Anonymous
2026-09-01 02:00:27
(1 day ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-30 14:08:21
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 35.223.144.195 (195.144.223.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 35.223.144.195 (195.144.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 10:08:16.224656 2026] [security2:error] [pid 5929:tid 5929] [client 35.223.144.195:56838] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||karenbernsteinlaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "karenbernsteinlaw.com"] [uri "/wp-includes/id3/license.txt/blog/wp-json/wp/v2/users/"] [unique_id "apQ5UKT2t_lOap1NevQf_wAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-30 14:07:24
(3 days ago)
PSCSERV WPSCAN 35.223.144.195
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-30 14:01:14
(3 days ago)
URL Probing: /wp1/wp-includes/wlwmanifest.xml
Web App Attack
๐ฉ๐ช
IVski.com
2026-08-30 13:36:12
(3 days ago)
IVski WAF | Sensitive file probe - looking for WordPress license.txt
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
abuse-detection
2026-08-30 13:24:54
(3 days ago)
Security detection: http-probing
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-08-30 13:24:47
(3 days ago)
tried to access forbidden files; attempted to access /blog/wp-includes/wlwmanifest.xml
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-30 13:20:10
(3 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-30 13:12:53
(3 days ago)
35.223.144.195 - - [30/Aug/2026:15:12:48 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 40 ...
show more
35.223.144.195 - - [30/Aug/2026:15:12:48 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:12:48 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:12:48 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:12:49 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:12:49 +0200] "GET //2020/wp-includes/wlwmanifest.xml HT
show less
Web App Attack
Hacking
Anonymous
2026-08-30 13:12:47
(3 days ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐ซ๐ท
Zundapper
2026-08-30 13:12:38
(3 days ago)
35.223.144.195 - - [30/Aug/2026:15:12:36 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 ...
show more
35.223.144.195 - - [30/Aug/2026:15:12:36 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:12:36 +0200] "GET //feed/ HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:12:36 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:12:37 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:12:37 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5
...
show less
Web App Attack
Port Scan
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-30 13:08:41
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-08-30 13:08:23
(3 days ago)
35.223.144.195 - - [30/Aug/2026:15:08:21 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 ...
show more
35.223.144.195 - - [30/Aug/2026:15:08:21 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:08:22 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:08:22 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:08:22 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.223.144.195 - - [30/Aug/2026:15:08:22 +0200] "GET /wp/wp-includes/wlwmanifest.xml HTTP/1.1" 40
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-08-30 13:06:41
(3 days ago)
Abuse Detected (5)
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-08-30 13:00:05
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack