๐ง๐ช
Ivo Vynckier
2026-07-21 09:57:00
(1 day ago)
35.196.151.99 - - [20/Jul/2026:14:15:56 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 5550 ...
show more
35.196.151.99 - - [20/Jul/2026:14:15:56 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 5550 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.196.151.99 - - [20/Jul/2026:14:15:56 +0200] "GET //feed/ HTTP/1.1" 403 819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.196.151.99 - - [20/Jul/2026:14:15:56 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Web App Attack
Anonymous
2026-07-20 13:07:01
(2 days ago)
Automated web scanner. Requested suspicious paths: //wp-includes/ID3/license.txt | //blog/wp-include ...
show more
Automated web scanner. Requested suspicious paths: //wp-includes/ID3/license.txt | //blog/wp-includes/wlwmanifest.xml | //web/wp-includes/wlwmanifest.xml | //xmlrpc.php | //wordpress/wp-includes/wlwmanifest.xml | //2020/wp-includes/wlwmanifest.xml | //wp/wp-includes/wlwmanifest.xml | //2019/wp-includes/wlwmanifest.xml | //2021/wp-includes/wlwmanifest.xml | //shop/wp-includes/wlwmanifest.xml | //wp1/wp-includes/wlwmanifest.xml | //test/wp-includes/wlwmanifest.xml. UTC: 2026-07-20 12:46:07.
show less
Web App Attack
๐บ๐ธ
mnsf
2026-07-20 13:05:11
(2 days ago)
Too many Status 40X (14)
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-07-20 12:56:53
(2 days ago)
(xmlrpc) Apache: Failed xmlrpc access from 35.196.151.99 (US/United States/99.151.196.35.bc.googleus ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 35.196.151.99 (US/United States/99.151.196.35.bc.googleusercontent.com): 10 in the last 3600 secs (0-180)
show less
Hacking
๐ณ๐ฟ
Antinson
2026-07-20 12:42:14
(2 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐จ๐ญ
blinx
2026-07-20 12:39:21
(2 days ago)
Suspicious activity detected by Modsecurity
Web Spam
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-07-20 12:36:59
(2 days ago)
35.196.151.99 - - [20/Jul/2026:14:36:59 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
35.196.151.99 - - [20/Jul/2026:14:36:59 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "pingusmc.org"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-20 12:33:59
(2 days ago)
(mod_security) mod_security (id:225170) triggered by 35.196.151.99 (99.151.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 35.196.151.99 (99.151.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 08:33:51.403820 2026] [security2:error] [pid 3641:tid 3641] [client 35.196.151.99:59377] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blackberrycircle.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blackberrycircle.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "al4Vr7W2_3O-fqgZ0QZdwgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-07-20 12:25:29
(2 days ago)
2026/07/20 12:25:27 [error] 1774906#1774906: *392781043 access forbidden by rule, client: 35.196.151 ...
show more
2026/07/20 12:25:27 [error] 1774906#1774906: *392781043 access forbidden by rule, client: 35.196.151.99, server: binixo.lk, request: "GET //wp-includes/ID3/license.txt HTTP/2.0", host: "binixo.lk"
2026/07/20 12:25:27 [error] 1774906#1774906: *392781048 access forbidden by rule, client: 35.196.151.99, server: binixo.com.ar, request: "GET //wp-includes/ID3/license.txt HTTP/2.0", host: "binixo.com.ar"
2026/07/20 12:25:27 [error] 1774910#1774910: *392778607 access forbidden by rule, client: 35.196.151.99, server: binixo.lk, request: "GET //xmlrpc.php?rsd HTTP/2.0", host: "binixo.lk"
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-07-20 12:25:03
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐จ๐ฆ
Anytech
2026-07-20 12:21:38
(2 days ago)
Blocked by Conn-Monitor: wordpress-path-probe-nonwp
Bad Web Bot
Hacking
Web App Attack
๐จ๐ญ
backslash
2026-07-20 12:21:00
(2 days ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐ฌ๐ง
Mendip_Defender
2026-07-20 12:16:16
(2 days ago)
35.196.151.99 - - [20/Jul/2026:13:16:14 +0100] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 1066 ...
show more
35.196.151.99 - - [20/Jul/2026:13:16:14 +0100] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 1066 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.196.151.99 - - [20/Jul/2026:13:16:15 +0100] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 1066 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.196.151.99 - - [20/Jul/2026:13:16:15 +0100] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 1066 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Hacking
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-20 12:16:06
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.196.151.99 (US/United States/99. ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.196.151.99 (US/United States/99.151.196.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-20 12:13:35
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack