๐ง๐ช
cmbplf
2026-09-13 13:53:27
(3 days ago)
2.975 requests with url.path */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
๐ฌ๐ง
Apache
2026-09-13 13:47:16
(3 days ago)
(mod_security) mod_security (id:210410) triggered by 34.145.187.242 (US/United States/242.187.145.34 ...
show more
(mod_security) mod_security (id:210410) triggered by 34.145.187.242 (US/United States/242.187.145.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฉ๐ฐ
toolbit.online
2026-09-13 13:46:34
(3 days ago)
Behavior strongly consistent with automated vulnerability scanning, per CrowdSec - 11 probing events ...
show more
Behavior strongly consistent with automated vulnerability scanning, per CrowdSec - 11 probing events. Classified as automated probing for exposed files / admin panels (scenario "http-probing", in our own server logs). Behavioural detection, auto-banned at the firewall.
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-13 13:43:36
(3 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ฉ๐ช
LRob
2026-09-13 13:38:24
(3 days ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: // | query: author=1 (+1 more) | 2026-09-13 13:38 UTC
show less
Hacking
Web App Attack
๐ง๐ช
taivas.nl
2026-09-13 13:32:12
(3 days ago)
Bad_requests
Bad Web Bot
๐ต๐ฑ
Budyn
2026-09-13 13:20:53
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: sql.teddypot.website | URI: //xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36 | BODY: <?xml version="1.0"?><methodCall><methodName>system.multicall</methodName><params><param><value><array><data> <value><struct><member><name>methodName</name><value><string>wp.getUsersBlogs</string></value></member><member><name>params</name><value><array><data><value><array><data><value><string>admin</string></value><valu
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-13 13:20:08
(3 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-13 13:17:22
(3 days ago)
34.145.187.242 - - [13/Sep/2026:15:17:18 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 518 ...
show more
34.145.187.242 - - [13/Sep/2026:15:17:18 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 518 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.145.187.242 - - [13/Sep/2026:15:17:19 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 518 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.145.187.242 - - [13/Sep/2026:15:17:19 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 518 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.145.187.242 - - [13/Sep/2026:15:17:19 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 518 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.145.187.242 - - [13/Sep/2026:15:17:18 +0200] "GET / HTTP/1.1" 301 563 "-" "Mozilla/5.0
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-13 13:17:08
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 34.145.187.242 (242.187.145.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 34.145.187.242 (242.187.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:17:01.470920 2026] [security2:error] [pid 16040:tid 16040] [client 34.145.187.242:55426] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.splashstation.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.splashstation.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqaiTX2Ota2lE_u20bofcgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-13 13:05:57
(3 days ago)
34.145.187.242 - - [13/Sep/2026:15:05:52 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 548 ...
show more
34.145.187.242 - - [13/Sep/2026:15:05:52 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ฎ
kumiko
2026-09-13 13:05:50
(3 days ago)
[2026-09-13 16:05:49] Probing for WordPress exploits [2 requests]
"GET /en/xmlrpc.php?rsd HTTP/1.1 ...
show more
[2026-09-13 16:05:49] Probing for WordPress exploits [2 requests]
"GET /en/xmlrpc.php?rsd HTTP/1.1" 403
"GET /en/wp-includes/wlwmanifest.xml HTTP/1.1" 403
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-09-13 13:05:03
(3 days ago)
Scanning for exploits - //wp-includes/wlwmanifest.xml
Web App Attack
๐บ๐ธ
lavnet.net
2026-09-13 13:04:37
(3 days ago)
34.145.187.242 - - [13/Sep/2026:13:04:36 +0000] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 2083 ...
show more
34.145.187.242 - - [13/Sep/2026:13:04:36 +0000] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.145.187.242 - - [13/Sep/2026:13:04:36 +0000] "GET /xmlrpc.php?rsd HTTP/1.1" 403 2086 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.145.187.242 - - [13/Sep/2026:13:04:36 +0000] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.145.187.242 - - [13/Sep/2026:13:04:37 +0000] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 2083 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.145.187.242 - - [13/Sep/2026:13:04:37 +0000] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 2083 "
...
show less
Brute-Force
๐ฎ๐น
VHosting
2026-09-13 13:00:05
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack