๐ธ๐ช
vaia.cloud
2026-08-18 15:45:01
(6 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-08-18 15:41:52
(6 days ago)
35.205.139.91 - - [18/Aug/2026:17:41:49 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 " ...
show more
35.205.139.91 - - [18/Aug/2026:17:41:49 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
35.205.139.91 - - [18/Aug/2026:17:41:50 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
35.205.139.91 - - [18/Aug/2026:17:41:51 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
35.205.139.91 - - [18/Aug/2026:17:41:51 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
35.205.139.91 - - [18/Aug/2026:17:41:52 +0200] "GET /website/wp-includes/wlwmanifest.xml HTTP/1.1
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 15:37:18
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 35.205.139.91 (91.139.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 35.205.139.91 (91.139.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 11:37:10.668958 2026] [security2:error] [pid 31348:tid 31348] [client 35.205.139.91:59455] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||emailaegis.axiomemail.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "emailaegis.axiomemail.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "aoR8JqVHgtMPCKloUB8txgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-08-18 15:23:45
(6 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ซ๐ท
Bruno
2026-08-18 15:05:54
(6 days ago)
[Tue Aug 18 17:05:43.255790 2026] [authz_core:error] [pid 2923717:tid 2923793] [client 35.205.139.91 ...
show more
[Tue Aug 18 17:05:43.255790 2026] [authz_core:error] [pid 2923717:tid 2923793] [client 35.205.139.91:55077] AH01630: client denied by server configuration: /srv/web/sansouire/www2/xmlrpc.php
[Tue Aug 18 17:05:53.217858 2026] [authz_core:error] [pid 2923717:tid 2923806] [client 35.205.139.91:52033] AH01630: client denied by server configuration: /srv/web/sansouire/www2/xmlrpc.php
[Tue Aug 18 17:05:53.225008 2026] [authz_core:error] [pid 2923717:tid 2923776] [client 35.205.139.91:52033] AH01630: client denied by server configuration: /srv/web/sansouire/www2/xmlrpc.php
...
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-18 15:04:15
(6 days ago)
Probing websites for vulnerabilities
Web App Attack
๐จ๐ญ
backslash
2026-08-18 15:03:02
(6 days ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
๐ง๐พ
lns.bz
2026-08-18 15:02:17
(6 days ago)
Too many 404 requests [BY]
Web App Attack
๐จ๐ญ
zynex
2026-08-18 14:59:33
(6 days ago)
URL Probing: /2019/wp-includes/wlwmanifest.xml
Web App Attack
๐ฉ๐ช
stinpriza
2026-08-18 14:48:31
(6 days ago)
WP Authentication attempt for unknown user
Brute-Force
Web App Attack
๐ณ๐ด
jad-abuse
2026-08-18 14:46:21
(6 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 18 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-18 14:45:32
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 35.205.139.91 (91.139.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 35.205.139.91 (91.139.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 10:45:28.703737 2026] [security2:error] [pid 27233:tid 27233] [client 35.205.139.91:51403] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dwightbrown.com.casagrotto.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dwightbrown.com.casagrotto.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aoRwCHks7myFrS-_r1dpwwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-18 14:40:44
(6 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฎ๐น
VHosting
2026-08-18 14:40:04
(6 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack