๐บ๐ธ
ruusvuu
2026-06-21 02:56:21
(4 weeks ago)
Automated abuse report: 50 attack/probe requests from DigitalOcean, LLC / SG.
Targeted paths: //wp-i ...
show more
Automated abuse report: 50 attack/probe requests from DigitalOcean, LLC / SG.
Targeted paths: //wp-includes/wlwmanifest.xml, //xmlrpc.php, //blog/wp-includes/wlwmanifest.xml, //web/wp-includes/wlwmanifest.xml, //wordpress/wp-includes/wlwmanifest.xml.
Sample log lines:
[rulesandprompts] 06/20/2026, 19:56:19 MST | 168.144.110.217 | GET //shop/wp-includes/wlwmanifest.xml 404 172b 1.010 ms | ref=-
[rulesandprompts] 06/20/2026, 19:56:20 MST | 168.144.110.217 | GET //wp1/wp-includes/wlwmanifest.xml 404 171b 0.946 ms | ref=-
[rulesandprompts] 06/20/2026, 19:56:20 MST | 168.144.110.217 | GET //test/wp-includes/wlwmanifest.xml 404 172b 0.896 ms | ref=-
Detected by an automated web-server log monitor.
show less
Web App Attack
Anonymous
2026-06-20 14:23:51
(4 weeks ago)
168.144.110.217 - - [20/Jun/2026:16:23:31 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Window ...
show more
168.144.110.217 - - [20/Jun/2026:16:23:31 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
168.144.110.217 - - [20/Jun/2026:16:23:33 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
168.144.110.217 - - [20/Jun/2026:16:23:34 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
168.144.110.217 - - [20/Jun/2026:16:23:35 +0200] "GET /xmlrpc.php?rsd HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
168.144.110.217 - - [20/Jun/2026:16:23:36 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrom
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-06-20 08:00:10
(1 month ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ซ๐ท
ELYAZ
2026-06-20 07:26:21
(1 month ago)
(wordpress) Failed wordpress login from 168.144.110.217 (SG/Singapore/-): (CF_ENABLE)
Brute-Force
๐บ๐ธ
ruusvuu
2026-06-19 14:29:21
(1 month ago)
Automated abuse report: 50 attack/probe requests from DigitalOcean, LLC / SG.
Targeted paths: //wp-i ...
show more
Automated abuse report: 50 attack/probe requests from DigitalOcean, LLC / SG.
Targeted paths: //wp-includes/wlwmanifest.xml, //xmlrpc.php, //blog/wp-includes/wlwmanifest.xml, //web/wp-includes/wlwmanifest.xml, //wordpress/wp-includes/wlwmanifest.xml.
Sample log lines:
[rulesandprompts] 06/19/2026, 07:29:19 MST | 168.144.110.217 | GET //media/wp-includes/wlwmanifest.xml 404 173b 0.623 ms | ref=-
[rulesandprompts] 06/19/2026, 07:29:19 MST | 168.144.110.217 | GET //wp2/wp-includes/wlwmanifest.xml 404 171b 0.702 ms | ref=-
[rulesandprompts] 06/19/2026, 07:29:19 MST | 168.144.110.217 | GET //site/wp-includes/wlwmanifest.xml 404 172b 0.877 ms | ref=-
Detected by an automated web-server log monitor.
show less
Web App Attack
๐ฉ๐ช
LRob
2026-06-19 05:30:10
(1 month ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ซ๐ท
ELYAZ
2026-06-19 03:09:04
(1 month ago)
(wordpress) Failed wordpress login from 168.144.110.217 (SG/Singapore/-): (CF_ENABLE)
Brute-Force
๐ซ๐ท
ELYAZ
2026-06-18 02:23:04
(1 month ago)
(wordpress) Failed wordpress login from 168.144.110.217 (SG/Singapore/-): (CF_ENABLE)
Brute-Force
๐ฉ๐ช
LRob
2026-06-17 22:45:11
(1 month ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-16 19:04:14
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 168.144.110.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.110.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 15:04:08.819577 2026] [security2:error] [pid 10764:tid 10764] [client 168.144.110.217:58894] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.sonicbureau.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.sonicbureau.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajGeKG1r7mzRvuC3qfNajQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-06-16 17:45:07
(1 month ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-15 10:08:07
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 168.144.110.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 168.144.110.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 06:08:00.207069 2026] [security2:error] [pid 2128:tid 2128] [client 168.144.110.217:53122] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.montidaunitour.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.montidaunitour.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ai_PACbO8no85z7siQurlAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-06-15 05:51:21
(1 month ago)
(wordpress) Failed wordpress login from 168.144.110.217 (SG/Singapore/-): (CF_ENABLE)
Brute-Force
๐ฉ๐ช
LRob
2026-06-14 21:45:12
(1 month ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐ฉ๐ช
byeadan
2026-06-14 09:32:02
(1 month ago)
Fail2ban permanent ban: az-scanner jail
Brute-Force
Web App Attack