Anonymous
2025-11-04 17:02:57
(7 months ago)
[redacted] 35.237.41.106 - - [04/Nov/2025:18:02:56 +0100] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" " ...
show more
[redacted] 35.237.41.106 - - [04/Nov/2025:18:02:56 +0100] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
[redacted] 35.237.41.106 - - [04/Nov/2025:18:02:56 +0100] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
[redacted] 35.237.41.106 - - [04/Nov/2025:18:02:56 +0100] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
[redacted] 35.237.41.106 - - [04/Nov/2025:18:02:56 +0100] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36"
[redacted] 35.237.41.106 - - [04/Nov/2025:18:02:56 +0100] "POST //xmlrpc.php HTTP/1.1" 200 416 "-" "Moz
...
show less
Hacking
Web App Attack
๐ฎ๐น
VHosting
2025-11-04 17:00:10
(7 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2025-11-04 16:58:59
(7 months ago)
125.580 requests in 1 hour (1mo3w3d)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-04 16:53:32
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 35.237.41.106 (106.41.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 35.237.41.106 (106.41.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 04 11:53:28.375377 2025] [security2:error] [pid 22510:tid 22510] [client 35.237.41.106:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||southernbroadcast.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "southernbroadcast.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aQoviB4LBDrxrM1xpSdZGQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2025-11-04 16:34:17
(7 months ago)
3 attack(s) detected, such as these: {"event":"nginx_block","ip":"35.237.41.106","host":"sn.estate.k ...
show more
3 attack(s) detected, such as these: {"event":"nginx_block","ip":"35.237.41.106","host":"sn.estate.kasm.life","request":"GET /wp-includes/wlwmanifest.xml HTTP/1.1","user_agent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36","reason":"service:unknow","timestamp":"2025-11-04T16:34:17 00:00","logentry":"sn.estate.kasm.life 35.237.41.106 - - [04/Nov/2025:16:34:17 0000] GET /wp-includes/wlwmanifest.xml HTTP/1.1 444 0 - Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36 - matched:service:unknow"} * Report Details *: https://p4u.xyz/Q55USHR4426/1* IP Details *: https://p4u.xyz/Q55USHR4426/2
show less
Web Spam
Hacking
Bad Web Bot
๐ฎ๐ช
Jim Keir
2025-11-04 16:32:26
(7 months ago)
2025-11-04 16:32:25 35.237.41.106 File scanning, blocking 35.237.41.106 for 5 minutes
Web App Attack
๐ซ๐ท
masterguru
2025-11-04 16:27:18
(7 months ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-193)
Hacking
๐ฉ๐ช
ยฉMBยฉ
2025-11-04 16:26:43
(7 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Hacking
Web App Attack
๐ซ๐ท
Little Iguana
2025-11-04 16:24:50
(7 months ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐บ๐ธ
smithclass.net
2025-11-04 16:21:16
(7 months ago)
Nov 4 16:21:15 gravy wordpress(smithclass.net)[139111]: XML-RPC authentication attempt for unknown ...
show more
Nov 4 16:21:15 gravy wordpress(smithclass.net)[139111]: XML-RPC authentication attempt for unknown user gsmithsewanee-edu from 35.237.41.106
...
show less
Hacking
Brute-Force
๐ฎ๐ฉ
Burayot
2025-11-04 16:20:32
(7 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.237.41.106 (US/United States/106 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.237.41.106 (US/United States/106.41.237.35.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ซ๐ท
applemooz
2025-11-04 16:19:22
(7 months ago)
WordPress XMLRPC Brute Force Attacks
...
Brute-Force
Web App Attack
๐จ๐ญ
Origon
2025-11-04 16:13:09
(7 months ago)
http-probing - IP: 35.237.41.106 - time="2025-11-04T17:13:09+01:00" level=info msg="(555f66b4f6a745 ...
show more
http-probing - IP: 35.237.41.106 - time="2025-11-04T17:13:09+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-probing by ip 35.237.41.106 (US/396982) : 4h ban on Ip 35.237.41.106"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-04 16:12:50
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 35.237.41.106 (106.41.237.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 35.237.41.106 (106.41.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 04 11:12:44.764640 2025] [security2:error] [pid 18234:tid 18234] [client 35.237.41.106:54643] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sliconswamp.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sliconswamp.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aQol_P3NNEEmpUj4hNAFUQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack