 05:33:06
(2 weeks ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 29.195.131.45.rbl.malwa ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 29.195.131.45.rbl.malware.expert succeeded at REQUEST_HEADERS:x-forwarded-for. (1001000-mnz6-3)
show less
Hacking
๐บ๐ธ
Jason Howell
2026-07-31 16:27:55
(2 weeks ago)
45.131.195.29 - - [31/Jul/2026:11:27:47 -0500] "POST /wp-login.php HTTP/1.1" 200 6970 "https://ganno ...
show more
45.131.195.29 - - [31/Jul/2026:11:27:47 -0500] "POST /wp-login.php HTTP/1.1" 200 6970 "https://gannonpool.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/118.0.0.0 Safari/537.36"
45.131.195.29 - - [31/Jul/2026:11:27:50 -0500] "GET /wp-admin/index.php HTTP/1.1" 302 466 "https://gannonpool.com/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
45.131.195.29 - - [31/Jul/2026:11:27:52 -0500] "GET /wp-login.php?redirect_to=https%3A%2F%2Fgannonpool.com%2Fwp-admin%2Findex.php&reauth=1 HTTP/1.1" 200 4928 "https://gannonpool.com/wp-login.php" "Mozilla/5.0 (Windows NT 11.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
45.131.195.29 - - [31/Jul/2026:11:27:53 -0500] "POST /wp-login.php HTTP/1.1" 200 2999 "https://gannonpool.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 13_6_1; rv:121.0) Gecko/20100101 Firefox
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-07-30 16:31:44
(2 weeks ago)
3.242 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
๐ช๐ธ
masterguru
2026-07-30 14:55:44
(2 weeks ago)
wp-login request blocked, no referer. Pattern match "wp-login.php" at REQUEST_URI. (5001900-122)
Web App Attack
๐ซ๐ท
dynamix
2026-07-29 11:35:48
(2 weeks ago)
WordPress wp-login.php Brute Force Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 09:34:37
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.131.195.29 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.131.195.29 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 05:34:32.365792 2026] [security2:error] [pid 3427023:tid 3427059] [client 45.131.195.29:57097] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pref-realestate.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pref-realestate.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amnJKN6GSbIplsOqQrWfwAAAAMI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack