Anonymous
2026-06-04 14:46:32
(23 hours ago)
Failed Wordpress Logins
Web App Attack
Anonymous
2026-06-03 05:46:36
(2 days ago)
Failed Wordpress Logins
Web App Attack
๐จ๐ญ
Peter-Johann Sarbach
2026-06-03 04:44:49
(2 days ago)
Hacking website
Hacking
๐บ๐ธ
mind5t0rm
2026-06-02 13:01:21
(3 days ago)
(WPLOGIN) WP Login Attack 66.113.160.28 (US/United States/-): 3 in the last 3600 secs; Ports: *; Dir ...
show more
(WPLOGIN) WP Login Attack 66.113.160.28 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 66.113.160.28 - - [02/Jun/2026:19:07:55 +0700] "GET /wp-login.php HTTP/2.0" 200 2343 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
66.113.160.28 - - [02/Jun/2026:19:07:56 +0700] "POST /wp-login.php HTTP/2.0" 200 2498 "https://ddha.eu/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/18.3 Safari/605.1.15"
66.113.160.28 - - [02/Jun/2026:20:01:18 +0700] "GET /wp-login.php HTTP/2.0" 200 2815 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
show less
Port Scan
๐ฉ๐ช
gadix
2026-06-02 12:28:47
(3 days ago)
66.113.160.28 - - [02/Jun/2026:12:23:52 +0200] "POST /wp-login.php HTTP/2.0" 200 15629 "https://cf-f ...
show more
66.113.160.28 - - [02/Jun/2026:12:23:52 +0200] "POST /wp-login.php HTTP/2.0" 200 15629 "https://cf-fahrkompetenz.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
66.113.160.28 - - [02/Jun/2026:13:20:44 +0200] "POST /wp-login.php HTTP/2.0" 200 15621 "https://cf-fahrkompetenz.de/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
66.113.160.2
...
show less
Web App Attack
๐จ๐ฆ
KIsmay
2026-06-02 11:16:21
(3 days ago)
Jun 2 04:07:44 www4 WPAudit[356598]: 66.113.160.28 www.servicesfyi.ca "Mozilla/5.0 (Windows NT 10.0 ...
show more
Jun 2 04:07:44 www4 WPAudit[356598]: 66.113.160.28 www.servicesfyi.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" ncs-admin:ncs-admin123!! FAIL
Jun 2 04:32:12 www4 WPAudit[361678]: 66.113.160.28 servicesfyi.ca "Mozilla/5.0 (Windows NT 10.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" jody:ca2019 FAIL
Jun 2 05:23:22 www4 WPAudit[367314]: 66.113.160.28 lemoncreekcampground.ca "Mozilla/5.0 (X11; Fedora; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36" sbd-admin:sylvain@sbdadmin FAIL
Jun 2 06:31:05 www4 WPAudit[371221]: 66.113.160.28 siscobc.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36" sbd-admin:123 FAIL
Jun 2 07:16:21 www4 WPAudit[375895]: 66.113.160.28 lemoncreekcampground.ca "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-02 10:35:14
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
mind5t0rm
2026-06-02 10:16:46
(3 days ago)
(WPLOGIN) WP Login Attack 66.113.160.28 (US/United States/-): 3 in the last 3600 secs; Ports: *; Dir ...
show more
(WPLOGIN) WP Login Attack 66.113.160.28 (US/United States/-): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_TRIGGER; Logs: 66.113.160.28 - - [02/Jun/2026:16:33:34 +0700] "GET /wp-login.php HTTP/2.0" 200 1748 "https://www.inthepursuitstudio.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
66.113.160.28 - - [02/Jun/2026:16:33:35 +0700] "GET /wp-login.php HTTP/2.0" 200 1748 "https://www.inthepursuitstudio.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
66.113.160.28 - - [02/Jun/2026:17:16:43 +0700] "GET /wp-login.php HTTP/2.0" 200 3163 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
show less
Port Scan
๐ธ๐ฌ
abuseipreport.darajati
2026-06-02 08:21:19
(3 days ago)
66.113.160.28 - - [2026-06-02T16:17:19+08:00] "POST /wp-login.php HTTP/1.1" 200 2116 "https://hestia ...
show more
66.113.160.28 - - [2026-06-02T16:17:19+08:00] "POST /wp-login.php HTTP/1.1" 200 2116 "https://hestiaistiviani.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
66.113.160.28 - - [2026-06-02T16:18:46+08:00] "POST /wp-login.php HTTP/1.1" 200 2115 "https://hestiaistiviani.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
66.113.160.28 - - [2026-06-02T16:18:46+08:00] "POST /wp-login.php HTTP/1.1" 200 2115 "https://hestiaistiviani.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
66.113.160.28 - - [2026-06-02T16:21:18+08:00] "POST /wp-login.php HTTP/1.1" 200 2117 "https://hestiaistiviani.com/wp-login.php" "Mozilla/5.0 (X11; CrOS x86_64 14541.0.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
DocNetzwerk
2026-06-02 07:21:07
(3 days ago)
(wordpress) Failed wordpress login from 66.113.160.28 (US/United States/-)
Brute-Force
๐บ๐ธ
TAY
2026-06-02 07:09:34
(3 days ago)
66.113.160.28 - - [02/Jun/2026:15:00:14 +0800] "POST /wp-login.php HTTP/1.1" 200 2672 "https://littl ...
show more
66.113.160.28 - - [02/Jun/2026:15:00:14 +0800] "POST /wp-login.php HTTP/1.1" 200 2672 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
66.113.160.28 - - [02/Jun/2026:15:03:40 +0800] "POST /wp-login.php HTTP/1.1" 200 2673 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_7_4) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36"
66.113.160.28 - - [02/Jun/2026:15:09:33 +0800] "POST /wp-login.php HTTP/1.1" 200 2645 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-02 05:44:35
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 66.113.160.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 66.113.160.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 01:44:31.648943 2026] [security2:error] [pid 13036:tid 13036] [client 66.113.160.28:45184] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pleaseaddbacon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pleaseaddbacon.com"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ah5tv0pRRyHfpI7UcgEUAwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TAY
2026-06-02 05:26:50
(3 days ago)
66.113.160.28 - - [02/Jun/2026:13:18:45 +0800] "POST /wp-login.php HTTP/1.1" 200 2675 "https://littl ...
show more
66.113.160.28 - - [02/Jun/2026:13:18:45 +0800] "POST /wp-login.php HTTP/1.1" 200 2675 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
66.113.160.28 - - [02/Jun/2026:13:22:44 +0800] "POST /wp-login.php HTTP/1.1" 200 2675 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
66.113.160.28 - - [02/Jun/2026:13:26:50 +0800] "POST /wp-login.php HTTP/1.1" 200 2674 "https://littleprairie.com.my/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-02 04:40:35
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 66.113.160.28 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 66.113.160.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 00:40:27.385295 2026] [security2:error] [pid 5216:tid 5216] [client 66.113.160.28:47746] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rockinr.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rockinr.org"] [uri "/wp-json/wp/v2/users/me"] [unique_id "ah5eu0mzovd3rCnzqKaEwgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bsoft.de
2026-06-02 04:26:36
(3 days ago)
66.113.160.28 - - [02/Jun/2026:02:52:57 +0200] "GET /wp-login.php HTTP/1.1" 404 70082 "https://b-kit ...
show more
66.113.160.28 - - [02/Jun/2026:02:52:57 +0200] "GET /wp-login.php HTTP/1.1" 404 70082 "https://b-kits.com/wp-login.php" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Safari/537.36 Edg/133.0.0.0"
66.113.160.28 - - [02/Jun/2026:05:37:59 +0200] "GET /wp-login.php HTTP/1.1" 404 70043 "https://b-kits.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
66.113.160.28 - - [02/Jun/2026:06:26:35 +0200] "GET /wp-login.php HTTP/1.1" 404 69996 "https://b-kits.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
show less
Web App Attack