๐จ๐ญ
zynex
2026-07-28 13:40:39
(3 hours ago)
URL Probing: /2019/wp-includes/wlwmanifest.xml
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 13:32:18
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.53.161.56 (56.161.53.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.53.161.56 (56.161.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 09:32:11.131306 2026] [security2:error] [pid 1734674:tid 1734674] [client 34.53.161.56:61913] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gerrytolentino.praemiumtech.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gerrytolentino.praemiumtech.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "amivW4GQtbA7WF4c1ChywwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-07-28 13:32:13
(3 hours ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-28 13:13:58
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.53.161.56 (56.161.53.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.53.161.56 (56.161.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 09:13:54.177535 2026] [security2:error] [pid 25656:tid 25656] [client 34.53.161.56:62549] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gardner.farm.brazilianbottom.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gardner.farm.brazilianbottom.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "amirErv_kcO7S87N0MeybAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Sklurk
2026-07-28 13:08:01
(4 hours ago)
Web App Attack
Web App Attack
๐จ๐ญ
backslash
2026-07-28 13:06:00
(4 hours ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฉ๐ช
big-cloud.nl
2026-07-28 12:52:38
(4 hours ago)
Try to access /xmlrpc.php?rsd
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 12:48:12
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.53.161.56 (56.161.53.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.53.161.56 (56.161.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 08:48:05.425239 2026] [security2:error] [pid 3734711:tid 3735119] [client 34.53.161.56:52404] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||frannykingsmith.com.sloveniaflyfishing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "frannykingsmith.com.sloveniaflyfishing.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "amilBUwcEvK1dSjr8mH9RgAAAQw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-28 12:47:28
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
SCHAPPY
2026-07-28 12:30:13
(4 hours ago)
Mutliple attempts to access forbidden web resources, HTTP code 403.
Web App Attack
๐ฎ๐น
VHosting
2026-07-28 12:30:05
(4 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 12:29:34
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.53.161.56 (56.161.53.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.53.161.56 (56.161.53.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 08:29:26.778186 2026] [security2:error] [pid 1585960:tid 1585960] [client 34.53.161.56:58342] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||firewoodstudio.67ronin.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "firewoodstudio.67ronin.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "amigptR1X4-yPfD9m5pX7AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
largo-it.net
2026-07-28 12:27:17
(4 hours ago)
Jul 28 14:27:14 vps-9f3cdc33 haproxy[3101757]: 34.53.161.56:64482 [28/Jul/2026:14:27:14.087] www_fro ...
show more
Jul 28 14:27:14 vps-9f3cdc33 haproxy[3101757]: 34.53.161.56:64482 [28/Jul/2026:14:27:14.087] www_frontend~ finance_cluster/finance1_test1_https 23/0/11/335/369 404 3151 - - ---- 89/44/4/4/0 0/0 "GET /fr//wp-includes/wlwmanifest.xml HTTP/1.1"
Jul 28 14:27:14 vps-9f3cdc33 haproxy[3101757]: 34.53.161.56:64482 [28/Jul/2026:14:27:14.456] www_frontend~ finance_cluster/finance1_test1_https 35/0/11/356/402 404 3151 - - ---- 87/42/3/3/0 0/0 "GET /fr//xmlrpc.php?rsd HTTP/1.1"
Jul 28 14:27:15 vps-9f3cdc33 haproxy[3101757]: 34.53.161.56:64482 [28/Jul/2026:14:27:14.859] www_frontend~ finance_cluster/finance1_test1_https 12/0/10/905/963 404 199823 - - ---- 87/42/1/1/0 0/0 "GET /fr/ HTTP/1.1"
Jul 28 14:27:16 vps-9f3cdc33 haproxy[3101757]: 34.53.161.56:64482 [28/Jul/2026:14:27:15.822] www_frontend~ finance_cluster/finance1_test1_https 241/0/11/327/579 404 3151 - - ---- 87/42/2/2/0 0/0 "GET /fr//blog/wp-includes/wlwmanifest.xml HTTP/1.1"
Jul 28 14:27:16 vps-9f3cdc33 haproxy[3101757]: 34.53.161.56:64482
...
show less
Hacking
Bad Web Bot
Web App Attack