๐บ๐ธ
ph
2026-06-16 13:01:53
(3 days ago)
Bad web bot attempting to run xmlrpc.php on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 13:00:42
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 34.9.251.169 (169.251.9.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.9.251.169 (169.251.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 09:00:38.480300 2026] [security2:error] [pid 2244:tid 2244] [client 34.9.251.169:62652] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mkdesignndetailing.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mkdesignndetailing.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajFI9mnS6xAwegSNrBc5KgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lezetho
2026-06-16 13:00:28
(3 days ago)
DDoS, WebSpam, Web Attack, and Brute-force blocked by Cloudflare
DDoS Attack
Email Spam
Hacking
Brute-Force
๐ณ๐ด
jad-abuse
2026-06-16 12:58:07
(3 days ago)
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Obse ...
show more
ThreatFeed automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 14 hits.
show less
Brute-Force
Web App Attack
๐ฉ๐ช
Holger
2026-06-16 12:42:11
(3 days ago)
WordPress WebAttack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 12:41:46
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 34.9.251.169 (169.251.9.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.9.251.169 (169.251.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 08:41:41.362472 2026] [security2:error] [pid 5217:tid 5228] [client 34.9.251.169:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.mindgardens.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.mindgardens.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajFEhbRS1dCPmMxHRacoNgAAAYc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2026-06-16 12:37:00
(3 days ago)
IPBlock protected site ID [1887-mw].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ฆ๐บ
Anytech
2026-06-16 12:29:39
(3 days ago)
Blocked by Conn-Monitor: Web scanning activity
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-06-16 12:21:09
(3 days ago)
34.9.251.169 - - [16/Jun/2026:15:21:08 +0300] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 683 "- ...
show more
34.9.251.169 - - [16/Jun/2026:15:21:08 +0300] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 683 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
34.9.251.169 - - [16/Jun/2026:15:21:09 +0300] "GET /xmlrpc.php?rsd HTTP/1.1" 404 683 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
Kreapptivo
2026-06-16 12:19:59
(3 days ago)
[16/Jun/2026:14:19:58 +0200] Web-Request: "GET //wp-includes/ID3/license.txt", User-Agent: "Mozilla/ ...
show more
[16/Jun/2026:14:19:58 +0200] Web-Request: "GET //wp-includes/ID3/license.txt", User-Agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-16 12:17:11
(3 days ago)
10 attempts against mh-misc-ban on ceres
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 12:14:52
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 34.9.251.169 (169.251.9.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.9.251.169 (169.251.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 08:14:47.478313 2026] [security2:error] [pid 5004:tid 5004] [client 34.9.251.169:49772] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||method1.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "method1.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "ajE-N2zdgHRcKIWuMHej5QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Block Rockin' Beats
2026-06-16 12:13:03
(3 days ago)
Scanning for exploitable scripts
Hacking
Web App Attack
๐ฎ๐น
VHosting
2026-06-16 12:10:02
(3 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ช๐ธ
Francisco Vallejo
2026-06-16 12:07:27
(3 days ago)
[Tue Jun 16 14:07:26.095904 2026] [core:info] [pid 644722:tid 130567072904896] [client 34.9.251.169: ...
show more
[Tue Jun 16 14:07:26.095904 2026] [core:info] [pid 644722:tid 130567072904896] [client 34.9.251.169:64430] AH00128: File does not exist: /var/www/menu_barluna/wp-includes/ID3/license.txt
[Tue Jun 16 14:07:26.214688 2026] [core:info] [pid 644722:tid 130567064512192] [client 34.9.251.169:64430] AH00128: File does not exist: /var/www/menu_barluna/feed/
[Tue Jun 16 14:07:26.321115 2026] [core:info] [pid 644722:tid 130567039334080] [client 34.9.251.169:64430] AH00128: File does not exist: /var/www/menu_barluna/xmlrpc.php
[Tue Jun 16 14:07:26.426184 2026] [core:info] [pid 644722:tid 130567056119488] [client 34.9.251.169:64430] AH00128: File does not exist: /var/www/menu_barluna/blog/wp-includes/wlwmanifest.xml
[Tue Jun 16 14:07:26.536476 2026] [core:info] [pid 644722:tid 130565982377664] [client 34.9.251.169:64430] AH00128: File does not exist: /var/www/menu_barluna/web/wp-includes/wlwmanifest.xml
...
show less
Brute-Force
SSH