๐ณ๐ฑ
JCB
2026-06-11 08:35:00
(2 hours ago)
/wp-includes/wlwmanifest.xml
Brute-Force
Web App Attack
๐ณ๐ฑ
tmiland
2026-06-10 12:30:58
(22 hours ago)
(wordpress_xmlrpc) WordPress XMLPRC Attack 136.107.45.99 (US/United States/99.45.107.136.bc.googleus ...
show more
(wordpress_xmlrpc) WordPress XMLPRC Attack 136.107.45.99 (US/United States/99.45.107.136.bc.googleusercontent.com): 3 in the last 3600 secs; IP: 136.107.45.99; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 136.107.45.99 - - [10/Jun/2026:14:30:53 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 200 792 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 136.107.45.99 - - [10/Jun/2026:14:30:55 +0200] "POST //xmlrpc.php HTTP/1.1" 200 413 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 136.107.45.99 - - [10/Jun/2026:14:30:55 +0200] "POST //xmlrpc.php HTTP/1.1" 200 413 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Brute-Force
๐ณ๐ฟ
Antinson
2026-06-10 12:25:57
(22 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-10 12:19:21
(22 hours ago)
(mod_security) mod_security (id:225170) triggered by 136.107.45.99 (99.45.107.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.107.45.99 (99.45.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 08:19:15.576768 2026] [security2:error] [pid 27701:tid 27701] [client 136.107.45.99:62098] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.spacebooger.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.spacebooger.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ailWQ3qJTsLUdWxiSJY57gAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
strxmpp
2026-06-10 12:06:12
(23 hours ago)
136.107.45.99 - - [10/Jun/2026:14:06:11 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 4380 ...
show more
136.107.45.99 - - [10/Jun/2026:14:06:11 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 4380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-10 12:02:36
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 136.107.45.99 (99.45.107.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.107.45.99 (99.45.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 08:02:29.571735 2026] [security2:error] [pid 24390:tid 24390] [client 136.107.45.99:62289] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||qed-consulting.co|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "qed-consulting.co"] [uri "/wp-json/wp/v2/users/"] [unique_id "ailSVV6hHGQ8QNxpTeNjoAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-06-10 11:57:16
(23 hours ago)
136.107.45.99 - - [10/Jun/2026:13:57:15 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
136.107.45.99 - - [10/Jun/2026:13:57:15 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ท๐ด
INTEQ
2026-06-10 11:53:59
(23 hours ago)
Web attack from 136.107.45.99
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-06-10 11:52:22
(23 hours ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐บ๐ธ
aks4226
2026-06-10 11:46:07
(23 hours ago)
Bot search, attacking common web applications.
Web App Attack
๐ต๐ฑ
strefapi_com
2026-06-10 11:45:49
(23 hours ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
Major Hostility
2026-06-10 11:41:31
(23 hours ago)
"GET /wp-includes/ID3/license.txt HTTP/1.1" 404
"GET /feed/ HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/ ...
show more
"GET /wp-includes/ID3/license.txt HTTP/1.1" 404
"GET /feed/ HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/1.1" 403
"GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /2020/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /2019/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /2021/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /test/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /site/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /cms/wp-includes%2
show less
Web App Attack
Anonymous
2026-06-10 11:39:45
(23 hours ago)
Fail2Ban - Wordpress brute-force
...
Brute-Force
Web App Attack
๐ฉ๐ช
Lino Project
2026-06-10 11:37:15
(23 hours ago)
136.107.45.99 - - [10/Jun/2026:13:37:11 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 403 657 "-" "Mozilla/ ...
show more
136.107.45.99 - - [10/Jun/2026:13:37:11 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 403 657 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-10 11:28:41
(23 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking