๐ฌ๐ง
openstrike.co.uk
2026-08-25 05:14:36
(2 days ago)
18 attacks on Wordpress URLs, PHP URLs:
GET //sito/wp-includes/wlwmanifest.xml HTTP/1.1
GET //xmlrpc ...
show more
18 attacks on Wordpress URLs, PHP URLs:
GET //sito/wp-includes/wlwmanifest.xml HTTP/1.1
GET //xmlrpc.php?rsd HTTP/1.1
show less
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-25 04:06:43
(2 days ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
Anonymous
2026-08-24 10:07:02
(3 days ago)
Abuse detected: rate-limit and/or cross-site thresholds exceeded.
Bad Web Bot
๐ง๐ช
taivas.nl
2026-08-24 08:02:11
(3 days ago)
Bad_requests
Bad Web Bot
๐จ๐ญ
backslash
2026-08-24 07:48:00
(3 days ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-24 07:41:31
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 136.70.115.62 (62.115.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.70.115.62 (62.115.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:41:27.043203 2026] [security2:error] [pid 1795:tid 1795] [client 136.70.115.62:54108] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.btccasting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.btccasting.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aov1p8eyBm2grWM7mtR38wAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
ki3
2026-08-24 07:39:44
(3 days ago)
Fail2Ban: Web App Attacks and Forum Spam 136.70.115.62 1787557183.0(JST)
Web Spam
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-08-24 07:36:09
(3 days ago)
Web scanning / probing for vulnerable paths | URL: //wp2/wp-includes/wlwmanifest.xml | Evidence: boj ...
show more
Web scanning / probing for vulnerable paths | URL: //wp2/wp-includes/wlwmanifest.xml | Evidence: bojador.pt 136.70.115.62 - - [24/Aug/2026:09:16:36 +0200] \"GET //wp2/wp-includes/wlwmanifest.xml HTTP/1.1\" 404 23612 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐ง๐ช
cmbplf
2026-08-24 07:26:55
(3 days ago)
10.616 requests with url.path */xmlrpc.php
10.578 requests with url.path //xmlrpc.php
2.525 reque ...
show more
10.616 requests with url.path */xmlrpc.php
10.578 requests with url.path //xmlrpc.php
2.525 requests with url.path */wp-includes/wlwmanifest.xml
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
oralunal
2026-08-24 07:25:54
(3 days ago)
IP banned by Fail2Ban in jail oral-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 07:23:14
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 136.70.115.62 (62.115.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.70.115.62 (62.115.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:23:08.896853 2026] [security2:error] [pid 19522:tid 19552] [client 136.70.115.62:53096] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bortec-corp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bortec-corp.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aovxXHnDYK3zx94GH1TqBQAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-08-24 07:19:01
(3 days ago)
2026/08/24 07:18:59 [error] 262085#262085: *514238393 access forbidden by rule, client: 136.70.115.6 ...
show more
2026/08/24 07:18:59 [error] 262085#262085: *514238393 access forbidden by rule, client: 136.70.115.62, server: bonusnews.org, request: "GET //wp-includes/wlwmanifest.xml HTTP/2.0", host: "bonusnews.org"
2026/08/24 07:18:59 [error] 262085#262085: *514238402 access forbidden by rule, client: 136.70.115.62, server: bonusnews.org, request: "GET //xmlrpc.php?rsd HTTP/2.0", host: "bonusnews.org"
2026/08/24 07:18:59 [error] 262088#262088: *514238410 access forbidden by rule, client: 136.70.115.62, server: bonusnews.org, request: "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0", host: "bonusnews.org"
...
show less
Web App Attack
Anonymous
2026-08-24 07:16:04
(3 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, GET /?author=2 HTTP/1.1, GET /?au ...
show more
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1, GET /?author=2 HTTP/1.1, GET /?author=1 HTTP/1.1, GET /wp-json/wp/v2/users/ HTTP/1.1, GET / HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-24 07:12:25
(3 days ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐จ๐ญ
blinx
2026-08-24 07:07:14
(3 days ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack