๐ซ๐ท
SpaceHost-Server
2026-09-17 22:24:24
(1 day ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-16 22:22:55
(2 days ago)
Brute-Force
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-15 22:21:04
(3 days ago)
Brute-Force
Web App Attack
๐ฉ๐ช
macrob
2026-09-15 22:14:09
(3 days ago)
2026/09/15 22:14:07 [error] 2447291#2447291: *2547390 access forbidden by rule, client: 64.227.169.1 ...
show more
2026/09/15 22:14:07 [error] 2447291#2447291: *2547390 access forbidden by rule, client: 64.227.169.145, server: finmi.pl, request: "GET //wp-includes/wlwmanifest.xml HTTP/2.0", host: "finmi.pl"
2026/09/15 22:14:08 [error] 2447291#2447291: *2547396 access forbidden by rule, client: 64.227.169.145, server: finmi.pl, request: "GET //xmlrpc.php?rsd HTTP/2.0", host: "finmi.pl"
2026/09/15 22:14:08 [error] 2447291#2447291: *2547384 access forbidden by rule, client: 64.227.169.145, server: finmi.pl, request: "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0", host: "finmi.pl"
...
show less
Web App Attack
๐บ๐ธ
dot.mg
2026-09-15 21:50:35
(3 days ago)
Bad behaviour
Web Spam
๐ฎ๐ฑ
Dolphi
2026-09-15 19:50:05
(3 days ago)
POST //xmlrpc.php
Brute-Force
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-15 19:43:40
(3 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possi ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after PHP/CMS/webshell exploit probe (possible exploited host). Evidence: AttackPattern: /wp-includes/ (Match: /wp-includes/)
show less
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-15 19:30:11
(3 days ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-09-15 15:38:08
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12457
Exploited Host
Web App Attack
๐ซ๐ท
spot
2026-09-15 15:17:58
(3 days ago)
64.227.169.145 - - [15/Sep/2026:16:17:56 +0100] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 200 149 ...
show more
64.227.169.145 - - [15/Sep/2026:16:17:56 +0100] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 200 1497 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
...
show less
Web App Attack
Hacking
๐บ๐ธ
kosada.com
2026-09-15 12:22:56
(3 days ago)
Repeated requests for suspicious nonexistent URLs, for example: /wordpress/wp-includes/wlwmanifest.x ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /wordpress/wp-includes/wlwmanifest.xml (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 12:19:11
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 64.227.169.145 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 64.227.169.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 08:19:08.032247 2026] [security2:error] [pid 18664:tid 18668] [client 64.227.169.145:55242] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.lancasterdesignercraftsmen.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.lancasterdesignercraftsmen.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqk3vBkr6dnHCWRjGZWUpAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 11:54:17
(3 days ago)
(mod_security) mod_security (id:225170) triggered by 64.227.169.145 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 64.227.169.145 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:54:11.450007 2026] [security2:error] [pid 4402:tid 4402] [client 64.227.169.145:49581] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||parastesh.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "parastesh.org"] [uri "/wp-json/wp/v2/users/"] [unique_id "aqkx48v4b4Lj0YBo7MqhDgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Tripwire
2026-09-15 11:11:51
(3 days ago)
Scanning for exploits - //wp-includes/wlwmanifest.xml
Web App Attack
๐บ๐ธ
brightenfield
2026-09-15 11:06:08
(3 days ago)
Web App Attack
Web App Attack