๐ณ๐ฟ
Antinson
2026-07-20 05:12:48
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-20 04:58:36
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 34.75.212.65 (65.212.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.75.212.65 (65.212.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 00:58:31.933814 2026] [security2:error] [pid 322976:tid 322976] [client 34.75.212.65:64675] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ahsigns.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ahsigns.com"] [uri "/wordpress/wp-json/wp/v2/users/"] [unique_id "al2q9wqzD2fMQkRWbGrfzQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
HandyTreff.de
2026-07-20 04:52:54
(1 day ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -94.486 (Bad < -10 / Very Bad < -20 ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -94.486 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69
show less
Web App Attack
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-20 04:52:05
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-07-20 04:50:03
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฎ๐ฑ
Dolphi
2026-07-20 04:42:15
(1 day ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
๐ซ๐ท
Guardian
2026-07-20 04:37:40
(1 day ago)
Unauthorized connection attempt / Port scanning (x5)
34.75.212.65 [20/Jul/2026:04:37:39] "GET //wp-i ...
show more
Unauthorized connection attempt / Port scanning (x5)
34.75.212.65 [20/Jul/2026:04:37:39] "GET //wp-includes/ID3/license.txt HTTP/1.1"
34.75.212.65 [20/Jul/2026:04:37:39] "GET //feed/ HTTP/1.1"
34.75.212.65 [20/Jul/2026:04:37:39] "GET //xmlrpc.php?rsd HTTP/1.1"
34.75.212.65 [20/Jul/2026:04:37:39] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1"
34.75.212.65 [20/Jul/2026:04:37:39] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1"
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 04:35:45
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 34.75.212.65 (65.212.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.75.212.65 (65.212.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 00:35:41.564987 2026] [security2:error] [pid 3395669:tid 3395669] [client 34.75.212.65:50468] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||adlc18.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "adlc18.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "al2lnbmxpbLkVKDgwIa15QAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wordpresshosting.solutions
2026-07-20 04:35:23
(1 day ago)
Web brute-force / failed auth detected. Evidence: [Mon Jul 20 04:35:22.515612 2026] [access_compat:e ...
show more
Web brute-force / failed auth detected. Evidence: [Mon Jul 20 04:35:22.515612 2026] [access_compat:error] [pid 3061095] [client 34.75.212.65:0] AH01797: client denied by server configuration: [WEB_ROOT]/xmlrpc.php
[Mon Jul 20 04:35:22.612549 2026] [access_compat:error] [pid 3061107] [client 34.75.212.65:0] AH01797: client denied by server configuration: [WEB_ROOT]/xmlrpc.php
show less
Brute-Force
Web App Attack
๐บ๐ธ
ipblock.com
2026-07-20 04:32:00
(1 day ago)
IPBlock protected site ID [3192-af][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-07-20 04:30:58
(1 day ago)
(wordpress-404) Searching for non-existent wordpress installs from 34.75.212.65 (US/United States/So ...
show more
(wordpress-404) Searching for non-existent wordpress installs from 34.75.212.65 (US/United States/South Carolina/North Charleston/65.212.75.34.bc.googleusercontent.com/[redacted])
show less
Brute-Force