Major Hostility
19 Jan 2022
"GET /?author=2 HTTP/1.1" 404
"POST /xmlrpc.php HTTP/1.1" 403
Web App Attack
spam.must.die
19 Jan 2022
Jan 19 11:07:33 ubuntu-wp wordpress(nixintel.info)[129302]: Attempted user enumeration from 146.70.2 ... show more Jan 19 11:07:33 ubuntu-wp wordpress(nixintel.info)[129302]: Attempted user enumeration from 146.70.29.187
Jan 19 11:07:34 ubuntu-wp wordpress(nixintel.info)[129262]: Attempted user enumeration from 146.70.29.187
Jan 19 11:07:34 ubuntu-wp wordpress(nixintel.info)[129261]: Attempted user enumeration from 146.70.29.187
Jan 19 11:07:35 ubuntu-wp wordpress(nixintel.info)[129278]: XML-RPC authentication attempt for unknown user admin from 146.70.29.187
Jan 19 11:07:35 ubuntu-wp wordpress(nixintel.info)[129287]: XML-RPC authentication attempt for unknown user admin from 146.70.29.187
... show less
Web App Attack
vfinder
19 Jan 2022
Backdrop CMS module - Request: //wp-includes/wlwmanifest.xml
Bad Web Bot
Web App Attack
tradenet
19 Jan 2022
146.70.29.187 - - [19/Jan/2022:04:49:07 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 ... show more 146.70.29.187 - - [19/Jan/2022:04:49:07 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [19/Jan/2022:04:49:08 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [19/Jan/2022:04:49:09 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [19/Jan/2022:04:49:11 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [19/Jan/2022:04:49:12 -0600] "POST //xmlrpc.php HTTP/2.0" 200 253 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome
... show less
Bad Web Bot
Web App Attack
gwynethllewelyn.net
19 Jan 2022
Jan 19 10:08:14 autonomy wordpress(gwynethllewelyn.net)[469686]: Blocked authentication attempt for ... show more Jan 19 10:08:14 autonomy wordpress(gwynethllewelyn.net)[469686]: Blocked authentication attempt for admin from 146.70.29.187
... show less
Web App Attack
ManagedStack
19 Jan 2022
Unauthorized path/IP Access (full log not revealed as it contains sensitive data)
Hacking
Web App Attack
I.Hate.Spam
19 Jan 2022
Website hacking attempt
Hacking
Database.red
18 Jan 2022
[2022-01-18 23:28:13] Exploit probing - //wp-includes/wlwmanifest.xml
Hacking
Brute-Force
Web App Attack
BRHosting
18 Jan 2022
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack
tradenet
18 Jan 2022
146.70.29.187 - - [18/Jan/2022:15:41:39 -0600] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5.0 ... show more 146.70.29.187 - - [18/Jan/2022:15:41:39 -0600] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [18/Jan/2022:15:41:39 -0600] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [18/Jan/2022:15:41:40 -0600] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [18/Jan/2022:15:41:41 -0600] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [18/Jan/2022:15:41:42 -0600] "POST //xmlrpc.php HTTP/2.0" 200 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome
... show less
Bad Web Bot
Web App Attack
axllent
18 Jan 2022
Scanning for exploits - //wp-includes/wlwmanifest.xml
Web App Attack
MortimerCat
18 Jan 2022
Attempting to exploit via a http POST
Web App Attack
synotio
18 Jan 2022
15 attacks reported by wp-fail2ban in 15 minutes
Brute-Force
Web App Attack
CryptoYakari
18 Jan 2022
146.70.29.187 - - [18/Jan/2022:18:02:09 +0300] "GET //wp-includes/wlwmanifest.xml HTTP/1.0" 404 3589 ... show more 146.70.29.187 - - [18/Jan/2022:18:02:09 +0300] "GET //wp-includes/wlwmanifest.xml HTTP/1.0" 404 3589 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [18/Jan/2022:18:02:09 +0300] "GET //xmlrpc.php?rsd HTTP/1.0" 404 201 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [18/Jan/2022:18:02:10 +0300] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.0" 404 3589 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [18/Jan/2022:18:02:10 +0300] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.0" 404 3589 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
146.70.29.187 - - [18/Jan/2022:18:02:10 +0300] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.0" 404 3589 "-
... show less
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
pusathosting.com
04 Oct 2021
polres 146.70.29.187 [04/Oct/2021:11:23:09 "-" "POST //xmlrpc.php 500 6002
146.70.29.187 [04/O ... show more polres 146.70.29.187 [04/Oct/2021:11:23:09 "-" "POST //xmlrpc.php 500 6002
146.70.29.187 [04/Oct/2021:11:23:12 "-" "POST //xmlrpc.php 500 745
146.70.29.187 [04/Oct/2021:11:23:12 "-" "POST //xmlrpc.php 500 6002 show less
Brute-Force
Web App Attack