π¨π
filou812
2026-07-22 03:20:58
(1 day ago)
urls tried are "//wp-includes/wlwmanifest.xml", "//blog/wp-includes/wlwmanifest.xml", "//web/wp-incl ...
show more
urls tried are "//wp-includes/wlwmanifest.xml", "//blog/wp-includes/wlwmanifest.xml", "//web/wp-includes/wlwmanifest.xml", "//wordpress/wp-includes/wlwmanifest.xml", "//website/wp-includes/wlwmanifest.xml"
show less
Web App Attack
πΈπͺ
vaia.cloud
2026-07-22 02:40:01
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
π©πͺ
abdubhai
2026-07-22 01:12:15
(1 day ago)
157.245.1.52 - - [22/Jul/2026:06
...
Brute-Force
π³π±
WeCloudit-Anti-Abuse
2026-07-22 00:36:31
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π¦πΊ
Klaverstyn
2026-07-21 23:01:43
(1 day ago)
Scanning for vulnerable paths/scripts
Bad Web Bot
πΊπΈ
etu brutus
2026-07-21 20:54:54
(1 day ago)
157.245.1.52 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
π«π·
Magnytu2
2026-07-21 19:46:20
(1 day ago)
mae-7 : Trying access unauthorized files/dir=>//wp-includes/wlwmanifest.xml
Hacking
Anonymous
2026-07-21 17:47:00
(1 day ago)
157.245.1.52 - - [21/Jul/2026:19:46:59 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows N ...
show more
157.245.1.52 - - [21/Jul/2026:19:46:59 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.1.52 - - [21/Jul/2026:19:46:59 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.1.52 - - [21/Jul/2026:19:46:59 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.1.52 - - [21/Jul/2026:19:46:59 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.1.52 - - [21/Jul/2026:19:46:59 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTM
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-07-21 14:59:58
(1 day ago)
Scenarios: http-probing
Total requests: 92
Web App Attack
π³π±
ipoac.nl
2026-07-21 14:57:06
(1 day ago)
-.nl:443 157.245.1.52 - - [21/Jul/2026:16:57:05 +0200] -.nl "GET //wp-includes/wlwmanifest.xml HTTP/ ...
show more
-.nl:443 157.245.1.52 - - [21/Jul/2026:16:57:05 +0200] -.nl "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 1983 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
show less
Bad Web Bot
Anonymous
2026-07-21 14:32:54
(2 days ago)
(wordpress) Failed wordpress login from 157.245.1.52 (US/United States/New Jersey/Clifton/-/[redacte ...
show more
(wordpress) Failed wordpress login from 157.245.1.52 (US/United States/New Jersey/Clifton/-/[redacted])
show less
Brute-Force
π©πͺ
maxpower
2026-07-21 13:31:01
(2 days ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 157.245.1.52 (US/United States/-): 1 in the la ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 157.245.1.52 (US/United States/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 157.245.1.52 - - [21/Jul/2026:15:31:00 +0200] "GET //wp-json/wp/v2/users/ HTTP/2.0" 200 338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36" "157.245.1.52" host=italpmiabruzzo.it
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-07-21 12:08:31
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 157.245.1.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.245.1.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 08:08:25.132139 2026] [security2:error] [pid 31098:tid 31098] [client 157.245.1.52:61511] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.instalatoribucuresti.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.instalatoribucuresti.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al9hOUqLg2l8EoepmiGwKAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π΄
jad-abuse
2026-07-21 12:07:40
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 20 hits.
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-21 11:33:03
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 157.245.1.52 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 157.245.1.52 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 07:32:58.737264 2026] [security2:error] [pid 353753:tid 353753] [client 157.245.1.52:54159] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||leroyrankin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "leroyrankin.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "al9Y6pg9MIDI_dYS8n7BQgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack