๐บ๐ธ
ambor
2026-06-22 13:18:08
(1 day ago)
Honeypot access: PHP file scan attempt: //xmlrpc.php. Path: //xmlrpc.php
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-06-22 12:35:37
(1 day ago)
WP-xmlrpc exploit
Web Spam
Blog Spam
Hacking
Exploited Host
Web App Attack
๐ฉ๐ช
webanyone
2026-06-22 12:30:35
(1 day ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ซ๐ฎ
pixiekat
2026-06-22 12:01:36
(1 day ago)
[Mon Jun 22 13:01:35.050792 2026] [authz_core:error] [pid 92929:tid 92990] [client 138.197.169.133:6 ...
show more
[Mon Jun 22 13:01:35.050792 2026] [authz_core:error] [pid 92929:tid 92990] [client 138.197.169.133:65354] AH01630: client denied by server configuration: proxy:http://localhost:13378/
[Mon Jun 22 13:01:35.182403 2026] [authz_core:error] [pid 92929:tid 92994] [client 138.197.169.133:65354] AH01630: client denied by server configuration: proxy:http://localhost:13378/wp-includes/wlwmanifest.xml
[Mon Jun 22 13:01:35.314307 2026] [authz_core:error] [pid 92929:tid 92996] [client 138.197.169.133:65354] AH01630: client denied by server configuration: proxy:http://localhost:13378/xmlrpc.php
[Mon Jun 22 13:01:35.445750 2026] [authz_core:error] [pid 92929:tid 92974] [client 138.197.169.133:65354] AH01630: client denied by server configuration: proxy:http://localhost:13378/
[Mon Jun 22 13:01:35.578970 2026] [authz_core:error] [pid 92929:tid 92998] [client 138.197.169.133:65354] AH01630: client denied by server configuration: proxy:http://localhost:13378/blog/wp-includes/wlwmanifest.xml
...
show less
Brute-Force
๐ฉ๐ช
MarkGGN
2026-06-22 11:55:04
(1 day ago)
Web attack. [1782129303] [0] [www.*] [#3420790] [0] [2] [138.197.169.133] [403] [GET] [/index.php] [ ...
show more
Web attack. [1782129303] [0] [www.*] [#3420790] [0] [2] [138.197.169.133] [403] [GET] [/index.php] [User enumeration scan (author archives)] [hex:617574686f723d31]
[1782129303] [0] [www.*] [#1792890] [0] [2] [138.197.169.133] [403] [GET] [/index.php] [User enumeration scan (author archives)] [hex:617574686f723d32]
show less
Web App Attack
๐ธ๐ช
nekopavel
2026-06-22 11:54:33
(1 day ago)
138.197.169.133 - - [22/Jun/2026:13:24:08 +0200]"GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 123 ...
show more
138.197.169.133 - - [22/Jun/2026:13:24:08 +0200]"GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 123838"-" mishashto.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36""0.615" "0.000""Toronto" "CA"
138.197.169.133 - - [22/Jun/2026:13:24:08 +0200]"GET //xmlrpc.php?rsd HTTP/1.1" 404 123784"-" mishashto.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36""0.129" "0.000""Toronto" "CA"
138.197.169.133 - - [22/Jun/2026:13:24:08 +0200]"GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 123868"-" mishashto.com "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36""0.132" "0.000""Toronto" "CA"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
NXTwoThou
2026-06-22 11:50:59
(1 day ago)
BadRequest
Web App Attack
Anonymous
2026-06-22 11:38:47
(1 day ago)
PSCSERV WPSCAN 138.197.169.133
Bad Web Bot
Web App Attack
Anonymous
2026-06-22 11:32:04
(1 day ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1, GET //?author=1 HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-22 10:43:41
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 138.197.169.133 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 138.197.169.133 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 06:43:38.395781 2026] [security2:error] [pid 23281:tid 23281] [client 138.197.169.133:63333] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mindroothealth.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mindroothealth.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajkR2j91N-L7UxM-6ww2eQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-06-22 10:38:58
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from CA.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from CA.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: //wp-includes/wlwmanifest.xml | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ณ๐ฑ
MM-bot
2026-06-22 10:30:16
(1 day ago)
URL-probe: HTTP/1.1 GET request on //wp-includes/wlwmanifest.xml (2026-06-22 12:30:16 UTC+2)
Web App Attack
Hacking
๐ฉ๐ช
strxmpp
2026-06-22 10:16:14
(1 day ago)
138.197.169.133 - - [22/Jun/2026:12:16:14 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 55 ...
show more
138.197.169.133 - - [22/Jun/2026:12:16:14 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 559 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
...
show less
Bad Web Bot
๐ช๐ธ
masterguru
2026-06-22 09:58:38
(1 day ago)
(xmlrpc) Failed xmlrpc access from 138.197.169.133 (CA/Canada/-): 5 in the last 3600 secs (0-122)
Hacking
๐บ๐ธ
mnsf
2026-06-22 09:10:39
(1 day ago)
Abuse Detected (1)
Brute-Force
Web App Attack