๐ง๐ช
cmbplf
2026-07-03 08:45:03
(15 hours ago)
14.085 requests with url.path */xmlrpc.php
13.987 requests with url.path //xmlrpc.php
1.424 reque ...
show more
14.085 requests with url.path */xmlrpc.php
13.987 requests with url.path //xmlrpc.php
1.424 requests with url.path */wp-includes/wlwmanifest.xml
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
mnsf
2026-07-03 08:08:00
(16 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ช๐ธ
Francisco Vallejo
2026-07-03 08:00:32
(16 hours ago)
[Fri Jul 03 10:00:30.755573 2026] [core:info] [pid 1393522:tid 127200934217408] [client 34.56.125.19 ...
show more
[Fri Jul 03 10:00:30.755573 2026] [core:info] [pid 1393522:tid 127200934217408] [client 34.56.125.192:51201] AH00128: File does not exist: /var/www/barluna/wp-includes/ID3/license.txt
[Fri Jul 03 10:00:30.869657 2026] [core:info] [pid 1393522:tid 127200942610112] [client 34.56.125.192:51201] AH00128: File does not exist: /var/www/barluna/feed/
[Fri Jul 03 10:00:31.017068 2026] [core:info] [pid 1393522:tid 127201872524992] [client 34.56.125.192:51201] AH00128: File does not exist: /var/www/barluna/xmlrpc.php
[Fri Jul 03 10:00:31.124330 2026] [core:info] [pid 1393522:tid 127201596913344] [client 34.56.125.192:51201] AH00128: File does not exist: /var/www/barluna/blog/wp-includes/wlwmanifest.xml
[Fri Jul 03 10:00:31.348965 2026] [core:info] [pid 1393522:tid 127201580127936] [client 34.56.125.192:51201] AH00128: File does not exist: /var/www/barluna/web/wp-includes/wlwmanifest.xml
...
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-07-03 07:58:25
(16 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.56.125.192 (192.125.56.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.56.125.192 (192.125.56.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 03:58:19.223700 2026] [security2:error] [pid 25139:tid 25139] [client 34.56.125.192:50680] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||barecreationsaz.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "barecreationsaz.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "akdrm3oZ5hRG8vMg02q9_wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-03 07:58:04
(16 hours ago)
10 attempts against mh-misc-ban on taro
Web App Attack
๐บ๐ธ
Lee Daniel
2026-07-03 07:55:32
(16 hours ago)
34.56.125.192 - - [03/Jul/2026:03:55:31 -0400] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
34.56.125.192 - - [03/Jul/2026:03:55:31 -0400] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 36817 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.56.125.192 - - [03/Jul/2026:03:55:31 -0400] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 29087 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.56.125.192 - - [03/Jul/2026:03:55:31 -0400] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 36817 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.56.125.192 - - [03/Jul/2026:03:55:31 -0400] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 36817 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.56.125.192 - - [03/Jul/2026:03:55:31 -0400] "GET //wordpress/wp-includes/wlwmanife
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-07-03 07:54:08
(16 hours ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-03 07:42:47
(16 hours ago)
10 attempts against mh-misc-ban on ceres
Web App Attack
๐จ๐ญ
backslash
2026-07-03 07:42:00
(16 hours ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ซ๐ท
dynamix
2026-07-03 07:37:37
(16 hours ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-07-03 07:35:43
(16 hours ago)
-:443 34.56.125.192 - - [03/Jul/2026:09:35:43 +0200] - "GET //xmlrpc.php?rsd HTTP/1.1" 403 1072 "-" ...
show more
-:443 34.56.125.192 - - [03/Jul/2026:09:35:43 +0200] - "GET //xmlrpc.php?rsd HTTP/1.1" 403 1072 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Bad Web Bot
๐ฎ๐น
VHosting
2026-07-03 07:35:05
(16 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐จ๐ญ
Origon
2026-07-03 07:34:52
(16 hours ago)
http-probing - IP: 34.56.125.192 - time="2026-07-03T09:34:51+02:00" level=info msg="(555f66b4f6a745 ...
show more
http-probing - IP: 34.56.125.192 - time="2026-07-03T09:34:51+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 34.56.125.192 (US/396982) : 4h ban on Ip 34.56.125.192" module=db
show less
Web App Attack
๐ง๐ช
Lunix
2026-07-03 07:21:46
(16 hours ago)
Brute-Force
Web App Attack
๐ซ๐ท
Baking333
2026-07-03 07:19:49
(16 hours ago)
[redacted] 34.56.125.192 - - [03/Jul/2026:08:19:47 +0100] "GET //wp-includes/ID3/[redacted] HTTP/1.1 ...
show more
[redacted] 34.56.125.192 - - [03/Jul/2026:08:19:47 +0100] "GET //wp-includes/ID3/[redacted] HTTP/1.1" 302 1528 0/121593 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" [redacted] 34.56.125.192 - - [03/Jul/2026:08:19:48 +0100] "GET /[redacted]?rsd HTTP/1.1" 302 1527 0/51815 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Bad Web Bot
Web App Attack