๐ณ๐ฑ
Site.eu
2026-09-01 15:05:31
(18 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-01 14:59:37
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 136.107.54.246 (246.54.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 136.107.54.246 (246.54.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:59:30.708569 2026] [security2:error] [pid 20411:tid 20411] [client 136.107.54.246:49555] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||stansbracelets.com.lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "stansbracelets.com.lahamradio.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "apboUm5QPElZVsdofeYSQwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-09-01 14:58:14
(18 hours ago)
(wordpress) Failed wordpress login from 136.107.54.246 (US/United States/246.54.107.136.bc.googleuse ...
show more
(wordpress) Failed wordpress login from 136.107.54.246 (US/United States/246.54.107.136.bc.googleusercontent.com)
show less
Brute-Force
๐จ๐ฆ
polycoda
2026-09-01 14:37:04
(19 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Web App Attack
๐ซ๐ท
Sorgin Informatique
2026-09-01 14:33:33
(19 hours ago)
soe-7 : Trying access unauthorized files/dir=>/index.php/en//wp-includes/wlwmanifest.xml
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 14:25:12
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 136.107.54.246 (246.54.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 136.107.54.246 (246.54.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 10:25:07.909156 2026] [security2:error] [pid 26926:tid 26926] [client 136.107.54.246:58149] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sneedvillefarmersmarket.daisydoesoap.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sneedvillefarmersmarket.daisydoesoap.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "apbgQyQPrkf_93G6YgFsOAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 10:13:31
(23 hours ago)
136.107.54.246 - - [01/Sep/2026:12:13:28 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 ...
show more
136.107.54.246 - - [01/Sep/2026:12:13:28 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.54.246 - - [01/Sep/2026:12:13:29 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.54.246 - - [01/Sep/2026:12:13:30 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.54.246 - - [01/Sep/2026:12:13:30 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.54.246 - - [01/Sep/2026:12:13:30 +0200] "GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 40
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 10:05:30
(23 hours ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
Anonymous
2026-09-01 10:00:44
(23 hours ago)
[redacted] 136.107.54.246 - - [01/Sep/2026:12:00:39 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" ...
show more
[redacted] 136.107.54.246 - - [01/Sep/2026:12:00:39 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 136.107.54.246 - - [01/Sep/2026:12:00:39 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 136.107.54.246 - - [01/Sep/2026:12:00:40 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 136.107.54.246 - - [01/Sep/2026:12:00:40 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
[redacted] 136.107.54.246 - - [01/Sep/2026:12:00:41 +0200] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mo
...
show less
Hacking
Web App Attack
๐ฉ๐ช
Viveronese
2026-09-01 09:59:13
(23 hours ago)
HTTP vulnerability scanning
Web App Attack
๐จ๐ญ
zynex
2026-09-01 09:54:17
(23 hours ago)
URL Probing: /wp-includes/id3/license.txt/2019/wp-includes/wlwmanifest.xml
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-01 09:52:15
(23 hours ago)
136.107.54.246 - - [01/Sep/2026:11:52:12 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 40 ...
show more
136.107.54.246 - - [01/Sep/2026:11:52:12 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.54.246 - - [01/Sep/2026:11:52:12 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.54.246 - - [01/Sep/2026:11:52:12 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.54.246 - - [01/Sep/2026:11:52:13 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.107.54.246 - - [01/Sep/2026:11:52:11 +0200] "GET / HTTP/1.1" 301 557 "-" "Mozilla/5.0
show less
Web App Attack
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 09:43:32
(23 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 09:32:39
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 136.107.54.246 (246.54.107.136.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 136.107.54.246 (246.54.107.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:32:34.864223 2026] [security2:error] [pid 29256:tid 29256] [client 136.107.54.246:57020] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||members.15tobefit.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "members.15tobefit.com"] [uri "/blog/wp-json/wp/v2/users/"] [unique_id "apabsqC3y7U8NgE_LK6dygAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 09:31:20
(1 day ago)
Fail2Ban: WordPress XML-RPC brute-force attack detected.
Bad Web Bot
Web App Attack