๐ญ๐บ
miszterx.hu
2026-08-26 09:25:27
(4 days ago)
XORP (haproxy): 2x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 2x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ง๐ช
taivas.nl
2026-08-26 04:32:40
(5 days ago)
Many_bad_calls
Web App Attack
Anonymous
2026-08-25 10:33:00
(5 days ago)
suricata IPS/IDS detection, ruleset ET SCAN WordPress Scanner Performing Multiple Requests to Window ...
show more
suricata IPS/IDS detection, ruleset ET SCAN WordPress Scanner Performing Multiple Requests to Windows Live Writer XML
show less
Port Scan
Anonymous
2026-08-25 10:30:04
(5 days ago)
CrowdSec decision: crowdsecurity/http-probing (origin: crowdsec)
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-25 10:19:39
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-08-25 10:17:31
(5 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐จ๐ญ
zynex
2026-08-25 10:10:09
(5 days ago)
URL Probing: /xmlrpc.php
Web App Attack
๐จ๐ญ
Origon
2026-08-25 10:02:38
(5 days ago)
http-probing - IP: 35.196.207.242 - time="2026-08-25T12:02:37+02:00" level=info msg="(555f66b4f6a74 ...
show more
http-probing - IP: 35.196.207.242 - time="2026-08-25T12:02:37+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 35.196.207.242 (US/396982) : 4h ban on Ip 35.196.207.242" module=db
show less
Web App Attack
๐ง๐ช
taivas.nl
2026-08-25 10:02:12
(5 days ago)
Bad_requests
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-08-25 10:01:33
(5 days ago)
15 attempts against mh-modsecurity-ban on pf221107
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 10:00:38
(5 days ago)
(mod_security) mod_security (id:225170) triggered by 35.196.207.242 (242.207.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 35.196.207.242 (242.207.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 06:00:33.849754 2026] [security2:error] [pid 9325:tid 9325] [client 35.196.207.242:57761] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||renomarsh.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "renomarsh.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao1nwfqZAAtk_Yvq58PNIAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-08-25 09:59:13
(5 days ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
๐ธ๐ช
nekopavel
2026-08-25 09:54:06
(5 days ago)
35.196.207.242 - - [25/Aug/2026:11:54:03 +0200]"GET /outpost.goauthentik.io/start?rd=https%3a%2f%2fr ...
show more
35.196.207.242 - - [25/Aug/2026:11:54:03 +0200]"GET /outpost.goauthentik.io/start?rd=https%3a%2f%2fremnawave.pavel.gg%2f/wp-includes/wlwmanifest.xml HTTP/1.1" 302 768"-" remnawave.pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36""0.127" "0.000""North Charleston" "US"
35.196.207.242 - - [25/Aug/2026:11:54:03 +0200]"GET /outpost.goauthentik.io/start?rd=https%3a%2f%2fremnawave.pavel.gg%2f/xmlrpc.php?rsd HTTP/1.1" 302 750"-" remnawave.pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36""0.123" "0.000""North Charleston" "US"
35.196.207.242 - - [25/Aug/2026:11:54:03 +0200]"GET /outpost.goauthentik.io/start?rd=https%3a%2f%2fremnawave.pavel.gg%2f/blog/wp-includes/wlwmanifest.xml HTTP/1.1" 302 774"-" remnawave.pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36""0.122" "0.0
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
Guardian
2026-08-25 09:53:09
(5 days ago)
Unauthorized connection attempt / Port scanning (x9)
35.196.207.242 [25/Aug/2026:11:53:08 +0200] "GE ...
show more
Unauthorized connection attempt / Port scanning (x9)
35.196.207.242 [25/Aug/2026:11:53:08 +0200] "GET / HTTP/1.1"
35.196.207.242 [25/Aug/2026:11:53:08 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1"
35.196.207.242 [25/Aug/2026:11:53:08 +0200] "GET //xmlrpc.php?rsd HTTP/1.1"
35.196.207.242 [25/Aug/2026:11:53:08 +0200] "GET / HTTP/1.1"
35.196.207.242 [25/Aug/2026:11:53:08 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1"
35.196.207.242 [25/Aug/2026:11:53:09 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1"
35.196.207.242 [25/Aug/2026:11:53:09 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1"
35.196.207.242 [25/Aug/2026:11:53:09 +0200] "GET //website/wp-includes/wlwmanifest.xml HTTP/1.1"
35.196.207.242 [25/Aug/2026:11:53:09 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1"
35.196.207.242 [25/Aug/2026:11:53:09 +0200] "GET //news/wp-includes/wlwmanifest.xml HTTP/1.1"
show less
Port Scan
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-25 09:50:36
(5 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack