๐ฒ๐ฝ
octageeks.com
2026-08-25 04:06:41
(1 day ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
๐บ๐ธ
mnsf
2026-08-24 08:05:44
(2 days ago)
Abuse Detected (12)
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-08-24 08:02:29
(2 days ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.48.124.26 (US/United States/26.124.48.34.bc ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.48.124.26 (US/United States/26.124.48.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/24 10:02:25 [error] 2107374#2107374: *3074535 access forbidden by rule, client: 34.48.124.26, server: circuitografico.it.etag.it, request: "GET //xmlrpc.php?rsd HTTP/1.1", host: "circuitografico.it"
2026/08/24 10:02:25 [error] 2107374#2107374: *3074535 access forbidden by rule, client: 34.48.124.26, server: circuitografico.it.etag.it, request: "GET //?author=1 HTTP/1.1", host: "circuitografico.it"
2026/08/24 10:02:25 [error] 2107374#2107374: *3074535 access forbidden by rule, client: 34.48.124.26, server: circuitografico.it.etag.it, request: "GET //?author=2 HTTP/1.1", host: "circuitografico.it"
show less
Port Scan
๐บ๐ธ
integrantservices.com
2026-08-24 08:01:10
(2 days ago)
(wordpress) Failed wordpress login from 34.48.124.26 (US/United States/26.124.48.34.bc.googleusercon ...
show more
(wordpress) Failed wordpress login from 34.48.124.26 (US/United States/26.124.48.34.bc.googleusercontent.com)
show less
Brute-Force
๐ฉ๐ช
MSC IT for Business GmbH
2026-08-24 08:00:11
(2 days ago)
GASTO/CrowdSec: gasto/modsec-critical triggered (via crowdsec-agent, categories 15,21)
Hacking
Web App Attack
Anonymous
2026-08-24 07:45:03
(2 days ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1
Hacking
Web App Attack
Anonymous
2026-08-24 07:40:05
(2 days ago)
34.48.124.26 - - [24/Aug/2026:09:40:03 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows N ...
show more
34.48.124.26 - - [24/Aug/2026:09:40:03 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.48.124.26 - - [24/Aug/2026:09:40:04 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.48.124.26 - - [24/Aug/2026:09:40:04 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.48.124.26 - - [24/Aug/2026:09:40:04 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.48.124.26 - - [24/Aug/2026:09:40:04 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTM
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-24 07:36:04
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 34.48.124.26 (26.124.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.48.124.26 (26.124.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:35:56.185065 2026] [security2:error] [pid 30840:tid 30840] [client 34.48.124.26:55941] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||certifiedfarmersmarkets.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "certifiedfarmersmarkets.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aov0XGwdGfreyMeyuKYO0AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-08-24 07:34:16
(2 days ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.48.124.26 (US/United States/26.124.48.34.bc ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.48.124.26 (US/United States/26.124.48.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/24 09:34:12 [error] 2107367#2107367: *3069870 access forbidden by rule, client: 34.48.124.26, server: centromedicodiianni.it, request: "GET //xmlrpc.php?rsd HTTP/1.1", host: "centromedicodiianni.it"
2026/08/24 09:34:12 [error] 2107367#2107367: *3069870 access forbidden by rule, client: 34.48.124.26, server: centromedicodiianni.it, request: "GET //?author=1 HTTP/1.1", host: "centromedicodiianni.it"
2026/08/24 09:34:13 [error] 2107367#2107367: *3069870 access forbidden by rule, client: 34.48.124.26, server: centromedicodiianni.it, request: "GET //?author=2 HTTP/1.1", host: "centromedicodiianni.it"
show less
Port Scan
๐ณ๐ฑ
nate naten
2026-08-24 07:33:08
(2 days ago)
HoneyTrap: unknown_probe attempt on //wp-includes/wlwmanifest.xml from United States
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-08-24 07:27:15
(2 days ago)
7.660 requests with url.path */xmlrpc.php
7.625 requests with url.path //xmlrpc.php
1.903 request ...
show more
7.660 requests with url.path */xmlrpc.php
7.625 requests with url.path //xmlrpc.php
1.903 requests with url.path */wp-includes/wlwmanifest.xml
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
maxpower
2026-08-24 07:14:53
(2 days ago)
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.48.124.26 (US/United States/26.124.48.34.bc ...
show more
(nginx_hardened) REGOLA 3 - Nginx Hardening Triggered 34.48.124.26 (US/United States/26.124.48.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2026/08/24 09:14:47 [error] 2107371#2107371: *3064477 access forbidden by rule, client: 34.48.124.26, server: casaflaiano.it, request: "GET //xmlrpc.php?rsd HTTP/1.1", host: "www.casaflaiano.it"
2026/08/24 09:14:49 [error] 2107371#2107371: *3064477 access forbidden by rule, client: 34.48.124.26, server: casaflaiano.it, request: "GET //?author=1 HTTP/1.1", host: "www.casaflaiano.it"
2026/08/24 09:14:49 [error] 2107371#2107371: *3064477 access forbidden by rule, client: 34.48.124.26, server: casaflaiano.it, request: "GET //?author=2 HTTP/1.1", host: "www.casaflaiano.it"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-24 07:13:52
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 34.48.124.26 (26.124.48.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.48.124.26 (26.124.48.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 24 03:13:48.570043 2026] [security2:error] [pid 27298:tid 27298] [client 34.48.124.26:56402] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.cartiologyfilms.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.cartiologyfilms.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aovvLIxeHgt8hY6gWYKnGgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
cybersteve99
2026-08-24 07:07:09
(2 days ago)
Too many 4xx Requests -
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-08-24 07:06:33
(2 days ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/26.124.48.34.bc.googleusercontent.com
Web App Attack