๐บ๐ธ
TPI-Abuse
2026-08-25 12:37:18
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 35.239.136.146 (146.136.239.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 35.239.136.146 (146.136.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:37:10.783400 2026] [security2:error] [pid 12884:tid 12898] [client 35.239.136.146:53418] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||nabsci.aafm.us|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "nabsci.aafm.us"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao2Mdt-SnhndUbkDa9k7BwAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 12:21:10
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 35.239.136.146 (146.136.239.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:225170) triggered by 35.239.136.146 (146.136.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 08:21:01.722725 2026] [security2:error] [pid 24144:tid 24144] [client 35.239.136.146:64476] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||museum.henning.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "museum.henning.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "ao2Irfb79aI9iaTdKiV7VAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-08-25 12:20:15
(3 days ago)
35.239.136.146 - - [25/Aug/2026:15:20:06 +0300] "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0" 30 ...
show more
35.239.136.146 - - [25/Aug/2026:15:20:06 +0300] "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.239.136.146 - - [25/Aug/2026:15:20:07 +0300] "GET //web/wp-includes/wlwmanifest.xml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.239.136.146 - - [25/Aug/2026:15:20:08 +0300] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.239.136.146 - - [25/Aug/2026:15:20:09 +0300] "GET //wp/wp-includes/wlwmanifest.xml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.239.136.146 - - [25/Aug/2026:15:20:10 +0300] "GET //2020/wp-includes/wlwmanifest.xml HTTP/2.0"
...
show less
Web App Attack
Anonymous
2026-08-25 12:05:56
(3 days ago)
POST /xmlrpc.php HTTP/1.1
...
Brute-Force
๐ณ๐ฑ
BlueWire Hosting
2026-08-25 12:02:12
(3 days ago)
Probing websites for vulnerabilities
Web App Attack
๐ซ๐ท
Zundapper
2026-08-25 11:58:39
(3 days ago)
35.239.136.146 - - [25/Aug/2026:13:58:37 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 ...
show more
35.239.136.146 - - [25/Aug/2026:13:58:37 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.239.136.146 - - [25/Aug/2026:13:58:37 +0200] "GET //feed/ HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.239.136.146 - - [25/Aug/2026:13:58:38 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.239.136.146 - - [25/Aug/2026:13:58:38 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.239.136.146 - - [25/Aug/2026:13:58:38 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5
...
show less
Web App Attack
Port Scan
๐บ๐ธ
WeekendWeb
2026-08-25 11:55:48
(3 days ago)
Wordpress Vunerability attack
Web App Attack
Anonymous
2026-08-25 11:55:22
(3 days ago)
PAD: Scan_Well_Known!,No_Ref,Scan_404 detected
Bad Web Bot
๐ฎ๐ฑ
Dolphi
2026-08-25 11:50:02
(3 days ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-25 11:49:37
(3 days ago)
10 attempts against mh-misc-ban on frost
Web App Attack
๐ฉ๐ช
stinpriza
2026-08-25 11:33:14
(3 days ago)
common Web Exploits being scanned
Web App Attack
๐ฉ๐ช
IVski.com
2026-08-25 11:28:40
(3 days ago)
IVski WAF | Sensitive file probe - looking for WordPress license.txt
Hacking
Brute-Force
Web App Attack
๐ท๐บ
DZBOT
2026-08-25 11:26:47
(3 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฎ๐น
VHosting
2026-08-25 11:25:05
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-25 11:20:49
(3 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack