๐ง๐ช
cmbplf
2026-08-10 14:50:19
(1 month ago)
1.614 requests with url.path */wp-includes/wlwmanifest.xml
Brute-Force
Bad Web Bot
๐ซ๐ท
bazter.pro
2026-08-10 14:06:00
(1 month ago)
Auto-Ban [2026-08-10 17:05:59]: CRITICAL: Exploit trap paths (14); DC: Google LLC [Paths: 16] | Deta ...
show more
Auto-Ban [2026-08-10 17:05:59]: CRITICAL: Exploit trap paths (14); DC: Google LLC [Paths: 16] | Details: Exploit trap paths: /wp-includes/ID3/license.txt, /xmlrpc.php?rsd, /blog/wp-includes/wlwmanifest.xml, /web/wp-includes/wlwmanifest.xml, /wordpress/wp-includes/wlwmanifest.xml | Sensitive files/paths: /xmlrpc.php?rsd | 404 errors (16): /wordpress/wp-includes/wlwmanifest.xml, /wp1/wp-includes/wlwmanifest.xml, /wp-includes/ID3/license.txt, /shop/wp-includes/wlwmanifest.xml, /web/wp-includes/wlwmanifest.xml, /cms/wp-includes/wlwmanifest.xml, /test/wp-includes/wlwmanifest.xml, /site/wp-includes/wlwmanifest.xml, /xmlrpc.php?rsd, /feed/ (and 6 more)
show less
Web App Attack
Hacking
๐ณ๐ฟ
Antinson
2026-08-10 13:18:36
(1 month ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐จ๐ญ
ca
2026-08-10 13:04:49
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ญ๐บ
wickedip
2026-08-10 13:03:00
(1 month ago)
Multiple WAF violations. (Bruteforce /xmlrpc.php attack.)
Brute-Force
Exploited Host
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-08-10 12:47:49
(1 month ago)
10 attempts against mh-misc-ban on pyrus
Web App Attack
๐บ๐ธ
fazar
2026-08-10 12:44:28
(1 month ago)
crowdsecurity/http-probing on node: us01
Web App Attack
Hacking
Anonymous
2026-08-10 12:44:10
(1 month ago)
35.252.139.123 - - [10/Aug/2026:14:44:10 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 441 ...
show more
35.252.139.123 - - [10/Aug/2026:14:44:10 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.252.139.123 - - [10/Aug/2026:14:44:10 +0200] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.252.139.123 - - [10/Aug/2026:14:44:10 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.252.139.123 - - [10/Aug/2026:14:44:10 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 280 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.252.139.123 - - [10/Aug/2026:14:44:10 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 441 "-
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-10 12:43:50
(1 month ago)
(wordpress) Failed wordpress login from 35.252.139.123 (US/United States/Oregon/The Dalles/123.139.2 ...
show more
(wordpress) Failed wordpress login from 35.252.139.123 (US/United States/Oregon/The Dalles/123.139.252.35.bc.googleusercontent.com)
show less
Brute-Force
๐ฉ๐ช
big-cloud.nl
2026-08-10 12:43:33
(1 month ago)
Try to access /xmlrpc.php?rsd
Web App Attack
๐ฉ๐ช
enjoyably
2026-08-10 12:40:52
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฟ
Tripwire
2026-08-10 12:36:12
(1 month ago)
Scanning for exploits - //wp-includes/ID3/license.txt
Web App Attack
๐ฉ๐ช
Marc
2026-08-10 12:36:08
(1 month ago)
35.252.139.123 - - [10/Aug/2026:14:36:04 +0200] "POST //xmlrpc.php HTTP/1.1" 200 1029 "-" "Mozilla/5 ...
show more
35.252.139.123 - - [10/Aug/2026:14:36:04 +0200] "POST //xmlrpc.php HTTP/1.1" 200 1029 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 35.252.139.123 - - [10/Aug/2026:14:36:05 +0200] "POST //xmlrpc.php HTTP/1.1" 200 4802 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 35.252.139.123 - - [10/Aug/2026:14:36:06 +0200] "POST //xmlrpc.php HTTP/1.1" 200 4802 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-08-10 12:35:04
(1 month ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฉ๐ช
lolyay
2026-08-10 12:33:07
(1 month ago)
35.252.139.123 - - [10/Aug/2026:12:33:07 +0000] "GET /wp-includes/ID3/license.txt HTTP/1.1" 200 4 "- ...
show more
35.252.139.123 - - [10/Aug/2026:12:33:07 +0000] "GET /wp-includes/ID3/license.txt HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
35.252.139.123 - - [10/Aug/2026:12:33:07 +0000] "GET /xmlrpc.php?rsd HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot