๐ญ๐บ
miszterx.hu
2026-09-23 06:59:47
(2 days ago)
XORP (haproxy): 15x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ip ...
show more
XORP (haproxy): 15x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 14:22:53
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ท๐ด
iulianh
2026-09-22 14:21:44
(3 days ago)
80,443
Brute-Force
SSH
๐บ๐ธ
H24
2026-09-22 14:15:26
(3 days ago)
/wp/wp-includes/wlwmanifest.xml /wp-includes/ID3/license.txt /blog/wp-includes/wlwmanifest.xml /word ...
show more
/wp/wp-includes/wlwmanifest.xml /wp-includes/ID3/license.txt /blog/wp-includes/wlwmanifest.xml /wordpress/wp-includes/wlwmanifest.xml /web/wp-includes/wlwmanifest.xml /xmlrpc.php /wp1/wp-includes/wlwmanifest.xml /shop/wp-includes/wlwmanifest.xml /2021/wp-includes/wlwmanifest.xml /test/wp-includes/wlwmanifest.xml
show less
Web App Attack
๐ง๐ช
webbie
2026-09-22 14:06:37
(3 days ago)
35.227.167.108 - - [22/Sep/2026:16:06:35 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 503 ...
show more
35.227.167.108 - - [22/Sep/2026:16:06:35 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 5030 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.227.167.108 - - [22/Sep/2026:16:06:36 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 465 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.227.167.108 - - [22/Sep/2026:16:06:36 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 465 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.227.167.108 - - [22/Sep/2026:16:06:36 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 465 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.227.167.108 - - [22/Sep/2026:16:06:36 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 465 "-"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 14:06:26
(3 days ago)
Too many Status 40X (13)
Brute-Force
Web App Attack
๐ณ๐ฑ
loebas
2026-09-22 14:01:16
(3 days ago)
35.227.167.108 - - [22/Sep/2026:16:01:14 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 849 ...
show more
35.227.167.108 - - [22/Sep/2026:16:01:14 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 8491 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.227.167.108 - - [22/Sep/2026:16:01:14 +0200] "GET //feed/ HTTP/1.1" 404 3515 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.227.167.108 - - [22/Sep/2026:16:01:14 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 570 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.227.167.108 - - [22/Sep/2026:16:01:15 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 3515 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.227.167.108 - - [22/Sep/2026:16:01:15 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 3515 "-" "Mozilla/5.0 (Windows NT 10.0
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
infra-monitor
2026-09-22 14:00:11
(3 days ago)
Automated ban via infra-monitor: wp-sensitive-paths, wordpress-probe, webshell-high-confidence
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:54:59
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 35.227.167.108 (108.167.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 35.227.167.108 (108.167.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:54:53.085177 2026] [security2:error] [pid 25948:tid 25948] [client 35.227.167.108:52146] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||hollywooddrummers.mikedeutsch.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "hollywooddrummers.mikedeutsch.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "arKIrVXmIMvkn30UuBsnngAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-22 13:50:13
(3 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 13:50:06
(3 days ago)
Fail2Ban nginx-bad-request: malformed or invalid HTTP request
Port Scan
๐ณ๐ฑ
Site.eu
2026-09-22 13:48:57
(3 days ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
Anonymous
2026-09-22 13:43:59
(3 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-22 13:40:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-22 13:37:04
(3 days ago)
Bot / scanning and/or hacking attempts: POST //xmlrpc.php HTTP/1.1
Hacking
Web App Attack