๐ญ๐บ
miszterx.hu
2026-08-27 06:01:35
(6 days ago)
XORP (haproxy): 20x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 20x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ณ๐จ
ACE-INFORMATIQUE.NC
2026-08-27 06:00:03
(6 days ago)
HTTP authentication brute-force blocked by Fail2ban
Brute-Force
๐ฒ๐ฝ
octageeks.com
2026-08-27 04:17:37
(6 days ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
๐ต๐ฑ
Budyn
2026-08-26 16:32:50
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: auth.definitelynotahoneypot.online | URI: //xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36 | BODY: <?xml version="1.0"?><methodCall><methodName>system.multicall</methodName><params><param><value><array><data> <value><struct><member><name>methodName</name><value><string>wp.getUsersBlogs</string></value></member><member><name>params</name><value><array><data><value><array><data><value><string>admin</string
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 14:58:05
(1 week ago)
Bot / scanning and/or hacking attempts: GET //?author=2 HTTP/1.1, GET //xmlrpc.php?rsd HTTP/1.1, GET ...
show more
Bot / scanning and/or hacking attempts: GET //?author=2 HTTP/1.1, GET //xmlrpc.php?rsd HTTP/1.1, GET //wp-includes/wlwmanifest.xml HTTP/1.1, GET //wp-json/oembed/1.0/embed?url=https://thustocht.nl/ HTTP/1, GET / HTTP/1.1
show less
Hacking
Web App Attack
๐ฎ๐ฑ
Dolphi
2026-08-26 14:22:13
(1 week ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-08-26 14:05:13
(1 week ago)
Abuse Detected (13)
Brute-Force
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-08-26 13:54:34
(1 week ago)
143.198.80.191 - - [26/Aug/2026:14:54:42 +0100] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 30 ...
show more
143.198.80.191 - - [26/Aug/2026:14:54:42 +0100] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 301 5694 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
143.198.80.191 - - [26/Aug/2026:14:54:43 +0100] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 301 5693 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
143.198.80.191 - - [26/Aug/2026:14:54:43 +0100] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 301 5699 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
...
show less
Hacking
Web App Attack
Anonymous
2026-08-26 13:41:37
(1 week ago)
143.198.80.191 - - [26/Aug/2026:15:41:32 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 ...
show more
143.198.80.191 - - [26/Aug/2026:15:41:32 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
143.198.80.191 - - [26/Aug/2026:15:41:34 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
143.198.80.191 - - [26/Aug/2026:15:41:35 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
143.198.80.191 - - [26/Aug/2026:15:41:36 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
143.198.80.191 - - [26/Aug/2026:15:41:37 +0200] "GET /website/wp-includes/wlwmanifest.xml HTT
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-08-26 13:28:06
(1 week ago)
-:443 143.198.80.191 - - [26/Aug/2026:15:28:04 +0200] - "GET //wp-includes/wlwmanifest.xml HTTP/1.1" ...
show more
-:443 143.198.80.191 - - [26/Aug/2026:15:28:04 +0200] - "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 1968 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-26 13:17:55
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 143.198.80.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 143.198.80.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 09:17:46.823687 2026] [security2:error] [pid 6392:tid 6392] [client 143.198.80.191:62788] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||artspacecleveland.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "artspacecleveland.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao7nep0LTPvyAs6rh7x6JQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 12:27:05
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 143.198.80.191 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 143.198.80.191 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:26:58.128587 2026] [security2:error] [pid 1763:tid 1763] [client 143.198.80.191:60021] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.theamarals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.theamarals.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao7bkjAucNQPuCGclBTc3wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
webanyone
2026-08-26 11:46:35
(1 week ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ท๐ด
clauss
2026-08-26 11:46:25
(1 week ago)
143.198.80.191 - - [26/Aug/2026:14:46:19 +0300] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 27 " ...
show more
143.198.80.191 - - [26/Aug/2026:14:46:19 +0300] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
143.198.80.191 - - [26/Aug/2026:14:46:20 +0300] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
143.198.80.191 - - [26/Aug/2026:14:46:21 +0300] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
143.198.80.191 - - [26/Aug/2026:14:46:21 +0300] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
143.198.80.191 - - [26/Aug/2026:14:46:22 +0300] "GET /website/wp-includes/wlwmanifest.xml HTTP/1.
...
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-26 11:42:31
(1 week ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection