๐ง๐ช
cmbplf
2026-09-28 13:02:10
(1 hour ago)
12.578 requests in 1 hour (3mos1w5d)
Brute-Force
Bad Web Bot
๐ฉ๐ช
ghostwarriors
2026-09-28 12:50:30
(1 hour ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-28 12:45:45
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: //2019/wp-includes/wlwmanifest.xml
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-28 12:45:22
(1 hour ago)
34.121.28.111 - - [28/Sep/2026:14:45:16 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 403 ...
show more
34.121.28.111 - - [28/Sep/2026:14:45:16 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
aks4226
2026-09-28 12:45:02
(1 hour ago)
Bot search, attacking common web applications.
Web App Attack
Anonymous
2026-09-28 12:40:05
(2 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ณ๐ด
jad-abuse
2026-09-28 12:37:24
(2 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 16 hits.
show less
Brute-Force
Web App Attack
๐ต๐ฑ
Budyn
2026-09-28 12:37:04
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dock.budyn.wtf | URI: //xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
๐จ๐ฑ
ifiguero
2026-09-28 12:36:37
(2 hours ago)
Web Attack (\x00\x00\x00\x00\x00). 7d ban
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-28 12:35:53
(2 hours ago)
34.121.28.111 - - [28/Sep/2026:14:35:50 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
34.121.28.111 - - [28/Sep/2026:14:35:50 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.121.28.111 - - [28/Sep/2026:14:35:50 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.121.28.111 - - [28/Sep/2026:14:35:50 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.121.28.111 - - [28/Sep/2026:14:35:49 +0200] "GET / HTTP/1.1" 301 566 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.121.28.111 - - [28/Sep/2026:14:35:49 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 4281 "-" "Mozilla/5.0 (Window
show less
Web App Attack
Hacking
๐ณ๐ฑ
thedreamer.nl
2026-09-28 12:34:52
(2 hours ago)
34.121.28.111 - - [28/Sep/2026:14:32:43 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 401 0 "- ...
show more
34.121.28.111 - - [28/Sep/2026:14:32:43 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 401 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "Council Bluffs" "41.25910" "-95.85170"
34.121.28.111 - - [28/Sep/2026:14:32:43 +0200] "GET //feed/ HTTP/1.1" 401 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "Council Bluffs" "41.25910" "-95.85170"
34.121.28.111 - - [28/Sep/2026:14:32:43 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 401 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "Council Bluffs" "41.25910" "-95.85170"
34.121.28.111 - - [28/Sep/2026:14:32:43 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 401 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "Council Bluff
...
show less
Hacking
Brute-Force
๐ต๐ฑ
sefinek.net
2026-09-28 12:34:50
(2 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: //shop/wp-includes/wlwmanifest.xml | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
factor1
2026-09-28 12:33:32
(2 hours ago)
CrowdSec at athena Reports Abuse
Web App Attack
๐ฉ๐ช
tsZero
2026-09-28 12:31:18
(2 hours ago)
Scan example: path=/xmlrpc.php?rsd status=403
Hacking
๐ฉ๐ช
rh24
2026-09-28 12:19:54
(2 hours ago)
(wlwmanifest) wlwmanifest.xml scanner (WordPress probe) from 34.121.28.111 (US/United States/111.28. ...
show more
(wlwmanifest) wlwmanifest.xml scanner (WordPress probe) from 34.121.28.111 (US/United States/111.28.121.34.bc.googleusercontent.com)
show less
Hacking