|
๐บ๐ธ
mnsf
|
|
Abuse Detected (9)
|
Brute-Force
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 34.23.58.213 (213.58.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.23.58.213 (213.58.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:23:16.257568 2026] [security2:error] [pid 29240:tid 29240] [client 34.23.58.213:59329] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.athletefirst.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.athletefirst.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aovxZJ29KyZxmTapsMqlOgAAAAo"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
kosada.com
|
|
Web vulnerability probing: //wordpress/wp-includes/wlwmanifest.xml
|
Web App Attack
|
|
|
๐ฉ๐ช
BlueWire Hosting
|
|
Probing websites for vulnerabilities
|
Web App Attack
|
|
|
๐จ๐พ
mubusys.com
|
|
34.23.58.213 - - [24/Aug/2026:04:14:29 -0300] "" 400 0 "-" "-" "-"
34.23.58.213 - - [24/Aug/2026:04: ...
show more
34.23.58.213 - - [24/Aug/2026:04:14:29 -0300] "" 400 0 "-" "-" "-"
34.23.58.213 - - [24/Aug/2026:04:14:29 -0300] "" 400 0 "-" "-" "-"
show less
|
Hacking
Brute-Force
|
|
|
๐ซ๐ท
Feelautom
|
|
[FeelAutom Auto-Ban] AI Analyst: Score 180/200 et scan de chemins WordPress rรฉpรฉtรฉ (PathScan)
|
Port Scan
|
|
|
๐ณ๐ฑ
ipoac.nl
|
|
-:443 34.23.58.213 - - [24/Aug/2026:09:05:16 +0200] - "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 4 ...
show more
-:443 34.23.58.213 - - [24/Aug/2026:09:05:16 +0200] - "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 1968 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
|
Bad Web Bot
|
|
|
๐ง๐ช
cmbplf
|
|
8.987 post requests in 1 hour (1w2d5h)
|
Brute-Force
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:225170) triggered by 34.23.58.213 (213.58.23.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.23.58.213 (213.58.23.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:02:35.240842 2026] [security2:error] [pid 31225:tid 31225] [client 34.23.58.213:57094] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||artichokedesign.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "artichokedesign.net"] [uri "/wordpress/wp-json/wp/v2/users/"] [unique_id "aovsi7yJoTerufO_ELrFqAAAAAA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ณ๐ฑ
javierin
|
|
34.23.58.213 - arras-de-boda.es - - [24/Aug/2026:06:59:22 +0000] "GET //wp-includes/wlwmanifest.xml ...
show more
34.23.58.213 - arras-de-boda.es - - [24/Aug/2026:06:59:22 +0000] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 3953 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.23.58.213 - arras-de-boda.es - - [24/Aug/2026:06:59:22 +0000] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 3953 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.23.58.213 - arras-de-boda.es - - [24/Aug/2026:06:59:22 +0000] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 3953 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.23.58.213 - arras-de-boda.es - - [24/Aug/2026:06:59:22 +0000] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 3953 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.23.58.213 - ar
...
show less
|
Hacking
Web App Attack
|
|
|
๐ซ๐ท
Lunix
|
|
|
Brute-Force
Web App Attack
|
|
|
๐ฉ๐ช
maxpower
|
|
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.23.58.213 (US/United States/213.58.23.34.bc ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.23.58.213 (US/United States/213.58.23.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/24 08:52:27 [error] 2018399#2018399: *3058033 access forbidden by rule, client: 34.23.58.213, server: archabi.it, request: "GET //xmlrpc.php?rsd HTTP/1.1", host: "www.archabi.it"
2026/08/24 08:52:28 [error] 2018399#2018399: *3058033 access forbidden by rule, client: 34.23.58.213, server: archabi.it, request: "GET //?author=1 HTTP/1.1", host: "www.archabi.it"
2026/08/24 08:52:28 [error] 2018399#2018399: *3058033 access forbidden by rule, client: 34.23.58.213, server: archabi.it, request: "GET //?author=2 HTTP/1.1", host: "www.archabi.it"
show less
|
Port Scan
|
|
|
๐ฎ๐น
VHosting
|
|
Detected WordPress attack from different servers
|
Brute-Force
Web App Attack
|
|
|
๐ฆ๐บ
screwlooseit.com.au
|
|
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/213.58.23.34.bc.googleusercontent.com
|
Web App Attack
|
|
|
๐ต๐ฑ
Budyn
|
|
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.store | URI: //xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36 | BODY: <?xml version="1.0"?><methodCall><methodName>system.multicall</methodName><params><param><value><array><data> <value><struct><member><name>methodName</name><value><string>wp.getUsersBlogs</string></value></member><member><name>params</name><value><array><data><value><array><data><value><string>admin</string></value><value><str
show less
|
Bad Web Bot
Web App Attack
|
|