๐ซ๐ท
LRob
2026-10-07 03:33:04
(4 minutes ago)
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, ...
show more
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, secrets and build files, injected payloads. This is an attack on the sites we host, blocked on sight. Please check the machine behind it for an attack tool or malware. | method: GET | path: // | query: author=1 | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:24:41
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 149.202.40.94 (vps-df9e8a18.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 149.202.40.94 (vps-df9e8a18.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:24:33.738243 2026] [security2:error] [pid 12162:tid 12162] [client 149.202.40.94:57638] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||kdgsf.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "kdgsf.xyz"] [uri "/wp-json/wp/v2/users/"] [unique_id "asWtYUONPtduOClSCFPd5gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
david.houstin
2026-10-06 23:21:10
(4 hours ago)
149.202.40.94 - - [07/Oct/2026:01:21:02 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 466 ...
show more
149.202.40.94 - - [07/Oct/2026:01:21:02 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 466 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
149.202.40.94 - - [07/Oct/2026:01:21:02 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 259 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
149.202.40.94 - - [07/Oct/2026:01:21:02 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 466 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
149.202.40.94 - - [07/Oct/2026:01:21:02 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 466 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
149.202.40.94 - - [07/Oct/2026:01:21:02 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 466 "-" "M
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
ELYAZ
2026-10-06 19:48:49
(7 hours ago)
(y3) Failed access -byebye- from 149.202.40.94 (FR/France/vps-df9e8a18.vps.ovh.net): (CF_ENABLE)
Hacking
๐บ๐ธ
VirtualAllocEx
2026-10-06 19:02:09
(8 hours ago)
Cloudflare WAF blocked Web App Attack from 149.202.40.94. Observed 1 malicious request(s). Paths: // ...
show more
Cloudflare WAF blocked Web App Attack from 149.202.40.94. Observed 1 malicious request(s). Paths: //xmlrpc.php
show less
Web App Attack
๐ซ๐ท
Baking333
2026-10-06 15:50:21
(11 hours ago)
[redacted] 149.202.40.94 - - [06/Oct/2026:16:50:19 +0100] "GET //wp-includes/[redacted] HTTP/1.1" 30 ...
show more
[redacted] 149.202.40.94 - - [06/Oct/2026:16:50:19 +0100] "GET //wp-includes/[redacted] HTTP/1.1" 302 6773 0/94583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36" 443 [redacted] 149.202.40.94 - - [06/Oct/2026:16:50:19 +0100] "GET //[redacted]?rsd HTTP/1.1" 302 1554 0/111307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36" 443
show less
Bad Web Bot
Web App Attack
๐ช๐ธ
antivoid.xyz
2026-10-06 14:35:23
(13 hours ago)
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-10-06 13:51:01
(13 hours ago)
Probing websites for vulnerabilities
Web App Attack
SQL Injection
๐ซ๐ฎ
000rosiu
2026-10-06 13:34:08
(14 hours ago)
Triggered Cloudflare WAF (botFight) from FR.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | ...
show more
Triggered Cloudflare WAF (botFight) from FR.
Action: MANAGED_CHALLENGE | Protocol: HTTP/1.1 (GET) | Endpoint: //sito/wp-includes/wlwmanifest.xml | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ง๐ช
cmbplf
2026-10-05 23:33:47
(1 day ago)
64 requests with url.path //xmlrpc.php
Brute-Force
Bad Web Bot
๐ซ๐ท
david.houstin
2026-10-05 22:11:58
(1 day ago)
149.202.40.94 - - [06/Oct/2026:00:11:46 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 466 ...
show more
149.202.40.94 - - [06/Oct/2026:00:11:46 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 466 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
149.202.40.94 - - [06/Oct/2026:00:11:46 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 259 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
149.202.40.94 - - [06/Oct/2026:00:11:46 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 466 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
149.202.40.94 - - [06/Oct/2026:00:11:46 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 466 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
149.202.40.94 - - [06/Oct/2026:00:11:46 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 466 "-" "M
...
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
ELYAZ
2026-10-05 18:33:13
(1 day ago)
(y3) Failed access -byebye- from 149.202.40.94 (FR/France/vps-df9e8a18.vps.ovh.net): (CF_ENABLE)
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-05 17:57:58
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 149.202.40.94 (vps-df9e8a18.vps.ovh.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 149.202.40.94 (vps-df9e8a18.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 13:57:54.716600 2026] [security2:error] [pid 11057:tid 11057] [client 149.202.40.94:58052] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||drdot.xyz|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "drdot.xyz"] [uri "/wp-json/wp/v2/users/"] [unique_id "asPlIm4whhmePmPcnX_r3AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
VirtualAllocEx
2026-10-05 17:39:29
(1 day ago)
Cloudflare WAF blocked Web App Attack from 149.202.40.94. Observed 1 malicious request(s). Paths: // ...
show more
Cloudflare WAF blocked Web App Attack from 149.202.40.94. Observed 1 malicious request(s). Paths: //xmlrpc.php
show less
Web App Attack
Anonymous
2026-10-05 17:35:13
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking