๐บ๐ธ
EvilTurkey
2026-07-29 12:13:32
(1 day ago)
Web app attack against financial institution website.
Web App Attack
Hacking
๐ง๐ช
cmbplf
2026-07-29 10:33:50
(1 day ago)
6.695 requests with url.path //xmlrpc.php
1.301 requests with url.path */wp-includes/wlwmanifest.x ...
show more
6.695 requests with url.path //xmlrpc.php
1.301 requests with url.path */wp-includes/wlwmanifest.xml
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
mnsf
2026-07-29 08:07:25
(1 day ago)
Abuse Detected (13)
Brute-Force
Web App Attack
๐ซ๐ท
breubit
2026-07-29 07:53:10
(1 day ago)
35.255.21.38 - - [29/Jul/2026:09:53:10 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 302 984 " ...
show more
35.255.21.38 - - [29/Jul/2026:09:53:10 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 302 984 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
...
show less
Web App Attack
๐ฉ๐ช
Blexyel
2026-07-29 07:50:44
(1 day ago)
35.255.21.38 - - [29/Jul/2026:09:50:44 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 167 " ...
show more
35.255.21.38 - - [29/Jul/2026:09:50:44 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 404 167 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/89.0.4389.114 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-07-29 07:50:14
(1 day ago)
Automated Apache suspicious-path probe detected in last 1m: hits=1; wp-login_hits=0; uniq_paths=1
Web App Attack
๐ฉ๐ช
mondor.ro
2026-07-29 07:42:08
(1 day ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 35.255.21.38, Reason:[ ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 35.255.21.38, Reason:[(manifest) WordPress wlwmanifest.xml Attack 35.255.21.38 (US/United States/38.21.255.35.bc.googleusercontent.com): 10 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-29 07:39:25
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 35.255.21.38 (38.21.255.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 35.255.21.38 (38.21.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 03:39:18.173009 2026] [security2:error] [pid 8620:tid 8620] [client 35.255.21.38:65442] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ashleycroft.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ashleycroft.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ammuJpGwyD1GFgA7KbFw4AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
beon
2026-07-29 07:30:49
(1 day ago)
[DateTime=>2026-07-29T07:30:49Z to 2026-07-29T07:30:55Z (UTC)] , [HoneyPot_Hits=>4 times] , [HoneyPo ...
show more
[DateTime=>2026-07-29T07:30:49Z to 2026-07-29T07:30:55Z (UTC)] , [HoneyPot_Hits=>4 times] , [HoneyPots=>/wp-includes/wlwmanifest.xml, /wp-json/wp/v2/users/, /wp-json/oembed/1.0/embed, /xmlrpc.php] , [total_Hits=>5 times] , [Keyword=>WordPress]
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-07-29 07:29:03
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
Trashware
2026-07-29 07:28:23
(1 day ago)
Vulnerability scan
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-29 07:25:05
(1 day ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 07:24:04
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 35.255.21.38 (38.21.255.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 35.255.21.38 (38.21.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 03:23:58.957421 2026] [security2:error] [pid 2663900:tid 2663900] [client 35.255.21.38:64471] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ardath.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ardath.net"] [uri "/wp-json/wp/v2/users/"] [unique_id "ammqjgU6XybMe7c-pxwIJgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-07-29 07:22:22
(1 day ago)
URL Probing: /wp/wp-includes/wlwmanifest.xml
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-29 07:21:13
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack