🇧🇪
cmbplf
2026-09-08 14:03:32
(7 hours ago)
15.786 post requests in 1 hour (2w8h32m)
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 13:05:16
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 136.70.131.58 (58.131.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.70.131.58 (58.131.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 09:05:12.310465 2026] [security2:error] [pid 2477:tid 2477] [client 136.70.131.58:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.bradleybarefoot.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.bradleybarefoot.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqAICAdChKGhaABDcN-efgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
dominioz
2026-09-08 13:04:02
(8 hours ago)
2026-09-08 13:03:05 GET /wp-includes/wlwmanifest.xml - - 136.70.131.58 HTTP/1.1 Mozilla/5.0+(Windows ...
show more
2026-09-08 13:03:05 GET /wp-includes/wlwmanifest.xml - - 136.70.131.58 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 5563
2026-09-08 13:03:05 GET /xmlrpc.php rsd - 136.70.131.58 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 5342
2026-09-08 13:03:06 GET /blog/wp-includes/wlwmanifest.xml - - 136.70.131.58 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 5573
2026-09-08 13:03:06 GET /web/wp-includes/wlwmanifest.xml - - 136.70.131.58 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/89.0.4389.114+Safari/537.36 - 404 5571
...
show less
Web App Attack
🇨🇦
TechnoSolutions CL
2026-09-08 13:02:14
(8 hours ago)
136.70.131.58 - - [08/Sep/2026:13:02:13 +0000] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 405 552 ...
show more
136.70.131.58 - - [08/Sep/2026:13:02:13 +0000] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 405 552 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
136.70.131.58 - - [08/Sep/2026:13:02:13 +0000] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 200 3992 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WellSpring
2026-09-08 12:57:00
(8 hours ago)
xmlrpc exploit on 507.today/book/xmlrpc.php — WellSpr.ing/NetSentinel civic-AI security layer
Brute-Force
Web App Attack
🇫🇷
cydit.eu
2026-09-08 12:52:57
(8 hours ago)
HTTP DoS attack detected by fail2ban on thor.cydit.eu
DDoS Attack
🇩🇪
BlueWire Hosting
2026-09-08 12:48:23
(9 hours ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
🇩🇪
Blexyel
2026-09-08 12:38:24
(9 hours ago)
136.70.131.58 - - [08/Sep/2026:14:38:24 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 ...
show more
136.70.131.58 - - [08/Sep/2026:14:38:24 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 12:38:10
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 136.70.131.58 (58.131.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.70.131.58 (58.131.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 08:38:06.056520 2026] [security2:error] [pid 2511:tid 2511] [client 136.70.131.58:58302] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.blaslandsporthorses.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.blaslandsporthorses.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqABrtp9mt-1UrrbBi6b6wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-09-08 12:32:26
(9 hours ago)
[redacted] 136.70.131.58 - - [08/Sep/2026:13:32:24 +0100] "GET //wp-includes/[redacted] HTTP/1.1" 30 ...
show more
[redacted] 136.70.131.58 - - [08/Sep/2026:13:32:24 +0100] "GET //wp-includes/[redacted] HTTP/1.1" 302 1564 0/60182 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" [redacted] 136.70.131.58 - - [08/Sep/2026:13:32:24 +0100] "GET //[redacted]?rsd HTTP/1.1" 302 1564 0/43051 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-09-08 12:32:07
(9 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇫🇮
Kimmo Rieskaniemi
2026-09-08 12:30:57
(9 hours ago)
CrowdSec triggered crowdsecurity/http-probing
Web App Attack
Hacking
🇮🇹
VHosting
2026-09-08 12:30:04
(9 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇨🇭
zynex
2026-09-08 12:28:22
(9 hours ago)
URL Probing: /2019/wp-includes/wlwmanifest.xml
Web App Attack