🇲🇽
octageeks.com
2026-08-27 04:16:27
(2 days ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 12:10:07
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 34.139.58.159 (159.58.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.139.58.159 (159.58.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 08:10:01.683125 2026] [security2:error] [pid 17066:tid 17066] [client 34.139.58.159:57444] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.americanacademyofteachersofsinging.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.americanacademyofteachersofsinging.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao7Xma4ixTDumGEgW4aMHAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 12:03:08
(3 days ago)
wp admin page access attempt
...
Hacking
Web App Attack
🇧🇷
dominioz
2026-08-26 12:02:51
(3 days ago)
2026-08-26 12:01:49 GET /wp-includes/wlwmanifest.xml - - 34.139.58.159 HTTP/1.1 Mozilla/5.0+(Windows ...
show more
2026-08-26 12:01:49 GET /wp-includes/wlwmanifest.xml - - 34.139.58.159 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/78.0.3904.108+Safari/537.36 - 404 1987
2026-08-26 12:01:49 GET /xmlrpc.php rsd - 34.139.58.159 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/78.0.3904.108+Safari/537.36 - 404 5137
2026-08-26 12:01:49 GET /blog/wp-includes/wlwmanifest.xml - - 34.139.58.159 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/78.0.3904.108+Safari/537.36 - 404 1987
2026-08-26 12:01:50 GET /web/wp-includes/wlwmanifest.xml - - 34.139.58.159 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/78.0.3904.108+Safari/537.36 - 404 1987
...
show less
Web App Attack
🇩🇪
patrisei
2026-08-26 11:53:24
(3 days ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-probing
Port Scan
Web App Attack
🇩🇪
FeG Deutschland
2026-08-26 11:52:18
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 247
Exploited Host
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-08-26 11:49:42
(3 days ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-08-26 11:44:32
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 34.139.58.159 (159.58.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.139.58.159 (159.58.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 07:44:25.377188 2026] [security2:error] [pid 29274:tid 29274] [client 34.139.58.159:50997] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||allttilleigu.is|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "allttilleigu.is"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao7RmYakA2dmbRIIrQUDxAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-08-26 11:44:29
(3 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: //xmlrpc.php | 2026-08-26 11:44 UTC
show less
Hacking
Web App Attack
🇦🇺
screwlooseit.com.au
2026-08-26 11:42:54
(3 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/159.58.139.34.bc.googleusercontent.com
Web App Attack
🇮🇹
ciccio diddo
2026-08-26 11:31:23
(3 days ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
🇩🇪
SCHAPPY
2026-08-26 11:22:52
(3 days ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
🇨🇭
zynex
2026-08-26 11:20:12
(3 days ago)
URL Probing: /2018/wp-includes/wlwmanifest.xml
Web App Attack
🇫🇷
Zundapper
2026-08-26 11:16:29
(3 days ago)
34.139.58.159 - - [26/Aug/2026:13:16:28 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 ...
show more
34.139.58.159 - - [26/Aug/2026:13:16:28 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.139.58.159 - - [26/Aug/2026:13:16:28 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.139.58.159 - - [26/Aug/2026:13:16:29 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.139.58.159 - - [26/Aug/2026:13:16:29 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.139.58.159 - - [26/Aug/2026:13:16:29 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 54
...
show less
Web App Attack
Port Scan
🇮🇹
VHosting
2026-08-26 11:15:05
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack