Anonymous
2026-06-26 05:12:49
(1 day ago)
<jail> banned by fail2ban
Brute-Force
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-06-26 04:10:45
(1 day ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
๐บ๐ธ
mnsf
2026-06-25 21:30:50
(1 day ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ซ๐ฎ
YF
2026-06-25 12:01:13
(2 days ago)
WordPress directory enumeration
Web App Attack
๐จ๐ฆ
polycoda
2026-06-25 11:29:13
(2 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ Directory Listings (Decay-Based) - โ Excess ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ Directory Listings (Decay-Based) - โ Excessive 40X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-06-25 11:10:16
(2 days ago)
Scanning for exploits - //wp-includes/ID3/license.txt
Web App Attack
๐จ๐ญ
zynex
2026-06-25 11:08:42
(2 days ago)
URL Probing: /fr/home/wordpress/wp-includes/wlwmanifest.xml
Web App Attack
๐บ๐ธ
TAY
2026-06-25 11:08:27
(2 days ago)
34.140.195.240 - - [25/Jun/2026:19:08:25 +0800] "POST //xmlrpc.php HTTP/1.1" 200 623 "-" "Mozilla/5. ...
show more
34.140.195.240 - - [25/Jun/2026:19:08:25 +0800] "POST //xmlrpc.php HTTP/1.1" 200 623 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.140.195.240 - - [25/Jun/2026:19:08:26 +0800] "POST //xmlrpc.php HTTP/1.1" 200 5951 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.140.195.240 - - [25/Jun/2026:19:08:26 +0800] "POST //xmlrpc.php HTTP/1.1" 200 5951 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Brute-Force
๐ท๐บ
DZBOT
2026-06-25 11:05:54
(2 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 11:05:54
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 34.140.195.240 (240.195.140.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 34.140.195.240 (240.195.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 07:05:50.663679 2026] [security2:error] [pid 27850:tid 27850] [client 34.140.195.240:50045] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abilityimprinting.abilityengraving.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abilityimprinting.abilityengraving.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aj0LjghPw_-o9jmYL-Q-jQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
McClay
2026-06-25 11:04:25
(2 days ago)
HTTP-404 spam:34.140.195.240 - - [25/Jun/2026:13:04:25 +0200] "GET //wp-includes/ID3/license.txt HTT ...
show more
HTTP-404 spam:34.140.195.240 - - [25/Jun/2026:13:04:25 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 4845 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.140.195.240 - - [25/Jun/2026:13:04:25 +0200] "GET //feed/ HTTP/1.1" 404 1079 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.140.195.240 - - [25/Jun/2026:13:04:25 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 274 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.140.195.240 - - [25/Jun/2026:13:04:25 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 1079 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.140.195.240 - - [25/Jun/2026:13:04:25 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 1079 "-" "Mozilla/5.0 (Windows NT 10.0
...
show less
Web App Attack
๐ช๐ธ
pipeline.es
2026-06-25 11:00:44
(2 days ago)
Web scanning / probing for vulnerable paths | URL: //2019/wp-includes/wlwmanifest.xml | Evidence: mi ...
show more
Web scanning / probing for vulnerable paths | URL: //2019/wp-includes/wlwmanifest.xml | Evidence: microsites.grupoeuropa.com 34.140.195.240 - - [25/Jun/2026:12:58:18 +0200] \"GET //2019/wp-includes/wlwmanifest.xml HTTP/1.1\" 404 16197 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36\" GEOIP_COUNTRY_CODE=BE | ASN: GOOGLE-CLOUD-PLATFORM | Country: BE
show less
Port Scan
Web App Attack
๐ซ๐ท
masterguru
2026-06-25 10:52:32
(2 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 34.140.195.240 (BE/Belgium/240.195.140.34.bc.googleuserco ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 34.140.195.240 (BE/Belgium/240.195.140.34.bc.googleusercontent.com): 10 in the last 3600 secs (0-201)
show less
Hacking
Anonymous
2026-06-25 10:47:22
(2 days ago)
34.140.195.240 - - [25/Jun/2026:12:47:19 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 ...
show more
34.140.195.240 - - [25/Jun/2026:12:47:19 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.140.195.240 - - [25/Jun/2026:12:47:20 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.140.195.240 - - [25/Jun/2026:12:47:21 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.140.195.240 - - [25/Jun/2026:12:47:21 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.140.195.240 - - [25/Jun/2026:12:47:22 +0200] "GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 40
...
show less
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-06-25 10:39:25
(2 days ago)
729 requests with url.path */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot