Anonymous
2026-09-01 12:31:02
(9 hours ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1, GET / HTTP/1.1, GET //?author=2 ...
show more
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1, GET / HTTP/1.1, GET //?author=2 HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 12:22:04
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 107.149.152.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 107.149.152.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:22:01.206106 2026] [security2:error] [pid 1713:tid 1713] [client 107.149.152.136:25817] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mobileonlinecasinos.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mobileonlinecasinos.co"] [uri "/wp-json/wp/v2/users/"] [unique_id "apbDaZ_ORPj-EXk3_F1LBAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
factor1
2026-09-01 12:21:47
(9 hours ago)
CrowdSec at sherman Reports Abuse
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-01 12:13:47
(10 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-01 12:11:47
(10 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BR, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BR, Attack patterns: WordPress scanning
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-09-01 12:07:41
(10 hours ago)
107.149.152.136 - - [01/Sep/2026:15:07:40 +0300] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 41 ...
show more
107.149.152.136 - - [01/Sep/2026:15:07:40 +0300] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 41 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-01 11:59:16
(10 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 11:29:42
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 107.149.152.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 107.149.152.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:29:34.891032 2026] [security2:error] [pid 27415:tid 27415] [client 107.149.152.136:58913] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bickleton.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bickleton.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "apa3HtReAkJeZ5tdLLjNSgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Omar Martรญnez
2026-09-01 10:52:10
(11 hours ago)
107.149.152.136 - - [01/Sep/2026:04:52:09 -0600] "GET //wp-json/wp/v2/users/ HTTP/1.1" 200 1733 "-" ...
show more
107.149.152.136 - - [01/Sep/2026:04:52:09 -0600] "GET //wp-json/wp/v2/users/ HTTP/1.1" 200 1733 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
...
show less
Phishing
Email Spam
Blog Spam
Anonymous
2026-09-01 10:50:05
(11 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ญ๐บ
bcsaba
2026-09-01 10:47:31
(11 hours ago)
Repeated request on blocked xmlrpc.php.
107.149.152.136 - - [01/Sep/2026:12:47:24 +0200] "POST //xml ...
show more
Repeated request on blocked xmlrpc.php.
107.149.152.136 - - [01/Sep/2026:12:47:24 +0200] "POST //xmlrpc.php HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:34:22
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 107.149.152.136 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 107.149.152.136 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:34:15.792876 2026] [security2:error] [pid 22561:tid 22561] [client 107.149.152.136:59465] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.crep-psych.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.crep-psych.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "apaqJ-i8oElJFU99UnLG7QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-09-01 09:55:16
(12 hours ago)
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kinesk ...
show more
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kineskinja)
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-01 09:52:48
(12 hours ago)
107.149.152.136 - - [01/Sep/2026:11:52:44 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 ...
show more
107.149.152.136 - - [01/Sep/2026:11:52:44 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
107.149.152.136 - - [01/Sep/2026:11:52:46 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
107.149.152.136 - - [01/Sep/2026:11:52:47 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
107.149.152.136 - - [01/Sep/2026:11:52:48 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/79.0 Safari/537.36"
107.149.152.136 - - [01/Sep/2026:11:52:48 +0200] "GET /website/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-01 09:34:41
(12 hours ago)
Try to access /xmlrpc.php?rsd
Web App Attack