๐ณ๐ฑ
Site.eu
2026-07-13 23:32:47
(1 week ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ง๐ช
cmbplf
2026-07-13 16:05:34
(1 week ago)
76.935 requests in 1 hour (2mos4w13h)
Brute-Force
Bad Web Bot
๐ณ๐ฟ
Antinson
2026-07-13 15:55:02
(1 week ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-13 15:19:43
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 34.77.91.9 (9.91.77.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:225170) triggered by 34.77.91.9 (9.91.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 11:19:35.070004 2026] [security2:error] [pid 24607:tid 24607] [client 34.77.91.9:52521] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tasteshop.l3l4.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tasteshop.l3l4.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "alUCB5ZzsBr07DhvaQGpHwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-07-13 15:18:49
(1 week ago)
10 attempts against mh-misc-ban on ceres
Web App Attack
Anonymous
2026-07-13 15:10:04
(1 week ago)
Bot / scanning and/or hacking attempts: GET ///wp1/wp-includes/wlwmanifest.xml HTTP/1.1, POST //xmlr ...
show more
Bot / scanning and/or hacking attempts: GET ///wp1/wp-includes/wlwmanifest.xml HTTP/1.1, POST //xmlrpc.php HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 15:04:06
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 34.77.91.9 (9.91.77.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:225170) triggered by 34.77.91.9 (9.91.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 11:04:01.319041 2026] [security2:error] [pid 8534:tid 8572] [client 34.77.91.9:61178] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||streamriders.com.hdtv55.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "streamriders.com.hdtv55.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "alT-YQwDmoAW-SeM-oba9wAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-07-13 14:59:37
(1 week ago)
http-probing - IP: 34.77.91.9 - time="2026-07-13T16:59:37+02:00" level=info msg="(555f66b4f6a74558b ...
show more
http-probing - IP: 34.77.91.9 - time="2026-07-13T16:59:37+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 34.77.91.9 (BE/396982) : 4h ban on Ip 34.77.91.9" module=db
show less
Web App Attack
๐ช๐จ
icp77
2026-07-13 14:58:00
(1 week ago)
Abuse DDoS
DDoS Attack
Port Scan
Brute-Force
Exploited Host
Web App Attack
SSH
FTP Brute-Force
Hacking
SQL Injection
๐ฉ๐ช
Jarda_H
2026-07-13 14:52:04
(1 week ago)
wordpress-scan Attack Detected
Web App Attack
๐ณ๐ฑ
Roderic
2026-07-13 14:50:55
(1 week ago)
(wordpress-404) Searching for non-existent wordpress installs from 34.77.91.9 (BE/Belgium/Brussels C ...
show more
(wordpress-404) Searching for non-existent wordpress installs from 34.77.91.9 (BE/Belgium/Brussels Capital/Brussels/9.91.77.34.bc.googleusercontent.com/[redacted])
show less
Brute-Force
๐ฉ๐ช
FeG Deutschland
2026-07-13 14:50:32
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-13 14:48:38
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 34.77.91.9 (9.91.77.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:225170) triggered by 34.77.91.9 (9.91.77.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 13 10:48:31.156565 2026] [security2:error] [pid 24600:tid 24600] [client 34.77.91.9:61978] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||souldata.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "souldata.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "alT6v8PWDUH9jUsWPq7EDwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-07-13 14:48:01
(1 week ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ณ๐ด
jad-abuse
2026-07-13 14:46:15
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 16 hits.
show less
Brute-Force
Web App Attack