๐จ๐ญ
YF
2025-07-23 13:05:02
(1 year ago)
Unauthorized WordPress access attempt
Brute-Force
Web App Attack
๐ฉ๐ช
bescared
2025-07-23 12:47:26
(1 year ago)
F2B - Malicious activity detected. URL Probing.
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2025-07-23 12:38:04
(1 year ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: //shop/wp-includes/wlwmanifest.xml
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ฟ
ddw
2025-07-23 12:18:15
(1 year ago)
Access Violation Attempts - Multiple 403 Forbidden responses.
Hacking
Bad Web Bot
Web App Attack
๐ฌ๐ง
www.elivecd.org
2025-07-23 10:14:24
(1 year ago)
18.234.79.254 - - [23/Jul/2025:11:14:24 +0100] "GET /download//wp-includes/wlwmanifest.xml HTTP/1.1" ...
show more
18.234.79.254 - - [23/Jul/2025:11:14:24 +0100] "GET /download//wp-includes/wlwmanifest.xml HTTP/1.1" 301 5 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
DDoS Attack
๐ฉ๐ช
ManagedStack
2025-07-23 09:40:46
(1 year ago)
Wordpress Attack
Web App Attack
๐จ๐ฆ
polycoda
2025-07-23 07:45:47
(1 year ago)
๐ Wordpress login brute force attempt
Hacking
Web App Attack
๐ง๐ช
delabiemedia.be
2025-07-23 06:57:19
(1 year ago)
18.234.79.254 - - [23/Jul/2025:08:57:19 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 564 " ...
show more
18.234.79.254 - - [23/Jul/2025:08:57:19 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
18.234.79.254 - - [23/Jul/2025:08:57:19 +0200] "GET /xmlrpc.php?rsd HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Web App Attack
๐ณ๐ฑ
artificialred.nl
2025-07-23 06:49:02
(1 year ago)
[Server probing] access_ssl_log:18.234.79.254 - - [23/Jul/2025:08:48:43 +0200] GET //news/wp-include ...
show more
[Server probing] access_ssl_log:18.234.79.254 - - [23/Jul/2025:08:48:43 +0200] GET //news/wp-includes/wlwmanifest.xml HTTP/1.0" 404 1859 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-23 06:31:59
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 18.234.79.254 (ec2-18-234-79-254.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 18.234.79.254 (ec2-18-234-79-254.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 23 02:31:53.807006 2025] [security2:error] [pid 8168:tid 8168] [client 18.234.79.254:56948] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.consolidatedoperationsgroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.consolidatedoperationsgroup.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aICB2S2hEK0gA2iVKIzSSAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-23 05:33:24
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 18.234.79.254 (ec2-18-234-79-254.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 18.234.79.254 (ec2-18-234-79-254.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 23 01:33:20.117653 2025] [security2:error] [pid 26873:tid 26873] [client 18.234.79.254:64943] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.digi-estudio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.digi-estudio.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aIB0IOTDGdkPVD6TaNhVygAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-23 05:07:00
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 18.234.79.254 (ec2-18-234-79-254.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 18.234.79.254 (ec2-18-234-79-254.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 23 01:06:54.554384 2025] [security2:error] [pid 10984:tid 10984] [client 18.234.79.254:59866] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.clipper1970.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.clipper1970.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aIBt7nS-rLqBaWc0NhpsKwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2025-07-23 05:05:05
(1 year ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ง๐ช
taivas.nl
2025-07-23 05:02:11
(1 year ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-23 04:50:45
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 18.234.79.254 (ec2-18-234-79-254.compute-1.amaz ...
show more
(mod_security) mod_security (id:225170) triggered by 18.234.79.254 (ec2-18-234-79-254.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 23 00:50:38.256438 2025] [security2:error] [pid 27291:tid 27291] [client 18.234.79.254:62528] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.hydrusdetergents.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.hydrusdetergents.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aIBqHtrfuAwDYIuHnrPrhgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack