๐บ๐ธ
mnsf
2026-09-24 12:05:15
(18 hours ago)
Abuse Detected (12)
Brute-Force
Web App Attack
๐ช๐ธ
robotstxt
2026-09-24 11:37:20
(18 hours ago)
34.46.202.43 - - [24/Sep/2026:11:36:52 +0000] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 591 " ...
show more
34.46.202.43 - - [24/Sep/2026:11:36:52 +0000] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" "-" edge="34.46.202.43"
34.46.202.43 - - [24/Sep/2026:11:36:52 +0000] "GET //xmlrpc.php?rsd HTTP/1.1" 403 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" "-" edge="34.46.202.43"
34.46.202.43 - - [24/Sep/2026:11:36:52 +0000] "GET / HTTP/1.1" 403 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" "-" edge="34.46.202.43"
34.46.202.43 - - [24/Sep/2026:11:36:52 +0000] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 403 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" "-" edge="34.46.202.43"
34.46.202.43 - - [24/Sep/2026:11:36:53 +0000] "GET //web
...
show less
Web App Attack
๐จ๐ฆ
zXero
2026-09-24 11:23:57
(19 hours ago)
Fail2Ban automatic report - jail: no-wordpress
Brute-Force
SSH
DDoS Attack
Anonymous
2026-09-24 11:20:21
(19 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 11:13:35
(19 hours ago)
12.754 post requests in 1 hour (3d21h27m)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 11:07:02
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.46.202.43 (43.202.46.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.46.202.43 (43.202.46.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 07:06:55.508029 2026] [security2:error] [pid 19816:tid 19816] [client 34.46.202.43:58927] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cathybermanmft.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cathybermanmft.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "arUETyAI-X8VVlXRPt0YNwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-24 11:01:43
(19 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
LRob
2026-09-24 10:59:38
(19 hours ago)
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, ...
show more
This address sent web requests that have no legitimate reading: known exploit paths, path traversal, injected payloads, or the signature of a vulnerability scanner. This is an attack on the sites we host, blocked on sight. Please check the machine behind it for an attack tool or malware. | method: GET (+1 more) | path: // (+1 more) | query: author=1 (+1 more) | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36 | 2026-09-24 10:59 UTC
show less
Hacking
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-09-24 10:57:11
(19 hours ago)
Repeated 403 Forbidden responses
Web App Attack
๐ซ๐ท
Stara
2026-09-24 10:55:20
(19 hours ago)
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kinesk ...
show more
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kineskinja)
show less
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-24 10:50:11
(19 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
ruusvuu
2026-09-24 10:49:45
(19 hours ago)
Automated abuse report: 15 attack/probe requests from Google LLC / US.
Targeted paths: //wp-includes ...
show more
Automated abuse report: 15 attack/probe requests from Google LLC / US.
Targeted paths: //wp-includes/wlwmanifest.xml, //xmlrpc.php, //blog/wp-includes/wlwmanifest.xml, //web/wp-includes/wlwmanifest.xml, //wordpress/wp-includes/wlwmanifest.xml.
Sample log lines:
[mir-com] [9/24/2026, 3:49:45 AM] GET .mirregistry.com//wp/wp-includes/wlwmanifest.xml 404 34.46.202.43 - 5.373 ms
[mir-org] [9/24/2026, 3:49:45 AM] GET .mirregistry.org//news/wp-includes/wlwmanifest.xml 404 34.46.202.43 - 5.735 ms
[mir-com] [9/24/2026, 3:49:45 AM] GET .mirregistry.com//news/wp-includes/wlwmanifest.xml 404 34.46.202.43 - 11.437 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
๐ณ๐ฑ
MyGlobalFlowers
2026-09-24 10:49:38
(19 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 10:46:20
(19 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.46.202.43 (43.202.46.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.46.202.43 (43.202.46.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 06:46:14.097270 2026] [security2:error] [pid 12405:tid 12405] [client 34.46.202.43:54908] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||muslera.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "muslera.com"] [uri "/blog/wp-json/wp/v2/users/"] [unique_id "arT_dvyqBdi0u_vot8jSVgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-24 10:42:56
(19 hours ago)
34.46.202.43 - - [24/Sep/2026:12:42:52 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 " ...
show more
34.46.202.43 - - [24/Sep/2026:12:42:52 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.46.202.43 - - [24/Sep/2026:12:42:53 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.46.202.43 - - [24/Sep/2026:12:42:53 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.46.202.43 - - [24/Sep/2026:12:42:53 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
34.46.202.43 - - [24/Sep/2026:12:42:53 +0200] "GET //website/wp-includes/wlwmanifest.xml HTTP/1.1
show less
Web App Attack
Hacking