๐ซ๐ท
Catalin Negru
2026-08-31 19:06:42
(19 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
Anonymous
2026-08-26 10:11:06
(6 days ago)
Web app attack and vulnerability scan detected from IIS logs
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-08-26 09:20:23
(6 days ago)
CMS/framework probe: 34.168.77.225 - - [26/Aug/2026:11:20:22 +0200] "GET //wp-includes/ID3/license.t ...
show more
CMS/framework probe: 34.168.77.225 - - [26/Aug/2026:11:20:22 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" asn=396982 org="Google LLC" country=US
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 09:18:42
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 34.168.77.225 (225.77.168.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.168.77.225 (225.77.168.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:18:35.406119 2026] [security2:error] [pid 32753:tid 32753] [client 34.168.77.225:65386] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pardescommunications.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pardescommunications.com"] [uri "/blog/wp-json/wp/v2/users/"] [unique_id "ao6va0uu-bDDXsU4rhobHwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
mondor.ro
2026-08-26 09:18:34
(6 days ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.168.77.225, Reason: ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 34.168.77.225, Reason:[(manifest) WordPress wlwmanifest.xml Attack 34.168.77.225 (US/United States/225.77.168.34.bc.googleusercontent.com): 10 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐ท๐ด
clauss
2026-08-26 09:17:27
(6 days ago)
34.168.77.225 - - [26/Aug/2026:12:17:24 +0300] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
34.168.77.225 - - [26/Aug/2026:12:17:24 +0300] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 277 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.168.77.225 - - [26/Aug/2026:12:17:24 +0300] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 277 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.168.77.225 - - [26/Aug/2026:12:17:24 +0300] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 277 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.168.77.225 - - [26/Aug/2026:12:17:24 +0300] "GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 277 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.168.77.225 - - [26/Aug/2026:12:17:25 +0300] "GET /2020/wp-includes/wlwmanifest.xml HTTP/1.1" 40
...
show less
Web App Attack
Anonymous
2026-08-26 09:05:28
(6 days ago)
apache vulnerability scan
Web App Attack
๐ซ๐ท
Catalin Negru
2026-08-26 09:05:21
(6 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐บ๐ธ
mnsf
2026-08-26 09:05:07
(6 days ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-08-26 09:03:32
(6 days ago)
-:443 34.168.77.225 - - [26/Aug/2026:11:03:30 +0200] - "GET //xmlrpc.php?rsd HTTP/1.1" 403 1964 "-" ...
show more
-:443 34.168.77.225 - - [26/Aug/2026:11:03:30 +0200] - "GET //xmlrpc.php?rsd HTTP/1.1" 403 1964 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Bad Web Bot
๐บ๐ธ
aks4226
2026-08-26 09:00:15
(6 days ago)
Bot search, attacking common web applications.
Web App Attack
๐จ๐ญ
backslash
2026-08-26 08:57:01
(6 days ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฉ๐ช
et-a_network
2026-08-26 08:56:45
(6 days ago)
34.168.77.225 - - [26/Aug/2026:08:56:44 +0000] "GET //wp-includes/ID3/license.txt HTTP/2.0" 444 0 "- ...
show more
34.168.77.225 - - [26/Aug/2026:08:56:44 +0000] "GET //wp-includes/ID3/license.txt HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" host=overleaf.et-a.eu via=172.68.159.126 rt=0.000
34.168.77.225 - - [26/Aug/2026:08:56:44 +0000] "GET //xmlrpc.php?rsd HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" host=overleaf.et-a.eu via=172.64.198.210 rt=0.000
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Rip
2026-08-26 08:56:02
(6 days ago)
WordPress fingerprinting and attack surface probing
Port Scan
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-26 08:55:17
(6 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 31 hits.
show less
Brute-Force
Web App Attack