🇩🇪
ghostwarriors
2026-08-30 10:20:09
(2 weeks ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇺🇸
kosada.com
2026-08-30 10:11:22
(2 weeks ago)
Web vulnerability probing: /wordpress/wp-includes/wlwmanifest.xml
Web App Attack
🇩🇪
yitzhaq
2026-08-30 10:10:16
(2 weeks ago)
35.197.1.6 - - [30/Aug/2026:12:10:07 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 506 ...
show more
35.197.1.6 - - [30/Aug/2026:12:10:07 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 506 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.197.1.6 - - [30/Aug/2026:12:10:08 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 506 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.197.1.6 - - [30/Aug/2026:12:10:08 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 506 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.197.1.6 - - [30/Aug/2026:12:10:08 +0200] "GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 506 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.197.1.6 - - [30/Aug/2026:12:10:07 +0200] "GET / HTTP/1.1" 200 1514 "-" "Mozilla/5.0 (Windows NT 10.0; Win64
show less
Web App Attack
Hacking
🇩🇪
Blexyel
2026-08-30 10:09:48
(2 weeks ago)
35.197.1.6 - - [30/Aug/2026:12:09:47 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 ...
show more
35.197.1.6 - - [30/Aug/2026:12:09:47 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇩🇪
seal
2026-08-30 10:09:36
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
SSH
Brute-Force
🇺🇸
mnsf
2026-08-30 10:06:31
(2 weeks ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
🇫🇮
as211431.net
2026-08-30 09:59:23
(2 weeks ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: //cms/wp-includes/wlwmanifest.xml
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇫🇷
Stara
2026-08-30 09:55:16
(2 weeks ago)
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kinesk ...
show more
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kineskinja)
show less
Hacking
Brute-Force
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-08-30 09:51:16
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇫🇮
Shaik Sai Meera
2026-08-30 09:50:16
(2 weeks ago)
IM360 WAF: WordPress plugins/themes version enumeration
Brute-Force
FTP Brute-Force
Open Proxy
🇩🇪
mondor.ro
2026-08-30 09:48:33
(2 weeks ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 35.197.1.6, Reason:[(m ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 35.197.1.6, Reason:[(manifest) WordPress wlwmanifest.xml Attack 35.197.1.6 (US/United States/6.1.197.35.bc.googleusercontent.com): 10 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
🇫🇷
Zundapper
2026-08-30 09:45:21
(2 weeks ago)
35.197.1.6 - - [30/Aug/2026:11:45:20 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 "-" ...
show more
35.197.1.6 - - [30/Aug/2026:11:45:20 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.197.1.6 - - [30/Aug/2026:11:45:20 +0200] "GET //feed/ HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.197.1.6 - - [30/Aug/2026:11:45:20 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.197.1.6 - - [30/Aug/2026:11:45:20 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.197.1.6 - - [30/Aug/2026:11:45:20 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0;
...
show less
Web App Attack
Port Scan
🇺🇸
brightenfield
2026-08-30 09:42:11
(2 weeks ago)
Web App Attack
Web App Attack
🇮🇹
VHosting
2026-08-30 09:40:04
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
FeG Deutschland
2026-08-30 09:32:55
(2 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack