Epimetheus
2023-12-07 04:06:33
(3 days ago)
Unauthorized access attempts:
From:
159.223.59.130
Method:
H ... show more Unauthorized access attempts:
From:
159.223.59.130
Method:
HTTPS GET
URI Path:
//2019/wp-includes/wlwmanifest.xml
UA:
"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" show less
Web App Attack
Kenshin869
2023-12-07 03:22:17
(3 days ago)
Wordpress unauthorized access attempt
Brute-Force
HoneyPotEu
2023-12-07 03:09:52
(3 days ago)
159.223.59.130 - - [07/Dec/2023:04:08:52 +0100] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 400 552 ... show more 159.223.59.130 - - [07/Dec/2023:04:08:52 +0100] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 400 552 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3
... show less
Bad Web Bot
Web App Attack
Anonymous
2023-12-06 18:39:21
(3 days ago)
(wordpress) Failed wordpress XMLRPC 159.223.59.130 (SG/Singapore/os.vmdk-s-4vcpu-8gb-amd-sgp1-01)
Brute-Force
Donovan_DMC
2023-12-06 16:57:43
(3 days ago)
GET //wp-includes/wlwmanifest.xml - 159.223.59.130 (Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleW ... show more GET //wp-includes/wlwmanifest.xml - 159.223.59.130 (Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36)
[wp-includes]: WordPress Includes Scanner show less
Bad Web Bot
Web App Attack
MogBox
2023-12-06 15:19:23
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 159.223.59.130 (SG/Singapore/os.vmdk-s-4vcpu-8g ... show more (mod_security) mod_security (id:225170) triggered by 159.223.59.130 (SG/Singapore/os.vmdk-s-4vcpu-8gb-amd-sgp1-01): 1 in the last 3600 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Wed Dec 06 10:19:22.202662 2023] [security2:error] [pid 86409:tid 47744364373760] [client 159.223.59.130:0] [client 159.223.59.130] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mogbox.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mogbox.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "ZXCQ-umnpXgtUt3WJvkYNAAAAAY"] show less
Hacking
apitree
2023-12-06 14:22:59
(3 days ago)
suspicious behavior judging by the logs from the server
Phishing
Port Scan
Hacking
Spoofing
Bad Web Bot
aricooperdavis
2023-12-06 06:33:46
(4 days ago)
Probe for vulnerabilities. Path attempted: /wp-includes/wlwmanifest
Web App Attack
bigorre.org
2023-12-05 23:34:04
(4 days ago)
suspicious query, Sniffing for wordpress log://wp-includes/wlwmanifest.xml
Web App Attack
findlab
2023-12-05 19:20:01
(4 days ago)
Backdrop CMS module - scanning for vulnerable files
Bad Web Bot
Web App Attack
konstantin
2023-12-05 15:38:05
(4 days ago)
2023/12/05 18:38:01 [error] 95211#111220: *129964 access forbidden by rule, client: 159.223.59.130, ... show more 2023/12/05 18:38:01 [error] 95211#111220: *129964 access forbidden by rule, client: 159.223.59.130, server: rojnameyawelat6.com, request: "GET //xmlrpc.php?rsd HTTP/2.0", host: "rojnameyawelat6.com"
2023/12/05 18:38:04 [error] 95211#111220: *129964 access forbidden by rule, client: 159.223.59.130, server: rojnameyawelat6.com, request: "POST //xmlrpc.php HTTP/2.0", host: "rojnameyawelat6.com"
2023/12/05 18:38:04 [error] 95211#111220: *129964 access forbidden by rule, client: 159.223.59.130, server: rojnameyawelat6.com, request: "POST //xmlrpc.php HTTP/2.0", host: "rojnameyawelat6.com"
2023/12/05 18:38:04 [error] 95211#111220: *129964 access forbidden by rule, client: 159.223.59.130, server: rojnameyawelat6.com, request: "POST //xmlrpc.php HTTP/2.0", host: "rojnameyawelat6.com"
2023/12/05 18:38:05 [error] 95211#111220: *129964 access forbidden by rule, client: 159.223.59.130, server: rojnameyawelat6.com, request: "POST //xmlrpc.php HTTP/2.0", host: "rojnameyawelat6.com"
2023/12/05 18:38:
... show less
DDoS Attack
Web App Attack
conseilgouz
2023-12-05 15:26:38
(4 days ago)
vee-7 : Trying access unauthorized files/dir=>/wp-includes/wlwmanifest.xml
Hacking
spam.must.die
2023-12-05 14:24:40
(4 days ago)
IP triggered category <category>
Hacking
Web App Attack
MAGIC
2023-12-05 11:03:19
(4 days ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Kenshin869
2023-12-05 09:37:08
(5 days ago)
Wordpress unauthorized access attempt
Brute-Force