Anonymous
2026-06-04 17:09:12
(1 day ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-06-04 14:35:10
(1 day ago)
URL Probing: /wp/wp-includes/wlwmanifest.xml
Web App Attack
๐ง๐ท
Halux
2026-06-04 14:30:41
(1 day ago)
34.78.117.3 Web Application Firewall multiple violations
Hacking
Web App Attack
๐ซ๐ท
tecnoacquisti.com
2026-06-04 14:27:22
(1 day ago)
PrestaShop Security Module: Calls WordPress paths probing known vulnerabilities
Web App Attack
๐ซ๐ท
masterguru
2026-06-04 14:25:38
(1 day ago)
(xmlrpc) Apache: Failed xmlrpc access from 34.78.117.3 (BE/Belgium/3.117.78.34.bc.googleusercontent. ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 34.78.117.3 (BE/Belgium/3.117.78.34.bc.googleusercontent.com): 10 in the last 3600 secs (0-201)
show less
Hacking
๐ฉ๐ช
filstal.org
2026-06-04 14:23:52
(1 day ago)
WordPress login brute-force detected by Fail2Ban
Brute-Force
Web App Attack
Anonymous
2026-06-04 14:22:15
(1 day ago)
34.78.117.3 - - [04/Jun/2026:16:22:13 +0200] "POST /xmlrpc.php HTTP/1.1" 200 591 "-" "Mozilla/5.0 (W ...
show more
34.78.117.3 - - [04/Jun/2026:16:22:13 +0200] "POST /xmlrpc.php HTTP/1.1" 200 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
34.78.117.3 - - [04/Jun/2026:16:22:13 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
34.78.117.3 - - [04/Jun/2026:16:22:13 +0200] "POST /xmlrpc.php HTTP/1.1" 200 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
34.78.117.3 - - [04/Jun/2026:16:22:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 401 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
34.78.117.3 - - [04/Jun/2026:16:22:14 +0200] "POST /xmlrpc.php HTTP/1.1" 200 591 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-06-04 14:21:34
(1 day ago)
attempted to access /wp-includes/wlwmanifest.xml
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 14:17:16
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 34.78.117.3 (3.117.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:225170) triggered by 34.78.117.3 (3.117.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 10:17:11.722271 2026] [security2:error] [pid 17551:tid 17551] [client 34.78.117.3:57860] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.techsunlimited.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.techsunlimited.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiGI522q3FbSy-m3xtrmSAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Moby
2026-06-04 14:15:43
(1 day ago)
34.78.117.3 - - [04/Jun/2026:09:15:41 -0500] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 984 "-" ...
show more
34.78.117.3 - - [04/Jun/2026:09:15:41 -0500] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 984 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36" "75.88.18.218" "techspace.cc"
34.78.117.3 - - [04/Jun/2026:09:15:41 -0500] "GET /xmlrpc.php?rsd HTTP/1.1" 404 984 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36" "75.88.18.218" "techspace.cc"
Thu Jun 04 09:15:41.928116 202634.78.117.3 - - [04/Jun/2026:09:15:42 -0500] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 984 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36" "75.88.18.218" "techspace.cc"
...
show less
Web App Attack
๐จ๐ญ
backslash
2026-06-04 14:06:00
(1 day ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฎ๐น
VHosting
2026-06-04 14:05:04
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐จ๐ญ
Origon
2026-06-04 14:01:15
(1 day ago)
http-probing - IP: 34.78.117.3 - time="2026-06-04T16:01:14+02:00" level=info msg="(555f66b4f6a74558 ...
show more
http-probing - IP: 34.78.117.3 - time="2026-06-04T16:01:14+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 34.78.117.3 (BE/396982) : 4h ban on Ip 34.78.117.3" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 13:56:56
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 34.78.117.3 (3.117.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:225170) triggered by 34.78.117.3 (3.117.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 09:56:53.200876 2026] [security2:error] [pid 21104:tid 21104] [client 34.78.117.3:56360] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.technesa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.technesa.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aiGEJSggPRttB5BKqWmQ6gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack