๐ต๐พ
armandosaucedo.me
2026-05-15 08:24:54
(2 weeks ago)
Threat Intelligence via ARMTI, Web Attack: GET //feed/
Web App Attack
๐ฎ๐ฑ
Dolphi
2026-05-15 05:00:03
(2 weeks ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
Anonymous
2026-05-15 04:39:39
(2 weeks ago)
139.59.126.230 - - [15/May/2026:06:39:36 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 555 ...
show more
139.59.126.230 - - [15/May/2026:06:39:36 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
139.59.126.230 - - [15/May/2026:06:39:38 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
139.59.126.230 - - [15/May/2026:06:39:38 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
139.59.126.230 - - [15/May/2026:06:39:38 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
139.59.126.230 - - [15/May/2026:06:39:39 +0200] "GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 40
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
RH5
2026-05-15 04:33:04
(2 weeks ago)
Restricted URL probing (/xmlrpc.php) (UTC 2026-05-15 04:33)
Web App Attack
๐ณ๐ฑ
Site.eu
2026-05-15 03:37:55
(2 weeks ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ธ๐ฌ
ipidentify
2026-05-15 03:11:22
(2 weeks ago)
2026-05-15T03:11:22Z GET /wordpress/wp-includes/wlwmanifest.xml
2026-05-15T03:11:22Z GET /wp/wp-incl ...
show more
2026-05-15T03:11:22Z GET /wordpress/wp-includes/wlwmanifest.xml
2026-05-15T03:11:22Z GET /wp/wp-includes/wlwmanifest.xml
2026-05-15T03:11:22Z GET /2020/wp-includes/wlwmanifest.xml
2026-05-15T03:11:22Z GET /2019/wp-includes/wlwmanifest.xml
2026-05-15T03:11:22Z GET /2021/wp-includes/wlwmanifest.xml
2026-05-15T03:11:22Z GET /shop/wp-includes/wlwmanifest.xml
2026-05-15T03:11:22Z GET /wp1/wp-includes/wlwmanifest.xml
2026-05-15T03:11:22Z GET /test/wp-includes/wlwmanifest.xml
2026-05-15T03:11:22Z GET /site/wp-includes/wlwmanifest.xml
2026-05-15T03:11:22Z GET /cms/wp-includes/wlwmanifest.xml
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-15 02:44:19
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 139.59.126.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 139.59.126.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 22:44:14.742493 2026] [security2:error] [pid 30136:tid 30136] [client 139.59.126.230:62501] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.reelvisionboard.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.reelvisionboard.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "agaIfkQmrQF8AaVwGdsBWAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jkcunningham
2026-05-15 02:33:47
(2 weeks ago)
Vulnerability scanner. Scans for wordpress filesystem, targets os and filesystem.
Web App Attack
Bad Web Bot
Port Scan
๐บ๐ธ
TPI-Abuse
2026-05-15 01:08:36
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 139.59.126.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 139.59.126.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 21:08:29.385170 2026] [security2:error] [pid 14606:tid 14606] [client 139.59.126.230:61612] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dancingbearprinting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dancingbearprinting.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "agZyDVVG7-dYR62eALTrewAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-05-15 01:00:18
(2 weeks ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐ฉ๐ช
macrob
2026-05-14 23:48:01
(2 weeks ago)
2026/05/14 23:47:59 [error] 1462735#1462735: *227917749 access forbidden by rule, client: 139.59.126 ...
show more
2026/05/14 23:47:59 [error] 1462735#1462735: *227917749 access forbidden by rule, client: 139.59.126.230, server: bin-spin.com, request: "GET /wp-includes/ID3/license.txt HTTP/1.1", host: "bin-spin.com"
2026/05/14 23:48:00 [error] 1462735#1462735: *227917749 access forbidden by rule, client: 139.59.126.230, server: bin-spin.com, request: "GET /xmlrpc.php?rsd HTTP/1.1", host: "bin-spin.com"
2026/05/14 23:48:00 [error] 1462735#1462735: *227917776 access forbidden by rule, client: 139.59.126.230, server: bin-spin.com, request: "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1", host: "bin-spin.com"
...
show less
Web App Attack
๐ซ๐ท
ELYAZ
2026-05-14 23:31:23
(2 weeks ago)
(y3) Failed access -byebye- from 139.59.126.230 (SG/Singapore/-): (CF_ENABLE)
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-14 23:05:22
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 139.59.126.230 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 139.59.126.230 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 14 19:05:15.061401 2026] [security2:error] [pid 3695:tid 3695] [client 139.59.126.230:56493] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.mayiasteadman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.mayiasteadman.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "agZVK9XkFGQZBKCF_3xx0wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-05-14 23:01:18
(2 weeks ago)
5.222 post requests in 1 hour (1w3d21h)
Brute-Force
Bad Web Bot
๐บ๐ธ
mnsf
2026-05-14 22:06:00
(2 weeks ago)
Too many Status 40X (11)
Brute-Force
Web App Attack