🇺🇸
mnsf
2026-09-11 08:05:21
(2 hours ago)
Too many Status 40X (14)
Brute-Force
Web App Attack
🇵🇱
Budyn
2026-09-11 07:37:25
(2 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicio ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: WP Path Scanning (Recon). Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: shop.sweetpuddingtrap.top | URI: //xmlrpc.php?rsd | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
🇩🇪
raph
2026-09-11 07:34:56
(2 hours ago)
[Wordpress] crawler /wp-admin/*, /wp-content/*, etc.
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-11 07:34:16
(2 hours ago)
2.184 requests with url.path */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
🇦🇺
Bay13
2026-09-11 07:34:10
(2 hours ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
🇨🇭
zynex
2026-09-11 07:21:26
(2 hours ago)
URL Probing: /de/wp-includes/id3/license.txt/wp1/wp-includes/wlwmanifest.xml
Web App Attack
🇺🇸
creechy
2026-09-11 07:12:16
(2 hours ago)
34.48.126.32 - - [11/Sep/2026:00:12:15 -0700] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 787 "- ...
show more
34.48.126.32 - - [11/Sep/2026:00:12:15 -0700] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 787 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Hacking
Bad Web Bot
🇳🇿
Tripwire
2026-09-11 07:08:19
(3 hours ago)
Scanning for exploits - //wp-includes/ID3/license.txt
Web App Attack
🇩🇪
Blexyel
2026-09-11 06:54:14
(3 hours ago)
34.48.126.32 - - [11/Sep/2026:08:54:13 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
34.48.126.32 - - [11/Sep/2026:08:54:13 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 435 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "share.fomx.gay"
...
show less
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-11 06:50:03
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇬🇷
setupgr
2026-09-11 06:34:25
(3 hours ago)
(mod_security) mod_security (id:11000011) triggered by 34.48.126.32 (US/United States/District of Co ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.48.126.32 (US/United States/District of Columbia/Washington/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Sep 11 09:34:20.002911 2026] [security2:error] [pid 29155:tid 29321] [client 34.48.126.32:60588] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 32.126.48.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "setworldup365.com"] [uri "/"] [unique_id "aqOg645RCw3nR3vXMIYO3AAABJQ"]
show less
Port Scan
🇫🇷
Baking333
2026-09-11 06:33:42
(3 hours ago)
[redacted] 34.48.126.32 - - [11/Sep/2026:07:33:39 +0100] "GET //wp-includes/ID3/[redacted] HTTP/1.1" ...
show more
[redacted] 34.48.126.32 - - [11/Sep/2026:07:33:39 +0100] "GET //wp-includes/ID3/[redacted] HTTP/1.1" 302 6773 0/57213 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" [redacted] 34.48.126.32 - - [11/Sep/2026:07:33:40 +0100] "GET /[redacted]?rsd HTTP/1.1" 302 1554 0/43003 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 06:33:37
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇫🇮
as211431.net
2026-09-11 06:31:24
(3 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: //cms/wp-includes/wlwmanifest.xml
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot