Anonymous
2026-09-09 13:47:08
(11 hours ago)
Blocked: Reason='Suspicious traffic score=60 (review-based detection)'; Requests=15
Hacking
🇪🇸
alferez
2026-08-26 10:02:56
(2 weeks ago)
wp2shell bug exploit
Hacking
Exploited Host
Web App Attack
🇷🇺
DZBOT
2026-08-26 02:34:32
(2 weeks ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
SiliSoftware
2026-08-24 00:19:41
(2 weeks ago)
/wp-includes/ID3/license.txt
Web App Attack
Anonymous
2026-08-23 21:30:48
(2 weeks ago)
165.232.163.204 - - [23/Aug/2026:23:30:42 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 ...
show more
165.232.163.204 - - [23/Aug/2026:23:30:42 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
165.232.163.204 - - [23/Aug/2026:23:30:45 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
165.232.163.204 - - [23/Aug/2026:23:30:46 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
165.232.163.204 - - [23/Aug/2026:23:30:46 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
165.232.163.204 - - [23/Aug/2026:23:30:47 +0200] "GET /wp/wp-includes/wlwmanifest.xml HTTP/1.
...
show less
Brute-Force
Web App Attack
🇺🇸
mnsf
2026-08-23 20:05:03
(2 weeks ago)
Abuse Detected (10)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 19:50:37
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 165.232.163.204 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 165.232.163.204 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 15:50:28.867741 2026] [security2:error] [pid 17438:tid 17438] [client 165.232.163.204:51274] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||seizinthebook.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "seizinthebook.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aotPBL6rRm9rjiMcUDikzgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-08-22 10:25:16
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Unknown Bot / General Web Recon. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: astropot.space | URI: /wp-json/batch/v1 | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/112.0.0.0 Safari/537.36 | BODY: {"requests": []}
show less
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-08-22 08:20:30
(2 weeks ago)
Malware host detected by rbl.malware.expert. RBL lookup of 204.163.232.165.rbl.malware.expert succee ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 204.163.232.165.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-mnz6-1)
show less
Hacking
🇵🇱
Budyn
2026-08-22 02:18:40
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: astropot.space | URI: //wp-includes/ID3/license.txt | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
🇧🇪
cmbplf
2026-08-22 01:35:55
(2 weeks ago)
311 requests with url.path */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
🇩🇪
Vegascosmetics
2026-08-21 16:53:28
(2 weeks ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-includes/ (Match: /wp-includes/)
show less
Hacking
Exploited Host
Web App Attack
🇸🇪
vaia.cloud
2026-08-21 00:05:03
(2 weeks ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇩🇪
ghostwarriors
2026-08-20 13:50:25
(2 weeks ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack