Anonymous
2026-07-29 07:00:00
(6 hours ago)
Automated Apache web application probing in selected 24h window; attempts=25, unique_paths=3, error_ ...
show more
Automated Apache web application probing in selected 24h window; attempts=25, unique_paths=3, error_responses=5; targets include WordPress, .env/.git, phpMyAdmin, autodiscover, wpad.dat and related probe paths.
show less
Web App Attack
Anonymous
2026-07-29 07:00:00
(6 hours ago)
Apache probe; attempts=25; exact paths: //xmlrpc.php | //xmlrpc.php?rsd | /xmlrpc.php?rsd
Web App Attack
๐จ๐ฆ
polycoda
2026-07-29 05:06:17
(7 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-07-29 05:02:11
(8 hours ago)
Bad_requests
Bad Web Bot
๐ฉ๐ช
Marc
2026-07-29 05:01:11
(8 hours ago)
34.79.31.115 - - [29/Jul/2026:07:01:09 +0200] "POST //xmlrpc.php HTTP/1.1" 403 871 "-" "Mozilla/5.0 ...
show more
34.79.31.115 - - [29/Jul/2026:07:01:09 +0200] "POST //xmlrpc.php HTTP/1.1" 403 871 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" 34.79.31.115 - - [29/Jul/2026:07:01:10 +0200] "POST //xmlrpc.php HTTP/1.1" 403 4642 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" 34.79.31.115 - - [29/Jul/2026:07:01:10 +0200] "POST //xmlrpc.php HTTP/1.1" 403 4643 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
show less
Brute-Force
Web App Attack
Anonymous
2026-07-29 04:57:04
(8 hours ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1
Hacking
Web App Attack
๐จ๐ฆ
Anytech
2026-07-29 04:52:05
(8 hours ago)
Blocked by Conn-Monitor
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 04:30:19
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.79.31.115 (115.31.79.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.79.31.115 (115.31.79.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 00:30:12.710477 2026] [security2:error] [pid 18540:tid 18540] [client 34.79.31.115:54067] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||latentpixel.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "latentpixel.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ammB1MjgHWxN7J5JyOvULgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
YF
2026-07-29 04:30:14
(8 hours ago)
WordPress author enumeration
Web App Attack
๐ฉ๐ช
maxpower
2026-07-29 04:28:31
(8 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 34.79.31.115 (BE/Belgium/115.31.79.34.bc.googl ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 34.79.31.115 (BE/Belgium/115.31.79.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.79.31.115 - - [29/Jul/2026:06:28:29 +0200] "GET //wp-json/wp/v2/users/ HTTP/2.0" 200 301 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36" "34.79.31.115" host=lasfiziosapizzeria.it
show less
Port Scan
๐จ๐ญ
backslash
2026-07-29 04:27:00
(8 hours ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ซ๐ท
largo-it.net
2026-07-29 04:26:39
(8 hours ago)
Jul 29 06:26:28 vps-9f3cdc33 haproxy[3223045]: 34.79.31.115:59326 [29/Jul/2026:06:26:27.868] www_fro ...
show more
Jul 29 06:26:28 vps-9f3cdc33 haproxy[3223045]: 34.79.31.115:59326 [29/Jul/2026:06:26:27.868] www_frontend~ finance_cluster/finance1_test1_https 12/0/10/542/564 404 3151 - - ---- 97/51/6/6/0 0/0 "GET /fr//wp-includes/wlwmanifest.xml HTTP/1.1"
Jul 29 06:26:29 vps-9f3cdc33 haproxy[3223045]: 34.79.31.115:59326 [29/Jul/2026:06:26:28.433] www_frontend~ finance_cluster/finance1_test1_https 12/0/10/663/685 404 3151 - - ---- 96/50/7/7/0 0/0 "GET /fr//xmlrpc.php?rsd HTTP/1.1"
Jul 29 06:26:35 vps-9f3cdc33 haproxy[3223045]: 34.79.31.115:59326 [29/Jul/2026:06:26:30.484] www_frontend~ finance_cluster/finance1_test1_https 4261/0/11/523/4795 404 3151 - - ---- 92/46/5/5/0 0/0 "GET /fr//blog/wp-includes/wlwmanifest.xml HTTP/1.1"
Jul 29 06:26:35 vps-9f3cdc33 haproxy[3223045]: 34.79.31.115:59326 [29/Jul/2026:06:26:35.279] www_frontend~ finance_cluster/finance1_test1_https 12/0/10/315/337 404 3151 - - ---- 92/46/7/7/0 0/0 "GET /fr//web/wp-includes/wlwmanifest.xml HTTP/1.1"
Jul 29 06:26:36 vps-9f3cdc33 hapr
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-07-29 04:25:17
(8 hours ago)
WordPress: User enumeration. Pattern match "(author\\\\= (88030-197)
Hacking
๐จ๐ญ
zynex
2026-07-29 04:21:53
(8 hours ago)
URL Probing: /2020/wp-includes/wlwmanifest.xml
Web App Attack
๐ฉ๐ช
LRob
2026-07-29 04:15:20
(8 hours ago)
CrowdSec: lrob/wp-xmlrpc-bf | req: //xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) Appl ...
show more
CrowdSec: lrob/wp-xmlrpc-bf | req: //xmlrpc.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36
show less
Brute-Force
Web App Attack