|
๐ต๐ฑ
Niko's Stuff
|
|
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/157.66.56.60
|
Web App Attack
Hacking
|
|
|
Anonymous
|
|
157.66.56.60 - - [18/Apr/2026:02:41:25 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 "- ...
show more
157.66.56.60 - - [18/Apr/2026:02:41:25 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
157.66.56.60 - - [18/Apr/2026:02:41:28 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
157.66.56.60 - - [18/Apr/2026:02:41:29 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
157.66.56.60 - - [18/Apr/2026:02:41:30 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
157.66.56.60 - - [18/Apr/2026:02:41:30 +0200] "GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-"
...
show less
|
Brute-Force
Web App Attack
|
|
|
๐ซ๐ท
Baking333
|
|
[redacted] 157.66.56.60 - - [10/Apr/2026:14:03:06 +0100] "GET //wp-includes/ID3/[redacted] HTTP/1.1" ...
show more
[redacted] 157.66.56.60 - - [10/Apr/2026:14:03:06 +0100] "GET //wp-includes/ID3/[redacted] HTTP/1.1" 302 5332 0/71791 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" [redacted] 157.66.56.60 - - [10/Apr/2026:14:03:06 +0100] "GET /[redacted]?rsd HTTP/1.1" 302 1604 0/68222 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
FeG Deutschland
|
|
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 247
|
Exploited Host
Web App Attack
|
|
|
๐บ๐ธ
myagent.site
|
|
Blocking for trying to access an exploit file: //xmlrpc.php?rsd
|
Hacking
|
|
|
๐ณ๐ด
jlouisbiz
|
|
157.66.56.60 - - [10/Apr/2026:08:19:29 +0000] "GET /wp-includes/id3/license.txt/xmlrpc.php?rsd HTTP/ ...
show more
157.66.56.60 - - [10/Apr/2026:08:19:29 +0000] "GET /wp-includes/id3/license.txt/xmlrpc.php?rsd HTTP/1.1" 404 734 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
|
Brute-Force
|
|
|
๐ง๐ช
cmbplf
|
|
2.588 requests from abuseipdb.com blacklisted IP (2mos4w1d)
|
Brute-Force
Bad Web Bot
|
|
|
๐ฌ๐ง
Mendip_Defender
|
|
157.66.56.60 - - [09/Apr/2026:13:06:10 +0100] "GET /wp-includes/ID3/license.txt HTTP/1.0" 404 1073 " ...
show more
157.66.56.60 - - [09/Apr/2026:13:06:10 +0100] "GET /wp-includes/ID3/license.txt HTTP/1.0" 404 1073 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
157.66.56.60 - - [09/Apr/2026:13:06:10 +0100] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.0" 404 1073 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
157.66.56.60 - - [09/Apr/2026:13:06:10 +0100] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.0" 404 1073 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
|
Hacking
Web App Attack
|
|
|
๐ต๐ฑ
sefinek.net
|
|
Triggered Cloudflare WAF (firewallCustom) from ID.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from ID.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: //shop/wp-includes/wlwmanifest.xml | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
|
Bad Web Bot
|
|
|
๐ฉ๐ช
FeG Deutschland
|
|
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
|
Exploited Host
Web App Attack
|
|
|
๐ธ๐ช
nekopavel
|
|
157.66.56.60 - - [09/Apr/2026:04:32:05 +0200]"GET //wp-includes/ID3/license.txt HTTP/1.1" 301 0"-" n ...
show more
157.66.56.60 - - [09/Apr/2026:04:32:05 +0200]"GET //wp-includes/ID3/license.txt HTTP/1.1" 301 0"-" neko.chat "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36""0.005" "0.003""-" "ID"
157.66.56.60 - - [09/Apr/2026:04:32:06 +0200]"GET /xmlrpc.php?rsd HTTP/1.1" 404 548"-" web.neko.chat "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36""0.197" "0.004""-" "ID"
157.66.56.60 - - [09/Apr/2026:04:32:06 +0200]"GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548"-" web.neko.chat "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36""0.197" "0.004""-" "ID"
...
show less
|
Hacking
Bad Web Bot
Web App Attack
|
|
|
๐จ๐ญ
YF
|
|
Unauthorized WordPress access attempt
|
Brute-Force
Web App Attack
|
|
|
Anonymous
|
|
Auto-reported by Fail2Ban (NPM-Auth)
|
Web App Attack
|
|
|
๐ซ๐ท
Baking333
|
|
[redacted] 157.66.56.60 - - [08/Apr/2026:20:50:31 +0100] "GET //wp-includes/ID3/[redacted] HTTP/1.1" ...
show more
[redacted] 157.66.56.60 - - [08/Apr/2026:20:50:31 +0100] "GET //wp-includes/ID3/[redacted] HTTP/1.1" 302 5272 0/158281 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" [redacted] 157.66.56.60 - - [08/Apr/2026:20:50:32 +0100] "GET /[redacted]?rsd HTTP/1.1" 302 1544 0/61820 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐ต๐พ
armandosaucedo.me
|
|
Threat Intelligence via ARMTI, Web Attack: GET //wp-includes/ID3/license.txt
|
Web App Attack
|
|