๐จ๐ญ
YF
2026-10-09 11:37:22
(23 hours ago)
WordPress author enumeration
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 11:21:36
(23 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.141.242.5 (5.242.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.141.242.5 (5.242.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 07:21:32.818452 2026] [security2:error] [pid 25130:tid 25130] [client 34.141.242.5:59899] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||earthwormensemble.doublenaughtspycar.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "earthwormensemble.doublenaughtspycar.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "asjOPFTudjjpXCXAy37KqQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 11:13:04
(1 day ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ฉ๐ช
rh24
2026-10-09 11:08:05
(1 day ago)
(wlwmanifest) wlwmanifest.xml scanner (WordPress probe) from 34.141.242.5 (5.242.141.34.bc.googleuse ...
show more
(wlwmanifest) wlwmanifest.xml scanner (WordPress probe) from 34.141.242.5 (5.242.141.34.bc.googleusercontent.com)
show less
Hacking
Anonymous
2026-10-09 11:06:04
(1 day ago)
Trying to access config files
Web App Attack
๐ง๐พ
lns.bz
2026-10-09 11:03:19
(1 day ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 10:54:56
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 34.141.242.5 (5.242.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.141.242.5 (5.242.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 06:54:51.509736 2026] [security2:error] [pid 26157:tid 26157] [client 34.141.242.5:52230] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dpginc1.iyp-home.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dpginc1.iyp-home.com"] [uri "/blog/wp-json/wp/v2/users/"] [unique_id "asjH--h5RHZviHGm3SosJgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
security.rdmc.fr
2026-10-09 10:54:01
(1 day ago)
Web scan: multiple 4xx responses
Web App Attack
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-10-09 10:50:29
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
ghostwarriors
2026-10-09 10:50:06
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-09 10:45:16
(1 day ago)
34.141.242.5 - - [09/Oct/2026:12:45:11 +0200] "GET /wp-includes/id3/license.txt/blog/wp-includes/wlw ...
show more
34.141.242.5 - - [09/Oct/2026:12:45:11 +0200] "GET /wp-includes/id3/license.txt/blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 25170 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.141.242.5 - - [09/Oct/2026:12:45:11 +0200] "GET /wp-includes/id3/license.txt/web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 25164 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.141.242.5 - - [09/Oct/2026:12:45:11 +0200] "GET /wp-includes/id3/license.txt/wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 25200 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.141.242.5 - - [09/Oct/2026:12:45:11 +0200] "GET /wp-includes/id3/license.txt/wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 25158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.
show less
Web App Attack
Hacking
๐ณ๐ฟ
Tripwire
2026-10-09 10:44:24
(1 day ago)
Scanning for exploits - /process-serving//wp-includes/ID3/license.txt
Web App Attack
๐จ๐ญ
Origon
2026-10-09 10:42:59
(1 day ago)
http-probing - IP: 34.141.242.5 - time="2026-10-09T12:42:58+02:00" level=info msg="(555f66b4f6a7455 ...
show more
http-probing - IP: 34.141.242.5 - time="2026-10-09T12:42:58+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 34.141.242.5 (NL/396982) : 4h ban on Ip 34.141.242.5" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 10:37:49
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 34.141.242.5 (5.242.141.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.141.242.5 (5.242.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 06:37:45.425595 2026] [security2:error] [pid 10001:tid 10001] [client 34.141.242.5:60849] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dixiegeek.cosentient.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dixiegeek.cosentient.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "asjD-dwVlNrkWb3AGFgvRQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
HamSammich
2026-10-09 10:35:00
(1 day ago)
Automated sensor: 2 HTTP connection/probe attempts over the last 24h (latest 2026-10-09T10:35Z).
Brute-Force
Web App Attack