๐บ๐ธ
infra-monitor
2026-07-19 14:00:07
(2 months ago)
Automated ban via infra-monitor: wp-sensitive-paths, wordpress-probe
Web App Attack
๐ฉ๐ช
IVski.com
2026-07-19 13:38:52
(2 months ago)
IVski WAF | WordPress scanner detected - probing wp-content, xmlrpc or wp-login
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 13:33:38
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 136.107.129.162 (162.129.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:225170) triggered by 136.107.129.162 (162.129.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 09:33:31.598742 2026] [security2:error] [pid 3381:tid 3381] [client 136.107.129.162:55784] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.josephshv.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.josephshv.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "alzSK8pwnvlztjrQP3gluAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Magnytu2
2026-07-19 13:31:54
(2 months ago)
joe-7 : Trying access unauthorized files/dir=>//wp-includes/ID3/license.txt
Hacking
๐ง๐ฌ
HighWay
2026-07-19 13:26:18
(2 months ago)
136.107.129.162 - - [19/Jul/2026:13:26:16 +0000] "POST //xmlrpc.php HTTP/1.1" 200 755 "-" "Mozilla/5 ...
show more
136.107.129.162 - - [19/Jul/2026:13:26:16 +0000] "POST //xmlrpc.php HTTP/1.1" 200 755 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.129.162 - - [19/Jul/2026:13:26:16 +0000] "POST //xmlrpc.php HTTP/1.1" 200 755 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.129.162 - - [19/Jul/2026:13:26:16 +0000] "POST //xmlrpc.php HTTP/1.1" 200 755 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Port Scan
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-07-19 13:21:08
(2 months ago)
Too many 404 requests [BY]
Web App Attack
๐ซ๐ฎ
as211431.net
2026-07-19 13:20:32
(2 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: //2020/wp-includes/wlwmanifest.xml
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-07-19 13:19:38
(2 months ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-07-19 13:14:08
(2 months ago)
[server.techsupportltd.gr] httpd-xmlrpc-post: sites=www.jewelinas.gr; logs=/var/log/httpd/domains/je ...
show more
[server.techsupportltd.gr] httpd-xmlrpc-post: sites=www.jewelinas.gr; logs=/var/log/httpd/domains/jewelyn.gr.log; samples=//xmlrpc.php
show less
Brute-Force
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-07-19 13:10:18
(2 months ago)
This IP was detected by CrowdSec triggering custom/ip-honeypot
Web App Attack
Bad Web Bot
๐ณ๐ฑ
ipoac.nl
2026-07-19 13:09:55
(2 months ago)
-.nl:443 136.107.129.162 - - [19/Jul/2026:15:09:54 +0200] -.nl "GET //xmlrpc.php?rsd HTTP/1.1" 403 1 ...
show more
-.nl:443 136.107.129.162 - - [19/Jul/2026:15:09:54 +0200] -.nl "GET //xmlrpc.php?rsd HTTP/1.1" 403 1972 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Bad Web Bot
Anonymous
2026-07-19 13:09:12
(2 months ago)
[Sun Jul 19 15:09:11.603976 2026] [access_compat:error] [pid 1603942:tid 1603942] [client 136.107.12 ...
show more
[Sun Jul 19 15:09:11.603976 2026] [access_compat:error] [pid 1603942:tid 1603942] [client 136.107.129.162:57714] AH01797: client denied by server configuration: /var/www/html/wp-includes
[Sun Jul 19 15:09:11.700289 2026] [access_compat:error] [pid 1603942:tid 1603942] [client 136.107.129.162:57714] AH01797: client denied by server configuration: /var/www/html/feed
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-19 13:08:24
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 136.107.129.162 (162.129.107.136.bc.googleuserc ...
show more
(mod_security) mod_security (id:225170) triggered by 136.107.129.162 (162.129.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 09:08:20.003198 2026] [security2:error] [pid 1749377:tid 1749377] [client 136.107.129.162:58409] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.jdeloa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.jdeloa.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "alzMQ8HClRNK-DuLqcezEAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MaxMeier
2026-07-19 13:08:01
(2 months ago)
136.107.129.162 - - [19/Jul/2026:15:07:11 +0200] "" 400 0 "-" "-"
136.107.129.162 - - [19/Jul/2026:1 ...
show more
136.107.129.162 - - [19/Jul/2026:15:07:11 +0200] "" 400 0 "-" "-"
136.107.129.162 - - [19/Jul/2026:15:07:11 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.129.162 - - [19/Jul/2026:15:07:11 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.129.162 - - [19/Jul/2026:15:07:11 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.129.162 - - [19/Jul/2026:15:07:12 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.129.162 - - [19/Jul/2026:15:07:12 +0200] "
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-07-19 13:03:47
(2 months ago)
(wordpress-404) Searching for non-existent wordpress installs from 136.107.129.162 (US/United States ...
show more
(wordpress-404) Searching for non-existent wordpress installs from 136.107.129.162 (US/United States/District of Columbia/Washington/162.129.107.136.bc.googleusercontent.com/[redacted])
show less
Brute-Force