๐บ๐ธ
xxkodedxx
2026-09-28 10:01:29
(3 days ago)
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get, 3ร edge-block ...
show more
[Zorvexus edge-defense] GET .env / WordPress honeypot probe
Trigger: 1ร honeypot-get, 3ร edge-block in 10m window.
Origin: NL / AS396982 Google LLC
Active: 10:00:42โ10:00:47 UTC
Volume: 4 HTTP req, 5 honeypot probe(s)
Bait taken: /xmlrpc.php, /wp-json/oembed/1.0/embed?url=https://ai.zvxlabs.com, /wp-json/wp/v2/users/, /xmlrpc.php?rsd, /wp-includes/ID3/license.txt
Status mix: 444ร3 200ร1
UA: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-28 10:01:03
(3 days ago)
Bot / scanning and/or hacking attempts: POST /xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐ง๐พ
lns.bz
2026-09-28 10:00:40
(3 days ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
OceanTreasure
2026-09-28 09:52:37
(3 days ago)
tcp/443; WordPress XML-RPC brute force attempt: "GET //xmlrpc.php?rsd" @ 2026-09-28T09:52:37Z [proxy ...
show more
tcp/443; WordPress XML-RPC brute force attempt: "GET //xmlrpc.php?rsd" @ 2026-09-28T09:52:37Z [proxy]
show less
Web App Attack
Brute-Force
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-28 09:43:28
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฎ๐ฑ
Dolphi
2026-09-28 09:40:03
(3 days ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
Anonymous
2026-09-28 09:35:52
(3 days ago)
34.178.94.71 - - [28/Sep/2026:17:35:41 +0800] "GET //feed/ HTTP/1.1" 404 26371 "-" "Mozilla/5.0 (Win ...
show more
34.178.94.71 - - [28/Sep/2026:17:35:41 +0800] "GET //feed/ HTTP/1.1" 404 26371 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.178.94.71 - - [28/Sep/2026:17:35:42 +0800] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 26371 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.178.94.71 - - [28/Sep/2026:17:35:43 +0800] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 26371 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.178.94.71 - - [28/Sep/2026:17:35:44 +0800] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 26371 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.178.94.71 - - [28/Sep/2026:17:35:45 +0800] "GET //2020/wp-includes/wlwmanifest.xml HTTP/1.1" 404 26371 "-" "Mozi
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-28 09:31:02
(3 days ago)
14.391 requests with url.path //xmlrpc.php
12.671 requests with url.path */xmlrpc.php
1.575 reque ...
show more
14.391 requests with url.path //xmlrpc.php
12.671 requests with url.path */xmlrpc.php
1.575 requests with url.path */wp-includes/wlwmanifest.xml
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
RamSet
2026-09-28 09:24:09
(3 days ago)
[ycr] HTTP-Probe on port 443 (via domain). 16 distinct paths probed in 3s. Sustained 16 req/min, 16 ...
show more
[ycr] HTTP-Probe on port 443 (via domain). 16 distinct paths probed in 3s. Sustained 16 req/min, 16 nonexistent paths (404). Paths: /, //2019/wp-includes/wlwmanifest.xml, //2020/wp-includes/wlwmanifest.xml, //2021/wp-includes/wlwmanifest.xml, //blog/wp-includes/wlwmanifest.xml, //cms/wp-includes/wlwmanifest.xml, //feed/, //shop/wp-includes/wlwmanifest.xml, //site/wp-includes/wlwmanifest.xml, //test/wp-includes/wlwmanifest.xml, //web/wp-includes/wlwmanifest.xml, //wordpress/wp-includes/wlwmanifest.xml, //wp-includes/ID3/license.txt, //wp/wp-includes/wlwmanifest.xml, //wp1/wp-includes/wlwmanifest.xml, //xmlrpc.php?rsd
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-28 09:22:07
(3 days ago)
[ti-27al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-27al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.178.94.71 - - [28/Sep/2026:11:21:56 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 7456 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.178.94.71 - - [28/Sep/2026:11:21:56 +0200] "GET //feed/ HTTP/1.1" 404 2156 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.178.94.71 - - [28/Sep/2026:11:21:56 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 300 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.178.94.71 - - [28/Sep/2026:11:21:56 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTT
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-28 09:21:15
(3 days ago)
(wordpress) Failed wordpress login from 34.178.94.71 (71.94.178.34.bc.googleusercontent.com): (CF_E ...
show more
(wordpress) Failed wordpress login from 34.178.94.71 (71.94.178.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Brute-Force
๐ฎ๐น
VHosting
2026-09-28 09:20:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-09-28 09:03:02
(3 days ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐จ๐ญ
zynex
2026-09-28 08:57:55
(3 days ago)
URL Probing: /2020/wp-includes/wlwmanifest.xml
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-28 08:44:15
(3 days ago)
10 attempts against mh-misc-ban on ozone
Web App Attack