๐ฒ๐ฝ
octageeks.com
2026-08-21 04:07:51
(3 days ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 07:54:14
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 34.23.238.113 (113.238.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.23.238.113 (113.238.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 03:54:11.041655 2026] [security2:error] [pid 2886:tid 2886] [client 34.23.238.113:54546] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||wsspy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "wsspy.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aoayo9q8kM3pQyXatyj3gAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-08-20 07:45:27
(4 days ago)
-:443 34.23.238.113 - - [20/Aug/2026:09:45:26 +0200] - "GET //wp-includes/wlwmanifest.xml HTTP/1.1" ...
show more
-:443 34.23.238.113 - - [20/Aug/2026:09:45:26 +0200] - "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 2024 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Bad Web Bot
๐ธ๐ช
vaia.cloud
2026-08-20 07:45:01
(4 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐จ๐ญ
backslash
2026-08-20 07:42:00
(4 days ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฆ๐บ
Klaverstyn
2026-08-20 07:40:33
(4 days ago)
Excessive HTTP request rate
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 07:36:06
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 34.23.238.113 (113.238.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.23.238.113 (113.238.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 03:35:57.973949 2026] [security2:error] [pid 32087:tid 32117] [client 34.23.238.113:50534] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||willmanlawfirm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "willmanlawfirm.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aoauXQPrDOV63wm7cW5SIAAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rip
2026-08-20 07:25:56
(4 days ago)
WordPress fingerprinting and attack surface probing
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 07:20:04
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 34.23.238.113 (113.238.23.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.23.238.113 (113.238.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 03:19:55.497346 2026] [security2:error] [pid 24076:tid 24076] [client 34.23.238.113:52256] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||webuychesterfieldhouses.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "webuychesterfieldhouses.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aoaqm6GAXB11U3-zH461OwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-08-20 07:19:49
(4 days ago)
Web App Attack
Anonymous
2026-08-20 07:16:53
(4 days ago)
Persistent 404 errors over 12h - slow scanning
Bad Web Bot
๐ฉ๐ช
Trueforce Threat Report
2026-08-20 07:16:41
(4 days ago)
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-08-20 07:16:30
(4 days ago)
http-probing - IP: 34.23.238.113 - time="2026-08-20T09:16:29+02:00" level=info msg="(555f66b4f6a745 ...
show more
http-probing - IP: 34.23.238.113 - time="2026-08-20T09:16:29+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 34.23.238.113 (US/396982) : 4h ban on Ip 34.23.238.113" module=db
show less
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-08-20 07:16:26
(4 days ago)
34.23.238.113 - - [20/Aug/2026:09:15:10 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 200 2213 ...
show more
34.23.238.113 - - [20/Aug/2026:09:15:10 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 200 2213 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "US" "North Charleston" "32.86080" "-79.97460"
34.23.238.113 - - [20/Aug/2026:09:15:10 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 200 2213 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "US" "North Charleston" "32.86080" "-79.97460"
34.23.238.113 - - [20/Aug/2026:09:15:10 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 200 2213 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "US" "North Charleston" "32.86080" "-79.97460"
34.23.238.113 - - [20/Aug/2026:09:15:10 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 200 2213 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHT
...
show less
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-20 07:16:05
(4 days ago)
(wordpress) Failed wordpress login from 34.23.238.113 (US/United States/South Carolina/North Charles ...
show more
(wordpress) Failed wordpress login from 34.23.238.113 (US/United States/South Carolina/North Charleston/113.238.23.34.bc.googleusercontent.com/[redacted]): (CF_ENABLE)
show less
Brute-Force