🇫🇷
masterguru
2026-09-15 09:41:13
(1 hour ago)
(PERMBLOCK) 201.79.56.161 (US/United States/-) has had more than 4 temp blocks in the last 86400 sec ...
show more
(PERMBLOCK) 201.79.56.161 (US/United States/-) has had more than 4 temp blocks in the last 86400 secs (0-193)
show less
Hacking
🇫🇷
masterguru
2026-09-15 09:22:19
(2 hours ago)
(PERMBLOCK) 201.79.56.161 (US/United States/-) has had more than 4 temp blocks in the last 86400 sec ...
show more
(PERMBLOCK) 201.79.56.161 (US/United States/-) has had more than 4 temp blocks in the last 86400 secs (0-196)
show less
Hacking
🇫🇷
masterguru
2026-09-15 08:40:53
(2 hours ago)
(wordpress) Apache: Failed WordPress login from 201.79.56.161 (US/United States/-): 10 in the last 3 ...
show more
(wordpress) Apache: Failed WordPress login from 201.79.56.161 (US/United States/-): 10 in the last 3600 secs (0-193)
show less
Hacking
🇩🇪
XICTRON
2026-09-15 08:30:07
(3 hours ago)
WordPress attack attempt detected by Fail2Ban
Web App Attack
🇩🇪
ghostwarriors
2026-09-15 05:50:06
(5 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-15 05:23:31
(6 hours ago)
201.79.56.161 - - [15/Sep/2026:07:23:27 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 518 ...
show more
201.79.56.161 - - [15/Sep/2026:07:23:27 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 518 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [15/Sep/2026:07:23:27 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 518 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [15/Sep/2026:07:23:27 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 518 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [15/Sep/2026:07:23:28 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 518 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [15/Sep/2026:07:23:28 +0200] "GET //website/wp-includes/wlwmanifest.xml HTT
show less
Web App Attack
Hacking
🇬🇧
openstrike.co.uk
2026-09-15 05:13:42
(6 hours ago)
18 attacks on Wordpress URLs, PHP URLs:
GET //sito/wp-includes/wlwmanifest.xml HTTP/1.1
GET //xmlrpc ...
show more
18 attacks on Wordpress URLs, PHP URLs:
GET //sito/wp-includes/wlwmanifest.xml HTTP/1.1
GET //xmlrpc.php?rsd HTTP/1.1
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 02:19:10
(9 hours ago)
(mod_security) mod_security (id:225170) triggered by 201.79.56.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 201.79.56.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 22:19:06.908422 2026] [security2:error] [pid 26391:tid 26391] [client 201.79.56.161:49205] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||rustyog.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "rustyog.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqirGpUUwx2jrgY02aCDbAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-15 01:32:33
(9 hours ago)
201.79.56.161 - - [14/Sep/2026:21:22:25 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cyp ...
show more
201.79.56.161 - - [14/Sep/2026:21:22:25 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [14/Sep/2026:21:22:25 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [14/Sep/2026:21:22:25 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [14/Sep/2026:21:32:33 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.5
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 01:31:16
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 201.79.56.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 201.79.56.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 21:31:10.661894 2026] [security2:error] [pid 25168:tid 25191] [client 201.79.56.161:55290] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.killasgarage.bike|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.killasgarage.bike"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqif3hht0-hj9dSw_14WiQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-15 01:12:17
(10 hours ago)
201.79.56.161 - - [14/Sep/2026:21:12:16 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cyp ...
show more
201.79.56.161 - - [14/Sep/2026:21:12:16 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [14/Sep/2026:21:12:16 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [14/Sep/2026:21:12:16 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [14/Sep/2026:21:12:17 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.5
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 00:59:25
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 201.79.56.161 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 201.79.56.161 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 20:59:20.919266 2026] [security2:error] [pid 31048:tid 31048] [client 201.79.56.161:61768] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tracytappan.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tracytappan.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqiYaPRSslT2KTWO0f9O_QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 00:55:36
(10 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
LRob
2026-09-15 00:53:46
(10 hours ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-15 00:53 UTC
show less
Bad Web Bot
🇺🇸
IndigoRidge
2026-09-15 00:51:57
(10 hours ago)
201.79.56.161 - - [14/Sep/2026:20:51:56 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cyp ...
show more
201.79.56.161 - - [14/Sep/2026:20:51:56 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [14/Sep/2026:20:51:56 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [14/Sep/2026:20:51:56 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.56.161 - - [14/Sep/2026:20:51:56 -0400] "POST //wp-login.php HTTP/1.1" 200 13016 "https://cypresscenter.net//wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
201.79.5
...
show less
Web App Attack