π§πͺ
taivas.nl
2026-10-09 04:32:34
(22 minutes ago)
Many_bad_calls
Web App Attack
πΊπΈ
mnsf
2026-10-08 15:05:42
(13 hours ago)
Too many Status 40X (14)
Brute-Force
Web App Attack
π΅π±
Budyn
2026-10-08 15:00:16
(13 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: jenkins.astropot.space | URI: //xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π³π΄
Bots.go.to.hell
2026-10-08 14:58:47
(13 hours ago)
This IP was detected by CrowdSec triggering custom/ip-honeypot
Web App Attack
Bad Web Bot
π³π±
ipoac.nl
2026-10-08 14:57:07
(13 hours ago)
-.nl:443 136.70.206.97 - - [08/Oct/2026:16:57:05 +0200] -.nl "GET //xmlrpc.php?rsd HTTP/1.1" 403 197 ...
show more
-.nl:443 136.70.206.97 - - [08/Oct/2026:16:57:05 +0200] -.nl "GET //xmlrpc.php?rsd HTTP/1.1" 403 1972 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Bad Web Bot
Anonymous
2026-10-08 14:54:40
(14 hours ago)
[Thu Oct 08 16:54:39.425814 2026] [access_compat:error] [pid 3733742:tid 3733742] [client 136.70.206 ...
show more
[Thu Oct 08 16:54:39.425814 2026] [access_compat:error] [pid 3733742:tid 3733742] [client 136.70.206.97:57971] AH01797: client denied by server configuration: /var/www/html/wp-includes
[Thu Oct 08 16:54:39.519932 2026] [access_compat:error] [pid 3733742:tid 3733742] [client 136.70.206.97:57971] AH01797: client denied by server configuration: /var/www/html/feed
...
show less
Bad Web Bot
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-08 14:48:59
(14 hours ago)
[08/Oct/2026:17:48:58 +0300] -- 136.70.206.97 Ban reason: Scanner [CMS_GENERIC] | Request: GET //wp- ...
show more
[08/Oct/2026:17:48:58 +0300] -- 136.70.206.97 Ban reason: Scanner [CMS_GENERIC] | Request: GET //wp-includes/ID3/license.txt HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 14:47:01
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 136.70.206.97 (97.206.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.70.206.97 (97.206.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:46:53.947514 2026] [security2:error] [pid 15552:tid 15552] [client 136.70.206.97:54153] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jbernsteinpc.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jbernsteinpc.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ases3eqnBsUV2JTbo0Oc7AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
robotstxt
2026-10-08 14:43:18
(14 hours ago)
136.70.206.97 - - [08/Oct/2026:14:43:04 +0000] "GET //wp-includes/id3/license.txt/xmlrpc.php?rsd HTT ...
show more
136.70.206.97 - - [08/Oct/2026:14:43:04 +0000] "GET //wp-includes/id3/license.txt/xmlrpc.php?rsd HTTP/1.1" 403 5 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" edge="136.70.206.97"
136.70.206.97 - - [08/Oct/2026:14:43:04 +0000] "GET //wp-includes/id3/license.txt/blog/wp-includes/wlwmanifest.xml HTTP/1.1" 403 5 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" edge="136.70.206.97"
136.70.206.97 - - [08/Oct/2026:14:43:04 +0000] "GET //wp-includes/id3/license.txt/web/wp-includes/wlwmanifest.xml HTTP/1.1" 403 5 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "-" edge="136.70.206.97"
136.70.206.97 - - [08/Oct/2026:14:43:04 +0000] "GET //wp-includes/id3/license.txt/wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 403 5 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Apple
...
show less
Web App Attack
π©π°
ScamAware
2026-10-08 14:41:54
(14 hours ago)
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot ...
show more
Detected by Cloudflare Security Events via WordPress automation. Detection: bad_bot_scanner (Bad bot / scanner behavior). Hits from same IP in last 60 minutes: 1. Unique request paths counted internally: 1. Cloudflare action: block. Cloudflare source: firewallCustom.
show less
Bad Web Bot
π΅π±
bmino.pl
2026-10-08 14:35:49
(14 hours ago)
Autoban IP(2): 136.70.206.97 - Hostname: Google LLC - City: Washington - Country: United States - Or ...
show more
Autoban IP(2): 136.70.206.97 - Hostname: Google LLC - City: Washington - Country: United States - Organization: Google Cloud (us-east4) - Reason: POST //xmlrpc.php HTTP/1.1
show less
Web App Attack
Anonymous
2026-10-08 14:34:05
(14 hours ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
π§πͺ
taivas.nl
2026-10-08 14:32:11
(14 hours ago)
Bad_requests
Bad Web Bot
πΊπΈ
SiliSoftware
2026-10-08 14:31:58
(14 hours ago)
/wp-includes/ID3/license.txt
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 14:31:46
(14 hours ago)
(mod_security) mod_security (id:225170) triggered by 136.70.206.97 (97.206.70.136.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 136.70.206.97 (97.206.70.136.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:31:39.843902 2026] [security2:error] [pid 15968:tid 15968] [client 136.70.206.97:57379] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jamesallenwalker.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jamesallenwalker.com"] [uri "/wordpress/wp-json/wp/v2/users/"] [unique_id "asepS26FsRBdcESkzKnnwAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack