๐ต๐ฑ
Budyn
2026-08-28 19:44:19
(6 minutes ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: registry.teddypot.cloud | URI: //xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 | BODY: <?xml version="1.0"?><methodCall><methodName>system.multicall</methodName><params><param><value><array><data> <value><struct><member><name>methodName</name><value><string>wp.getUsersBlogs</string></value></member><member><name>params</name><value><array><data><value><array><data><value><string>admin</string></value><v
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-08-28 18:01:38
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from RO.
Action taken: BLOCK
ASN: 210558 (1337 Services Gm ...
show more
Triggered Cloudflare WAF (firewallCustom) from RO.
Action taken: BLOCK
ASN: 210558 (1337 Services GmbH)
Protocol: HTTP/1.1 (GET method)
Endpoint: /2019/wp-includes/wlwmanifest.xml
Timestamp: 2026-08-28T17:12:15Z
Ray ID: a324f0963f75e445
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36
show less
Bad Web Bot
๐ซ๐ท
[email protected]
2026-08-28 15:49:42
(4 hours ago)
PrestaShop Security Module: Calls WordPress paths probing known vulnerabilities
Web App Attack
๐ซ๐ท
Zundapper
2026-08-28 14:35:48
(5 hours ago)
185.19.40.40 - - [28/Aug/2026:16:35:47 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 " ...
show more
185.19.40.40 - - [28/Aug/2026:16:35:47 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
185.19.40.40 - - [28/Aug/2026:16:35:47 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
185.19.40.40 - - [28/Aug/2026:16:35:47 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Web App Attack
Port Scan
๐ฉ๐ช
LRob
2026-08-28 14:32:28
(5 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: //wp-json/wp/v2/users/ | 2026-08-28 14:32 UTC
show less
Hacking
Web App Attack
๐ฎ๐ช
Coolnagour
2026-08-28 11:37:11
(8 hours ago)
funnypot web honeypot, port 80: GET http://funnypot.org/xmlrpc.php
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-28 10:57:51
(8 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 185.19.40.40 (-): 1 in the last 360 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 185.19.40.40 (-): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-08-28 10:45:08
(9 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-28 10:08:55
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 185.19.40.40 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 185.19.40.40 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:08:39.624996 2026] [security2:error] [pid 4978:tid 4978] [client 185.19.40.40:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hvacs-aircon.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hvacs-aircon.com"] [uri "/ar/wp-json/wp/v2/users/"] [unique_id "apFeJ_ZafbhNGZpdSjGQzwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
integrantservices.com
2026-08-28 10:02:38
(9 hours ago)
(PERMBLOCK) 185.19.40.40 (-) has had more than 4 temp blocks
Hacking
๐บ๐ธ
integrantservices.com
2026-08-28 08:59:48
(10 hours ago)
(wordpress) Failed wordpress login from 185.19.40.40 (-)
Brute-Force
๐ฉ๐ช
rollenspiel.network
2026-08-28 08:09:58
(11 hours ago)
CrowdSec detection: crowdsecurity/http-probing
Web App Attack
๐จ๐ฆ
polycoda
2026-08-28 07:11:27
(12 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐ญ๐บ
miszterx.hu
2026-08-28 06:56:35
(12 hours ago)
XORP (haproxy): 27x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 27x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ฌ๐ง
BRHosting
2026-08-28 06:19:02
(13 hours ago)
Wordpress brute force attack for login credentials (eg xmlrc.php or wp-login.php)
Brute-Force
Web App Attack