๐ณ๐ฟ
Antinson
2026-06-17 05:20:57
(6 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
daveoctober
2026-06-17 05:08:50
(6 days ago)
October Sentinel: honeypot triggered
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-06-17 05:08:04
(6 days ago)
Wordfence waf block on illinoisvoices
Web App Attack
Anonymous
2026-06-17 05:07:02
(6 days ago)
Automated web scanner. Requested suspicious paths: //2019/wp-includes/wlwmanifest.xml, //2020/wp-inc ...
show more
Automated web scanner. Requested suspicious paths: //2019/wp-includes/wlwmanifest.xml, //2020/wp-includes/wlwmanifest.xml, //2021/wp-includes/wlwmanifest.xml, //blog/wp-includes/wlwmanifest.xml, //cms/wp-includes/wlwmanifest.xml. UTC: 2026-06-17 04:40:49.
show less
Web App Attack
๐บ๐ธ
mnsf
2026-06-17 05:06:27
(6 days ago)
Too many Status 40X (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 05:03:41
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 34.31.169.160 (160.169.31.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.31.169.160 (160.169.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 01:03:36.958578 2026] [security2:error] [pid 24101:tid 24101] [client 34.31.169.160:57329] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.innovacionesnimba.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.innovacionesnimba.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajIqqNd7WJ2jQWH9PtYCWgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-06-17 04:47:42
(6 days ago)
URL Probing: /wp1/wp-includes/wlwmanifest.xml
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 04:45:38
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 34.31.169.160 (160.169.31.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.31.169.160 (160.169.31.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 00:45:33.313019 2026] [security2:error] [pid 23892:tid 23892] [client 34.31.169.160:50527] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.impressionsinthread.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.impressionsinthread.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajImbXbj00L0QOtzD_MkhgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-17 04:42:42
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐ฆ๐บ
Lazarus
2026-06-17 04:37:38
(6 days ago)
HTTP probe.
Web App Attack
๐ฉ๐ช
AetherFox
2026-06-17 04:31:46
(6 days ago)
AetherFox VoidGuard detected: [Wed Jun 17 04:31:45.597222 2026] [authz_core:error] [pid 951308:tid 9 ...
show more
AetherFox VoidGuard detected: [Wed Jun 17 04:31:45.597222 2026] [authz_core:error] [pid 951308:tid 951358] [client 34.31.169.160:64080] AH01630: client denied by server configuration: proxy:http://[MASKED]/
[Wed Jun 17 04:31:45.597433 2026] [authz_core:error] [pid 951308:tid 951358] [client 34.31.169.160:64080] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Wed Jun 17 04:31:45.713764 2026] [authz_core:error] [pid 951308:tid 951324] [client 34.31.169.160:64080] AH01630: client denied by server configuration: proxy:http://[MASKED]/wp-includes/ID3/license.txt
[Wed Jun 17 04:31:45.713924 2026] [authz_core:error] [pid 951308:tid 951324] [client 34.31.169.160:64080] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Wed Jun 17 04:31:45.834956 2026] [authz_core:error] [pid 951308:tid 951333] [client 34.31.169.160:64080] AH01630: client denied by server configuration: proxy:http://[MASKED]/feed/
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-06-17 04:25:03
(6 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ง๐ท
dominioz
2026-06-17 04:22:54
(6 days ago)
2026-06-17 04:22:46 GET /wp-includes/ID3/license.txt X-ARR-CACHE-HIT=0&X-ARR-LOG-ID=e78ca110-0b5d-41 ...
show more
2026-06-17 04:22:46 GET /wp-includes/ID3/license.txt X-ARR-CACHE-HIT=0&X-ARR-LOG-ID=e78ca110-0b5d-414e-a6ae-f8b58b0838e5&SERVER-STATUS=404 - 34.31.169.160 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/95.0.4638.69+Safari/537.36 - 404 1261
2026-06-17 04:22:46 GET /feed/ X-ARR-CACHE-HIT=0&X-ARR-LOG-ID=0ac6843e-14c9-420f-a803-bf0ef2ef3e76&SERVER-STATUS=404 - 34.31.169.160 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/95.0.4638.69+Safari/537.36 - 404 1261
2026-06-17 04:22:46 GET /xmlrpc.php rsd - 34.31.169.160 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/95.0.4638.69+Safari/537.36 - 404 474
2026-06-17 04:22:46 GET /blog/wp-includes/wlwmanifest.xml X-ARR-CACHE-HIT=0&X-ARR-LOG-ID=d8d5d959-5907-4a5f-8b87-78b17af9ebcd&SERVER-STATUS=404 - 34.31.169.160 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Ch
...
show less
Web App Attack