๐ฉ๐ช
Vegascosmetics
2026-08-26 14:19:36
(3 minutes ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-includes/ (Match: /wp-includes/)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 14:05:54
(16 minutes ago)
(mod_security) mod_security (id:225170) triggered by 157.245.152.23 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 157.245.152.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 10:05:50.846677 2026] [security2:error] [pid 999:tid 999] [client 157.245.152.23:59617] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.abeltours.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.abeltours.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao7yvkRL6YF9L0NqB8pErAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-08-26 14:01:03
(21 minutes ago)
(xmlrpc) Apache: Failed xmlrpc access from 157.245.152.23 (SG/Singapore/-): 10 in the last 3600 secs ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 157.245.152.23 (SG/Singapore/-): 10 in the last 3600 secs (0-201)
show less
Hacking
๐ฉ๐ช
McClay
2026-08-26 13:44:09
(38 minutes ago)
HTTP-404 spam:157.245.152.23 - - [26/Aug/2026:15:44:04 +0200] "GET //wp-includes/wlwmanifest.xml HTT ...
show more
HTTP-404 spam:157.245.152.23 - - [26/Aug/2026:15:44:04 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 1079 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.152.23 - - [26/Aug/2026:15:44:04 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.152.23 - - [26/Aug/2026:15:44:05 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 1079 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.152.23 - - [26/Aug/2026:15:44:05 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 1079 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.152.23 - - [26/Aug/2026:15:44:05 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 10
...
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-26 12:57:12
(1 hour ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 157.245.152.23 (SG/Singapore/-): 1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 157.245.152.23 (SG/Singapore/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-26 11:10:34
(3 hours ago)
[26/Aug/2026:14:10:33 +0300] -- 157.245.152.23 Ban reason: Scanner [CMS_GENERIC] | Request: GET //wp ...
show more
[26/Aug/2026:14:10:33 +0300] -- 157.245.152.23 Ban reason: Scanner [CMS_GENERIC] | Request: GET //wp-includes/wlwmanifest.xml HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Zundapper
2026-08-26 11:04:32
(3 hours ago)
157.245.152.23 - - [26/Aug/2026:13:04:30 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 ...
show more
157.245.152.23 - - [26/Aug/2026:13:04:30 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.152.23 - - [26/Aug/2026:13:04:31 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.152.23 - - [26/Aug/2026:13:04:31 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.152.23 - - [26/Aug/2026:13:04:31 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
157.245.152.23 - - [26/Aug/2026:13:04:32 +0200] "GET //website/wp-includes/wlwmanifest.xm
...
show less
Web App Attack
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-26 08:28:55
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 157.245.152.23 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 157.245.152.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 04:28:49.406137 2026] [security2:error] [pid 19936:tid 19936] [client 157.245.152.23:50845] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.yogawithbubba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.yogawithbubba.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao6jwfVxY-YOkDfgpXbR6QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-08-26 08:21:06
(6 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐บ๐ธ
mnsf
2026-08-26 08:05:14
(6 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-26 07:25:03
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-08-26 07:15:08
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 07:14:38
(7 hours ago)
(mod_security) mod_security (id:225170) triggered by 157.245.152.23 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 157.245.152.23 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 03:14:30.117673 2026] [security2:error] [pid 25955:tid 25992] [client 157.245.152.23:63651] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||woodamy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "woodamy.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao6SVjLPIyb-EB4jWyP5lAAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-26 07:13:30
(7 hours ago)
Wordpress brute force attempt
Brute-Force
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-08-26 07:13:27
(7 hours ago)
-:443 157.245.152.23 - - [26/Aug/2026:09:13:25 +0200] - "GET //wp-includes/wlwmanifest.xml HTTP/1.1" ...
show more
-:443 157.245.152.23 - - [26/Aug/2026:09:13:25 +0200] - "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 2024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/80.0.3987.149 Safari/537.36"
show less
Bad Web Bot