๐บ๐ธ
lostswordfish.com
2026-06-30 07:22:05
(11 hours ago)
Wordfence waf block on madesimpleskincare
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 07:13:04
(11 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.145.135.0 (0.135.145.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.145.135.0 (0.135.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 03:12:59.210424 2026] [security2:error] [pid 20493:tid 20493] [client 34.145.135.0:53985] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mariarozella.bbproductionsonline.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mariarozella.bbproductionsonline.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "akNsewBZiZSXxnXjt8xLsQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2026-06-30 07:11:01
(11 hours ago)
17 attack(s) detected, such as these: {"event":"web_block","ip":"34.145.135.0","host":"_","request": ...
show more
17 attack(s) detected, such as these: {"event":"web_block","ip":"34.145.135.0","host":"_","request":"","user_agent":"","reason":"Status-0","timestamp":"2026-06-30T07:11:01 00:00","logentry":"_ 34.145.135.0 - - [30/Jun/2026:07:11:01 0000] \"\" 400 0 \"-\" \"-\" \"-\""} * Report Details *: https://p4u.xyz/I1V6GK1Y4JR/1* IP Details *: https://p4u.xyz/I1V6GK1Y4JR/2
show less
Web Spam
Hacking
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-06-30 06:56:09
(11 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
big-cloud.nl
2026-06-30 06:45:33
(11 hours ago)
Try to access /xmlrpc.php?rsd
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-06-30 06:41:29
(11 hours ago)
Probing websites for vulnerabilities
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-30 06:36:49
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.145.135.0 (0.135.145.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.145.135.0 (0.135.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 02:36:42.673258 2026] [security2:error] [pid 16406:tid 16406] [client 34.145.135.0:59475] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.londongroup.info|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.londongroup.info"] [uri "/wp-json/wp/v2/users/"] [unique_id "akNj-pr6MSk0j8JrJ5uGNwAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-30 06:36:29
(12 hours ago)
34.145.135.0 - - [30/Jun/2026:08:36:25 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 6851 " ...
show more
34.145.135.0 - - [30/Jun/2026:08:36:25 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 6851 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.145.135.0 - - [30/Jun/2026:08:36:26 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 6660 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.145.135.0 - - [30/Jun/2026:08:36:27 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 6851 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.145.135.0 - - [30/Jun/2026:08:36:27 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 6660 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.145.135.0 - - [30/Jun/2026:08:36:28 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 6851 "-" "Mo
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2026-06-30 06:23:11
(12 hours ago)
(mod_security) mod_security (id:210410) triggered by 34.145.135.0 (US/United States/0.135.145.34.bc. ...
show more
(mod_security) mod_security (id:210410) triggered by 34.145.135.0 (US/United States/0.135.145.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
integrantservices.com
2026-06-30 06:21:06
(12 hours ago)
(wordpress) Failed wordpress login from 34.145.135.0 (US/United States/0.135.145.34.bc.googleusercon ...
show more
(wordpress) Failed wordpress login from 34.145.135.0 (US/United States/0.135.145.34.bc.googleusercontent.com)
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-30 06:14:20
(12 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.145.135.0 (0.135.145.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.145.135.0 (0.135.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 02:14:16.453672 2026] [security2:error] [pid 19405:tid 19405] [client 34.145.135.0:61768] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lenorasflowers.lahamradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lenorasflowers.lahamradio.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "akNeuPCWJaZKobcXUQJc9QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Viveronese
2026-06-30 06:10:35
(12 hours ago)
HTTP vulnerability scanning
Web App Attack
๐ซ๐ฎ
KnightIndustries
2026-06-30 06:09:49
(12 hours ago)
2026-06-30T08:09:46.839207+02:00 milkyway wordpress(learncryptography.pw)[1521254]: XML-RPC authenti ...
show more
2026-06-30T08:09:46.839207+02:00 milkyway wordpress(learncryptography.pw)[1521254]: XML-RPC authentication failure for macminty from 34.145.135.0
2026-06-30T08:09:47.876617+02:00 milkyway wordpress(learncryptography.pw)[1514700]: XML-RPC authentication failure for macminty from 34.145.135.0
2026-06-30T08:09:49.088835+02:00 milkyway wordpress(learncryptography.pw)[1535709]: XML-RPC authentication failure for macminty from 34.145.135.0
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-30 06:05:29
(12 hours ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ซ๐ท
largo-it.net
2026-06-30 06:03:15
(12 hours ago)
Jun 30 08:03:13 vps-9f3cdc33 haproxy[1032114]: 34.145.135.0:63484 [30/Jun/2026:08:03:13.297] www_fro ...
show more
Jun 30 08:03:13 vps-9f3cdc33 haproxy[1032114]: 34.145.135.0:63484 [30/Jun/2026:08:03:13.297] www_frontend~ finance_cluster/finance1_test1_https 0/0/10/62/72 404 3252 - - ---- 54/6/0/0/0 0/0 "GET //wp-includes/ID3/license.txt HTTP/1.1"
Jun 30 08:03:13 vps-9f3cdc33 haproxy[1032114]: 34.145.135.0:63484 [30/Jun/2026:08:03:13.369] www_frontend~ finance_cluster/finance1_test1_https 154/0/11/52/217 404 3151 - - ---- 54/6/0/0/0 0/0 "GET //feed/ HTTP/1.1"
Jun 30 08:03:13 vps-9f3cdc33 haproxy[1032114]: 34.145.135.0:63484 [30/Jun/2026:08:03:13.587] www_frontend~ finance_cluster/finance1_test1_https 344/0/11/50/405 404 3151 - - ---- 54/6/0/0/0 0/0 "GET //xmlrpc.php?rsd HTTP/1.1"
Jun 30 08:03:14 vps-9f3cdc33 haproxy[1032114]: 34.145.135.0:63484 [30/Jun/2026:08:03:13.992] www_frontend~ finance_cluster/finance1_test1_https 88/0/11/49/148 404 3151 - - ---- 54/6/0/0/0 0/0 "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1"
Jun 30 08:03:14 vps-9f3cdc33 haproxy[1032114]: 34.145.135.0:63484 [30/Jun/2026:08:
...
show less
Hacking
Bad Web Bot
Web App Attack