π©πͺ
ghostwarriors
2026-08-25 12:50:03
(4 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 12:45:00
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.136.139.7 (7.139.136.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.136.139.7 (7.139.136.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:44:56.181199 2026] [security2:error] [pid 22063:tid 22063] [client 34.136.139.7:61307] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lgbtqhistoryinaustin.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lgbtqhistoryinaustin.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao2OSPpUgfbmCumfL8eR_wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
yitzhaq
2026-08-25 12:21:44
(4 hours ago)
34.136.139.7 - - [25/Aug/2026:14:21:40 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
34.136.139.7 - - [25/Aug/2026:14:21:40 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.136.139.7 - - [25/Aug/2026:14:21:40 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.136.139.7 - - [25/Aug/2026:14:21:40 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.136.139.7 - - [25/Aug/2026:14:21:40 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.136.139.7 - - [25/Aug/2026:14:21:41 +0200] "GET //2020/wp-includes/wlwmanifest.xml HTTP/1.1" 40
show less
Web App Attack
Hacking
π³π±
Site.eu
2026-08-25 12:19:37
(5 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
π³π±
Savvii
2026-08-25 12:14:19
(5 hours ago)
10 attempts against mh-misc-ban on frost
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-25 12:11:37
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.136.139.7 (7.139.136.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.136.139.7 (7.139.136.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:11:31.762669 2026] [security2:error] [pid 1219374:tid 1219397] [client 34.136.139.7:56807] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||labs.cocoonprojects.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "labs.cocoonprojects.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao2Gc83YgOrWSREBjNrmTgAAAIs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-08-25 12:10:50
(5 hours ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: //xmlrpc.php | 2026-08-25 12:10 UTC
show less
Hacking
Web App Attack
π¨π
Origon
2026-08-25 12:07:04
(5 hours ago)
http-probing - IP: 34.136.139.7 - time="2026-08-25T14:07:03+02:00" level=info msg="(555f66b4f6a7455 ...
show more
http-probing - IP: 34.136.139.7 - time="2026-08-25T14:07:03+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 34.136.139.7 (US/396982) : 4h ban on Ip 34.136.139.7" module=db
show less
Web App Attack
πΊπΈ
mnsf
2026-08-25 12:05:12
(5 hours ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
π©πͺ
big-cloud.nl
2026-08-25 12:04:35
(5 hours ago)
Try to access /xmlrpc.php?rsd
Web App Attack
π©πͺ
on-com
2026-08-25 12:04:24
(5 hours ago)
URL scan
Brute-Force
Web App Attack
π©πͺ
todix
2026-08-25 11:57:41
(5 hours ago)
Web App Attack Exploid from 34.136.139.7
Web App Attack
Anonymous
2026-08-25 11:44:05
(5 hours ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1, GET //feed/ HTTP/1.1, GET //xmlr ...
show more
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1, GET //feed/ HTTP/1.1, GET //xmlrpc.php?rsd HTTP/1.1, GET //wp-includes/ID3/license.txt HTTP/1.1, GET //?author=1 HTTP/1.1, GET //wp-json/wp/v2/users/ HTTP/1.1
show less
Hacking
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-08-25 11:43:52
(5 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π©πͺ
KiekerJan
2026-08-25 11:43:52
(5 hours ago)
34.136.139.7 - - [25/Aug/2026:13:43:51 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
34.136.139.7 - - [25/Aug/2026:13:43:51 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.136.139.7 - - [25/Aug/2026:13:43:51 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack