๐ฒ๐ฉ
ruslan
2026-05-20 05:24:00
(3 months ago)
"34.67.189.146 - - [13/May/2026:07:45:50 +0300] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 40 ...
show more
"34.67.189.146 - - [13/May/2026:07:45:50 +0300] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 1249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36""
"34.67.189.146 - - [13/May/2026:07:45:50 +0300] "GET /xmlrpc.php?rsd HTTP/1.1" 404 1249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36""
"34.67.189.146 - - [13/May/2026:07:45:50 +0300] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 1249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36""
"34.67.189.146 - - [13/May/2026:07:45:50 +0300] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 1249 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36""
show less
Brute-Force
Exploited Host
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-05-14 22:00:27
(3 months ago)
Auto-ban: 326 malicious requests on 2026-05-13 (e.g., env/backup probes, brute-force, or error burst ...
show more
Auto-ban: 326 malicious requests on 2026-05-13 (e.g., env/backup probes, brute-force, or error bursts).
show less
Web App Attack
SSH
Hacking
Anonymous
2026-05-13 05:32:00
(3 months ago)
Probing xmlrpc
Bad Web Bot
๐ณ๐ฟ
Antinson
2026-05-13 05:02:54
(3 months ago)
High error rate and elevated request volume targeting cPanel servers
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-13 04:55:20
(3 months ago)
(mod_security) mod_security (id:240335) triggered by 34.67.189.146 (146.189.67.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:240335) triggered by 34.67.189.146 (146.189.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 00:55:15.106095 2026] [security2:error] [pid 8922:tid 8922] [client 34.67.189.146:63161] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 34.67.189.146 (+1 hits since last alert)|mail.capturedbyjamie.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "mail.capturedbyjamie.com"] [uri "/blog/xmlrpc.php"] [unique_id "agQEMyosINQlPuWnATL_3QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-05-13 04:52:25
(3 months ago)
34.67.189.146 - - [13/May/2026:06:52:19 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 " ...
show more
34.67.189.146 - - [13/May/2026:06:52:19 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2026-05-13 04:47:06
(3 months ago)
(mod_security) mod_security (id:210410) triggered by 34.67.189.146 (US/United States/146.189.67.34.b ...
show more
(mod_security) mod_security (id:210410) triggered by 34.67.189.146 (US/United States/146.189.67.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฉ๐ช
abdubhai
2026-05-13 04:44:47
(3 months ago)
34.67.189.146 - - [13/May/2026:0
...
Brute-Force
๐ซ๐ท
Baking333
2026-05-13 04:41:53
(3 months ago)
[redacted] 34.67.189.146 - - [13/May/2026:05:41:51 +0100] "GET //wp-includes/[redacted] HTTP/1.1" 30 ...
show more
[redacted] 34.67.189.146 - - [13/May/2026:05:41:51 +0100] "GET //wp-includes/[redacted] HTTP/1.1" 302 5288 0/63276 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" [redacted] 34.67.189.146 - - [13/May/2026:05:41:52 +0100] "GET //[redacted]?rsd HTTP/1.1" 302 1559 0/72510 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
myintarweb
2026-05-13 04:37:11
(3 months ago)
34.67.189.146 - - [13/May/2026:05:37:10 +0100] 443 "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 1 ...
show more
34.67.189.146 - - [13/May/2026:05:37:10 +0100] 443 "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 1565 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-05-13 04:36:03
(3 months ago)
Bot / scanning and/or hacking attempts: GET //?author=2 HTTP/1.1, POST //xmlrpc.php HTTP/1.1, GET // ...
show more
Bot / scanning and/or hacking attempts: GET //?author=2 HTTP/1.1, POST //xmlrpc.php HTTP/1.1, GET //?author=1 HTTP/1.1, GET //wp-json/wp/v2/users/ HTTP/1.1, GET //xmlrpc.php?rsd HTTP/1.1, GET //wp-includes/wlwmanifest.xml HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ช
cmbplf
2026-05-13 04:28:27
(3 months ago)
55.332 requests with url.path //xmlrpc.php
55.225 requests with url.path */xmlrpc.php
1.756 reque ...
show more
55.332 requests with url.path //xmlrpc.php
55.225 requests with url.path */xmlrpc.php
1.756 requests with url.path */wp-includes/wlwmanifest.xml
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-13 04:27:04
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 34.67.189.146 (146.189.67.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.67.189.146 (146.189.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 13 00:26:57.823338 2026] [security2:error] [pid 24549:tid 24549] [client 34.67.189.146:58887] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bernsteinip.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bernsteinip.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "agP9kQcYvT2nBvqmUHqFFgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-05-13 04:12:04
(3 months ago)
Wordfence waf block on lostswordfish
Web App Attack
๐ฎ๐น
VHosting
2026-05-13 04:05:02
(3 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack