🇲🇽
octageeks.com
2026-08-30 04:23:06
(15 hours ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
🇧🇪
madeit
2026-08-29 19:19:02
(1 day ago)
Web App Attack
🇪🇸
el-brujo
2026-08-29 19:17:25
(1 day ago)
139.59.229.13 - - [29/Aug/2026:21:17:23 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/2.0" 404 1587 ...
show more
139.59.229.13 - - [29/Aug/2026:21:17:23 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/2.0" 404 15875 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
139.59.229.13 - - [29/Aug/2026:21:17:25 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0" 404 15875 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
139.59.229.13 - - [29/Aug/2026:21:17:25 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/2.0" 404 15875 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
DDoS Attack
Hacking
🇩🇪
Marc
2026-08-29 17:51:37
(1 day ago)
139.59.229.13 - - [29/Aug/2026:19:51:31 +0200] "POST //xmlrpc.php HTTP/1.1" 403 929 "-" "Mozilla/5.0 ...
show more
139.59.229.13 - - [29/Aug/2026:19:51:31 +0200] "POST //xmlrpc.php HTTP/1.1" 403 929 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 139.59.229.13 - - [29/Aug/2026:19:51:33 +0200] "POST //xmlrpc.php HTTP/1.1" 403 4723 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 139.59.229.13 - - [29/Aug/2026:19:51:35 +0200] "POST //xmlrpc.php HTTP/1.1" 403 4723 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Brute-Force
Web App Attack
🇳🇿
Antinson
2026-08-29 17:46:35
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇺🇸
TPI-Abuse
2026-08-29 17:29:32
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 139.59.229.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 139.59.229.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 13:29:24.305809 2026] [security2:error] [pid 31186:tid 31186] [client 139.59.229.13:59545] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||grabagame.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "grabagame.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "apMW9MumOnA5al5LH2YRrwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
el-brujo
2026-08-29 16:20:29
(1 day ago)
139.59.229.13 - - [29/Aug/2026:18:20:27 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/2.0" 404 1588 ...
show more
139.59.229.13 - - [29/Aug/2026:18:20:27 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/2.0" 404 15886 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
139.59.229.13 - - [29/Aug/2026:18:20:28 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0" 404 15886 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
139.59.229.13 - - [29/Aug/2026:18:20:29 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/2.0" 404 15886 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
DDoS Attack
Hacking
🇺🇸
TPI-Abuse
2026-08-29 15:52:39
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 139.59.229.13 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 139.59.229.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 11:52:31.439864 2026] [security2:error] [pid 26786:tid 26786] [client 139.59.229.13:59346] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||socialstudiesforkids.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "socialstudiesforkids.com"] [uri "/wordpress/wp-json/wp/v2/users/"] [unique_id "apMAP90IvxqHYB3V4JF6bgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-29 15:22:54
(1 day ago)
XSS Attempt
Hacking
🇨🇭
zynex
2026-08-29 14:45:06
(1 day ago)
URL Probing: /wp-includes/wlwmanifest.xml
Web App Attack
🇮🇩
Burayot
2026-08-29 14:36:15
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 139.59.229.13 (SG/Singapore/-): 1 i ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 139.59.229.13 (SG/Singapore/-): 1 in the last 3600 secs
show less
Web App Attack
🇫🇮
danskefilm.dk
2026-08-29 14:00:01
(1 day ago)
wordpress login attempts
Web App Attack
🇦🇺
screwlooseit.com.au
2026-08-29 13:42:08
(1 day ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
SG/Singapore/-
Web App Attack
🇫🇷
Lunix
2026-08-29 11:48:02
(1 day ago)
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-29 11:25:00
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking