🇺🇸
mnsf
2026-09-03 12:05:31
(20 hours ago)
Abuse Detected (18)
Brute-Force
Web App Attack
🇨🇭
YF
2026-09-03 12:00:42
(20 hours ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
🇹🇷
ycoskun41
2026-09-03 11:56:19
(20 hours ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 11:50:45
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.181.209.23 (23.209.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.181.209.23 (23.209.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 07:50:40.799058 2026] [security2:error] [pid 1415:tid 1415] [client 34.181.209.23:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.yggdrasil.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.yggdrasil.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aplfEFE9-coSuBQq1Bvk9QAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Rip
2026-09-03 11:47:14
(20 hours ago)
WordPress fingerprinting and attack surface probing
Port Scan
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-03 11:46:30
(20 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇳🇱
javierin
2026-09-03 11:40:36
(20 hours ago)
34.181.209.23 - xn--nombres-de-nio-2nb.es - - [03/Sep/2026:11:40:34 +0000] "GET //wp-includes/wlwman ...
show more
34.181.209.23 - xn--nombres-de-nio-2nb.es - - [03/Sep/2026:11:40:34 +0000] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 19565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.181.209.23 - xn--nombres-de-nio-2nb.es - - [03/Sep/2026:11:40:34 +0000] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 19565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.181.209.23 - xn--nombres-de-nio-2nb.es - - [03/Sep/2026:11:40:34 +0000] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 19565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.181.209.23 - xn--nombres-de-nio-2nb.es - - [03/Sep/2026:11:40:35 +0000] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 19565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78
...
show less
Hacking
Web App Attack
🇩🇪
FeG Deutschland
2026-09-03 11:30:41
(20 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 11:30:38
(20 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.181.209.23 (23.209.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.181.209.23 (23.209.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 07:30:31.064537 2026] [security2:error] [pid 16387:tid 16387] [client 34.181.209.23:54809] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.xhumanlikerobots.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.xhumanlikerobots.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aplaV6BATzJ0lACf9MM4sAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-03 11:24:30
(20 hours ago)
URL Probing: /2019/wp-includes/wlwmanifest.xml
Web App Attack
🇳🇱
Site.eu
2026-09-01 13:36:59
(2 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇫🇮
as211431.net
2026-09-01 13:29:58
(2 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: //test/wp-includes/wlwmanifest.xml
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇳🇱
i-turnradio.nl
2026-09-01 13:23:30
(2 days ago)
2026-09-01 @ 15:23:30 (CET) ~ Blocked for trying to access: /wp-includes/ID3/license.txt
Web App Attack
🇫🇷
Catalin Negru
2026-09-01 13:20:56
(2 days ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇯🇵
Valhalla
2026-09-01 13:17:57
(2 days ago)
/wp-includes/ID3/license.txt
Hacking
Web App Attack