🇧🇪
cmbplf
2026-09-06 15:09:11
(7 hours ago)
38.018 requests in 1 hour (1mo4w1d)
Brute-Force
Bad Web Bot
🇺🇸
WizardsToolkit
2026-09-06 15:06:43
(7 hours ago)
tried to access forbidden files; attempted to access /blog/wp-includes/wlwmanifest.xml
Web App Attack
🇳🇱
Site.eu
2026-09-06 14:57:58
(7 hours ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
🇳🇿
Antinson
2026-09-06 14:56:56
(7 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇩🇪
abdubhai
2026-09-06 14:52:29
(7 hours ago)
34.85.162.27 - - [06/Sep/2026:19
...
Brute-Force
Anonymous
2026-09-06 14:41:05
(7 hours ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
🇫🇷
Zundapper
2026-09-06 14:32:20
(7 hours ago)
34.85.162.27 - - [06/Sep/2026:16:32:20 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 " ...
show more
34.85.162.27 - - [06/Sep/2026:16:32:20 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.85.162.27 - - [06/Sep/2026:16:32:20 +0200] "GET //feed/ HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.85.162.27 - - [06/Sep/2026:16:32:20 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.85.162.27 - - [06/Sep/2026:16:32:20 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.85.162.27 - - [06/Sep/2026:16:32:20 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Window
...
show less
Web App Attack
Port Scan
🇨🇭
zynex
2026-09-06 14:19:46
(7 hours ago)
URL Probing: /wp-includes/id3/license.txt/shop/wp-includes/wlwmanifest.xml
Web App Attack
🇺🇸
kosada.com
2026-09-06 14:19:03
(7 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /wp-includes/id3/license.txt/web/wp- ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /wp-includes/id3/license.txt/web/wp-includes/wlwmanifest.xml (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36")
show less
Web App Attack
Anonymous
2026-09-06 14:17:05
(7 hours ago)
34.85.162.27 - - [06/Sep/2026:16:17:03 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 "- ...
show more
34.85.162.27 - - [06/Sep/2026:16:17:03 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.85.162.27 - - [06/Sep/2026:16:17:04 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.85.162.27 - - [06/Sep/2026:16:17:04 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.85.162.27 - - [06/Sep/2026:16:17:04 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.85.162.27 - - [06/Sep/2026:16:17:05 +0200] "GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-"
...
show less
Brute-Force
Web App Attack
🇬🇷
setupgr
2026-09-06 14:08:10
(8 hours ago)
(mod_security) mod_security (id:11000011) triggered by 34.85.162.27 (US/United States/District of Co ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.85.162.27 (US/United States/District of Columbia/Washington/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:08:07.057921 2026] [security2:error] [pid 2931:tid 3080] [client 34.85.162.27:60974] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 27.162.85.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "host.setworldup365.com"] [uri "/"] [unique_id "ap1zx4UVipLknC0H8kNtxgAAAso"]
show less
Port Scan
🇺🇸
mnsf
2026-09-06 14:05:40
(8 hours ago)
Abuse Detected (7)
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-06 14:00:05
(8 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
SCHAPPY
2026-09-06 13:56:58
(8 hours ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-06 13:54:07
(8 hours ago)
34.85.162.27 - - [06/Sep/2026:07:54:06 -0600] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
34.85.162.27 - - [06/Sep/2026:07:54:06 -0600] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 4504 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack