🇺🇸
Rbot
2026-09-06 18:21:00
(3 days ago)
10 attacks using wp-json/wp/v2/users/
Web App Attack
🇧🇪
cmbplf
2026-09-06 11:49:57
(3 days ago)
1.342 requests with url.path */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
🇺🇸
mnsf
2026-09-06 10:05:43
(3 days ago)
Abuse Detected (11)
Brute-Force
Web App Attack
🇩🇪
ghostwarriors
2026-09-06 09:50:15
(3 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-06 09:27:42
(3 days ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-06 09:23:58
(3 days ago)
cloudlinux2 fail2ban: 2026-09-06 11:18:51,871 fail2ban.filter [2048]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-06 11:18:51,871 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 34.6.201.12 - 2026-09-06 11:18:51cloudlinux2 fail2ban: 2026-09-06 11:18:53,943 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 34.6.201.12 - 2026-09-06 11:18:53cloudlinux2 fail2ban: 2026-09-06 11:19:58,169 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 136.67.92.208 - 2026-09-06 11:19:58cloudlinux2 fail2ban: 2026-09-06 11:20:01,676 fail2ban.filter [2048]: INFO [plesk-modsecurity] Found 136.67.92.208 - 2026-09-06 11:20:01cloudlinux2 fail2ban: 2026-09-06 11:20:16,486 fail2ban.filter [2048]: INFO [plesk-wordpress] Found 65.109.35.14 - 2026-09-06 11:20:16cloudlinux2 fail2ban: 2026-09-06 11:20:38,653 fail2ban.filter [2048]: INFO [plesk-wordpress] Found 98.159.37.107 - 2026-09-06 11:20:38cloudlinux2 fail2ban: 2026-09-06 11:20:42,049 fail2ban.filter [2048]: INFO [plesk-wordpress] Found 98.159.37.107 - 2026-09-06 11:20:41cloudl
show less
Web App Attack
🇫🇷
ELYAZ
2026-09-06 09:21:48
(3 days ago)
(y3) Failed access -byebye- from 104.196.141.68 (US/United States/68.141.196.104.bc.googleuserconten ...
show more
(y3) Failed access -byebye- from 104.196.141.68 (US/United States/68.141.196.104.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
🇺🇸
WeekendWeb
2026-09-06 09:19:24
(3 days ago)
Wordpress Vunerability attack
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 09:16:44
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇫🇷
dynamix
2026-09-06 09:16:26
(3 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
Anonymous
2026-09-06 09:16:14
(3 days ago)
[redacted] 104.196.141.68 - - [06/Sep/2026:11:16:07 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" ...
show more
[redacted] 104.196.141.68 - - [06/Sep/2026:11:16:07 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 104.196.141.68 - - [06/Sep/2026:11:16:08 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 104.196.141.68 - - [06/Sep/2026:11:16:08 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 104.196.141.68 - - [06/Sep/2026:11:16:09 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
[redacted] 104.196.141.68 - - [06/Sep/2026:11:16:10 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-"
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 09:15:47
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 104.196.141.68 (68.141.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 104.196.141.68 (68.141.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 05:15:40.482694 2026] [security2:error] [pid 21285:tid 21285] [client 104.196.141.68:60508] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.taekwondoit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.taekwondoit.com"] [uri "/about-us/wp-json/wp/v2/users/"] [unique_id "ap0vPLtAjkqEbRBDAH13fQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-06 09:15:10
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇴
jad-abuse
2026-09-06 09:10:13
(3 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_u ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: scanner_ua. Observed by 1 sensor(s); 1 hits.
show less
Bad Web Bot
Web App Attack