🇺🇸
TPI-Abuse
2026-08-30 16:37:44
(10 hours ago)
(mod_security) mod_security (id:225170) triggered by 34.85.235.136 (136.235.85.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 34.85.235.136 (136.235.85.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 12:37:41.312351 2026] [security2:error] [pid 2666363:tid 2666425] [client 34.85.235.136:60783] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||daraluz.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "daraluz.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "apRcVYHJszO_6HLV-M3ngwAAANY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-08-30 16:37:09
(10 hours ago)
Blocked by CSF 13 firewall - Rule: XMLRPC
US/United States/136.235.85.34.bc.googleusercontent.com
Web App Attack
🇺🇸
cwytech
2026-08-30 16:33:42
(10 hours ago)
Fleet-wide ban from the Ghostfleet 👻. Triggered by scenario: cwy/wordpress-xmlrpc-bf-slow-high.
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-08-30 16:31:21
(10 hours ago)
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 34.85.235.136 (US/United States/136.235.85.34. ...
show more
(wp_fingerprint) REGOLA 6 - WP Exploit Attempt xmlrpc 34.85.235.136 (US/United States/136.235.85.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.85.235.136 - - [30/Aug/2026:18:31:16 +0200] "GET //wp-json/wp/v2/users/ HTTP/2.0" 200 624 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" "34.85.235.136" host=ctpescara.it
show less
Port Scan
🇮🇹
VHosting
2026-08-30 16:30:04
(10 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-08-30 16:30:03
(10 hours ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1
Hacking
Web App Attack
🇩🇪
filstal.org
2026-08-30 15:57:48
(10 hours ago)
Bad bot activity detected (automated scraping/probing).
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-08-30 15:30:36
(11 hours ago)
[30/Aug/2026:18:30:36 +0300] -- 34.85.235.136 Ban reason: User-Agent CMS-Checker
Bad Web Bot
Web App Attack
Anonymous
2026-03-24 20:17:32
(5 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
Anonymous
2026-03-24 14:32:17
(5 months ago)
34.85.235.136 - - [24/Mar/2026:16:32:17 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.0" 404 462 " ...
show more
34.85.235.136 - - [24/Mar/2026:16:32:17 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.0" 404 462 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.85.235.136 - - [24/Mar/2026:16:32:17 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 294 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.85.235.136 - - [24/Mar/2026:16:32:17 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.0" 404 462 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.85.235.136 - - [24/Mar/2026:16:32:17 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 294 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
34.85.235.136 - - [24/Mar/2026:16:32:17 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.0" 404 462 "-"
...
show less
Brute-Force
Web App Attack
🇳🇿
Antinson
2026-03-24 14:30:55
(5 months ago)
High error rate and elevated request volume targeting cPanel servers
Bad Web Bot
🇺🇸
Major Hostility
2026-03-24 14:13:50
(5 months ago)
"GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/1.1" 403
"GET /blog/wp-inc ...
show more
"GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /xmlrpc.php?rsd HTTP/1.1" 403
"GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /website/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /news/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /2018/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /2019/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /shop/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /wp1/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /test/wp-includes/wlwmanifest.xml HTTP/1.1" 404
"GET /media/wp-includes/wlwmanifest.xml HTTP/1.1" 404
show less
Web App Attack
🇩🇪
Blexyel
2026-03-24 13:58:10
(5 months ago)
34.85.235.136 - - [24/Mar/2026:13:58:05 +0000] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 " ...
show more
34.85.235.136 - - [24/Mar/2026:13:58:05 +0000] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇵🇱
webadmin
2026-03-24 13:55:26
(5 months ago)
2026/03/24 14:55:23 [error] 4038332#4038332: *290738 open() "/usr/share/nginx/html/wp-includes/wlwma ...
show more
2026/03/24 14:55:23 [error] 4038332#4038332: *290738 open() "/usr/share/nginx/html/wp-includes/wlwmanifest.xml" failed (2: No such file or directory), client: 34.85.235.136, server: mail.agileskincare.org, request: "GET /wp-includes/wlwmanifest.xml HTTP/1.1", host: "mail.agileskincare.org"
2026/03/24 14:55:23 [error] 4038332#4038332: *290738 open() "/usr/share/nginx/html/xmlrpc.php" failed (2: No such file or directory), client: 34.85.235.136, server: mail.agileskincare.org, request: "GET /xmlrpc.php?rsd HTTP/1.1", host: "mail.agileskincare.org"
2026/03/24 14:55:24 [error] 4038332#4038332: *290738 open() "/usr/share/nginx/html/blog/wp-includes/wlwmanifest.xml" failed (2: No such file or directory), client: 34.85.235.136, server: mail.agileskincare.org, request: "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1", host: "mail.agileskincare.org"
2026/03/24 14:55:24 [error] 4038332#4038332: *290738 open() "/usr/share/nginx/html/web/wp-includes/wlwmanifest.xml" failed (2: No such file or dire
...
show less
Web App Attack