๐ญ๐บ
miszterx.hu
2026-08-24 06:21:51
(1 day ago)
XORP (haproxy): 16x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 16x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ง๐ช
cmbplf
2026-08-23 12:49:24
(2 days ago)
6.792 requests with url.path */xmlrpc.php
6.699 requests with url.path //xmlrpc.php
3.934 request ...
show more
6.792 requests with url.path */xmlrpc.php
6.699 requests with url.path //xmlrpc.php
3.934 requests with url.path */wp-includes/wlwmanifest.xml
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
iNetWorker
2026-08-23 12:43:02
(2 days ago)
trolling for resource vulnerabilities
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-23 12:34:52
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
Major Hostility
2026-08-23 12:27:45
(2 days ago)
"GET /wp-includes/ID3/license.txt HTTP/1.1" 404
"GET /feed/ HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/ ...
show more
"GET /wp-includes/ID3/license.txt HTTP/1.1" 404
"GET /feed/ HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/1.1" 403
"GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /2020/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /2019/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /2021/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /test/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /site/wp-includes/wlwmanifest.xml HTTP/1.1" 404
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-23 12:27:27
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 136.70.107.63 (63.107.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.70.107.63 (63.107.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 08:27:18.678235 2026] [security2:error] [pid 22285:tid 22285] [client 136.70.107.63:49604] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||magazine.angelabcomics.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "magazine.angelabcomics.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aornJrvX6cFVnbr7MS5eKwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-08-23 12:15:52
(2 days ago)
136.70.107.63 - - [23/Aug/2026:15:15:50 +0300] "POST /xmlrpc.php HTTP/1.1" 200 236 "-" "Mozilla/5.0 ...
show more
136.70.107.63 - - [23/Aug/2026:15:15:50 +0300] "POST /xmlrpc.php HTTP/1.1" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
136.70.107.63 - - [23/Aug/2026:15:15:51 +0300] "POST /xmlrpc.php HTTP/1.1" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-23 12:12:04
(2 days ago)
10 attempts against mh-misc-ban on pyrus
Web App Attack
๐ฎ๐น
VHosting
2026-08-23 12:00:08
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-08-23 11:50:09
(2 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: login.sweetpuddingtrap.top | URI: //xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-08-23 11:40:59
(2 days ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
lnklnx
2026-08-23 11:40:52
(2 days ago)
www.lnklnx.com:443 136.70.107.63 - - [23/Aug/2026:06:40:49 -0500] "GET //wp-includes/ID3/license.txt ...
show more
www.lnklnx.com:443 136.70.107.63 - - [23/Aug/2026:06:40:49 -0500] "GET //wp-includes/ID3/license.txt HTTP/1.1" 403 5137 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-23 11:40:19
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 17 hits.
show less
Brute-Force
Web App Attack