๐จ๐ฆ
polycoda
2026-06-10 10:46:03
(6 days ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 200 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐ง๐ช
cmbplf
2026-06-10 09:07:48
(6 days ago)
166.620 requests in 1 hour (3mos1w5d)
Brute-Force
Bad Web Bot
๐ง๐ท
Halux
2026-06-10 09:00:00
(6 days ago)
34.178.179.100 Web Application Firewall multiple violations
Hacking
Web App Attack
๐ซ๐ท
Delta-shop
2026-06-10 08:50:52
(6 days ago)
PrestaShop Security Module: Calls WordPress paths probing known vulnerabilities
Web App Attack
๐จ๐ฆ
polycoda
2026-06-10 08:46:20
(6 days ago)
AutoBlock: ๐ WordPress Login Brute Force (20X or 30X) (Decay-Based) - โช๏ธ Excessive 30X Errors (Decay ...
show more
AutoBlock: ๐ WordPress Login Brute Force (20X or 30X) (Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
vtchost.com
2026-06-10 08:42:03
(6 days ago)
vtchost.com:443 34.178.179.100 - - [10/Jun/2026:10:42:02 +0200] "GET //wp-includes/ID3/license.txt H ...
show more
vtchost.com:443 34.178.179.100 - - [10/Jun/2026:10:42:02 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 418 2589 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
vtchost.com:443 34.178.179.100 - - [10/Jun/2026:10:42:02 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 418 2589 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
vtchost.com:443 34.178.179.100 - - [10/Jun/2026:10:42:02 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 418 2589 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Brute-Force
๐จ๐ญ
4server
2026-06-10 08:39:17
(6 days ago)
[WedJun1010:39:12.9081382026][security2:error][pid1238961:tid1239207][client34.178.179.100:0]ModSecu ...
show more
[WedJun1010:39:12.9081382026][security2:error][pid1238961:tid1239207][client34.178.179.100:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"367\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"www.benvenutialfood.ch\"][uri\"/xmlrpc.php\"][unique_id\"aikisJMPS2FKqXrlVJjCZAAAANc\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 08:33:37
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 34.178.179.100 (100.179.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 34.178.179.100 (100.179.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 04:33:33.370948 2026] [security2:error] [pid 4221:tid 4221] [client 34.178.179.100:52467] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||newhopepetgrooming.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "newhopepetgrooming.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aikhXWwiHC5II7J5Z8Xh8AAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Oakley
2026-06-10 08:22:49
(6 days ago)
(mod_security) mod_security (id:900191) triggered by 34.178.179.100 (100.179.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:900191) triggered by 34.178.179.100 (100.179.178.34.bc.googleusercontent.com): 5 in the last 900 secs
show less
Web App Attack
Hacking
๐จ๐ญ
zynex
2026-06-10 08:21:24
(6 days ago)
URL Probing: /xmlrpc.php
Web App Attack
Anonymous
2026-06-10 08:16:44
(6 days ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-10 08:15:20
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 34.178.179.100 (100.179.178.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 34.178.179.100 (100.179.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 04:15:16.161172 2026] [security2:error] [pid 12346:tid 12484] [client 34.178.179.100:59267] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||honeyled.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "honeyled.com"] [uri "/blog/wp-json/wp/v2/users/"] [unique_id "aikdFGexOSsdrUAkXoohCwAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-06-10 07:59:37
(6 days ago)
Too many 404 requests [BY]
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-06-10 07:56:51
(6 days ago)
34.178.179.100 - - [10/Jun/2026:09:56:47 +0200] "POST //xmlrpc.php HTTP/1.1" 200 4931 "-" "Mozilla/5 ...
show more
34.178.179.100 - - [10/Jun/2026:09:56:47 +0200] "POST //xmlrpc.php HTTP/1.1" 200 4931 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.178.179.100 - - [10/Jun/2026:09:56:48 +0200] "POST //xmlrpc.php HTTP/1.1" 200 4915 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.178.179.100 - - [10/Jun/2026:09:56:48 +0200] "POST //xmlrpc.php HTTP/1.1" 200 4931 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Hacking
Web App Attack
๐ช๐ธ
pipeline.es
2026-06-10 07:56:15
(6 days ago)
Web scanning / probing for vulnerable paths | URL: ///site/wp-includes/wlwmanifest.xml | Evidence: w ...
show more
Web scanning / probing for vulnerable paths | URL: ///site/wp-includes/wlwmanifest.xml | Evidence: www.intranetnautaliaviajes.es 34.178.179.100 - - [10/Jun/2026:09:55:13 +0200] \"GET ///site/wp-includes/wlwmanifest.xml HTTP/1.1\" 403 234 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36\" GEOIP_COUNTRY_CODE=NL | ASN: GOOGLE-CLOUD-PLATFORM | Country: NL
show less
Port Scan
Web App Attack