๐บ๐ธ
CounterScrape
2026-07-03 04:01:35
(6 hours ago)
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapp ...
show more
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapped in honeypot. Concurrency hits: 2. Bandwidth drained: 0.18 MB.
show less
Bad Web Bot
Port Scan
๐บ๐ธ
CounterScrape
2026-07-02 04:01:05
(1 day ago)
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapp ...
show more
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapped in honeypot. Concurrency hits: 2. Bandwidth drained: 0.18 MB.
show less
Bad Web Bot
Port Scan
๐บ๐ธ
CounterScrape
2026-07-01 03:03:18
(2 days ago)
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapp ...
show more
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapped in honeypot. Concurrency hits: 2. Bandwidth drained: 0.18 MB.
show less
Bad Web Bot
Port Scan
๐บ๐ธ
CounterScrape
2026-06-30 03:00:36
(3 days ago)
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapp ...
show more
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapped in honeypot. Concurrency hits: 2. Bandwidth drained: 0.18 MB.
show less
Bad Web Bot
Port Scan
๐บ๐ธ
CounterScrape
2026-06-29 02:00:49
(4 days ago)
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapp ...
show more
CounterScrape Deception: Bot identified as EXPLOIT_SCANNER (Vulnerability / Exploit Scanning). Trapped in honeypot. Concurrency hits: 2. Bandwidth drained: 0.18 MB.
show less
Bad Web Bot
Port Scan
๐ง๐ท
ICS Labs
2026-06-23 19:52:11
(1 week ago)
ICS Labs identified 79.127.129.214 as a malicious indicator from threat intelligence.
DDoS Attack
Port Scan
Hacking
Brute-Force
Exploited Host
๐ฉ๐ช
updown.io
2026-06-13 08:05:23
(2 weeks ago)
{"level":"info","ts":1781337769.3590956,"logger":"http.log.access.log0","msg":"handled request","req ...
show more
{"level":"info","ts":1781337769.3590956,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"79.127.129.214","remote_port":"65442","client_ip":"79.127.129.214","proto":"HTTP/1.1","method":"GET","host":"13h0.status.updown.io","uri":"/","headers":{"Keep-Alive":["300"],"Connection":["keep-alive"],"User-Agent":["Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"],"Accept-Language":["en-US,en;q=0.5"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8"]}},"bytes_read":0,"user_id":"","duration":0.000048302,"size":0,"status":308,"resp_headers":{"Content-Type":[],"Server":["Caddy"],"Connection":["close"],"Location":["https://13h0.status.updown.io/"]}}
{"level":"info","ts":1781337769.9719725,"logger":"http.log.access.log0","msg":"handled request","request":{"remote_ip":"79.127.129.214","remote_port":"65490","client_ip":"79.127.129.214","proto":"HTTP/1.1","method":"GET","host":"13h
...
show less
DDoS Attack
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-06-10 09:08:25
(3 weeks ago)
(Kingcopy.org-AI-IDS-Report):IP automatically blocked after suspicious activity. Vegas Security
DDoS Attack
Hacking
Exploited Host
Anonymous
2026-06-10 08:42:24
(3 weeks ago)
79.127.129.214 - - [10/Jun/2026:10:41:52 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 ...
show more
79.127.129.214 - - [10/Jun/2026:10:41:52 +0200] "GET /wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
79.127.129.214 - - [10/Jun/2026:10:42:06 +0200] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
79.127.129.214 - - [10/Jun/2026:10:42:15 +0200] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
79.127.129.214 - - [10/Jun/2026:10:42:18 +0200] "GET /wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 567 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
79.127.129.214 - - [10/Jun/2026:10:42:23 +0200] "GET /website/wp-includes/wlwmanifest.xml HTT
...
show less
Brute-Force
Web App Attack
๐ซ๐ท
bazter.pro
2026-06-07 05:04:20
(3 weeks ago)
Auto-Ban [2026-06-07 08:04:20]: CRITICAL: Exploit trap paths (17); DC: Datacamp Limited [Paths: 17] ...
show more
Auto-Ban [2026-06-07 08:04:20]: CRITICAL: Exploit trap paths (17); DC: Datacamp Limited [Paths: 17] | Details: Exploit trap paths: //wp-includes/wlwmanifest.xml, //xmlrpc.php?rsd, //blog/wp-includes/wlwmanifest.xml, //web/wp-includes/wlwmanifest.xml, //wordpress/wp-includes/wlwmanifest.xml | Sensitive files/paths: //xmlrpc.php?rsd | 404 errors (16): //xmlrpc.php?rsd, //wp2/wp-includes/wlwmanifest.xml, //cms/wp-includes/wlwmanifest.xml, //web/wp-includes/wlwmanifest.xml, //news/wp-includes/wlwmanifest.xml, //2020/wp-includes/wlwmanifest.xml, //2019/wp-includes/wlwmanifest.xml, //test/wp-includes/wlwmanifest.xml, //wp-includes/wlwmanifest.xml, //wordpress/wp-includes/wlwmanifest.xml (and 6 more) | Other paths: //blog/wp-includes/wlwmanifest.xml
show less
Web App Attack
Hacking
๐ซ๐ท
ELYAZ
2026-06-07 04:51:22
(3 weeks ago)
(y3) Failed access -byebye- from 79.127.129.214 (JP/Japan/unn-79-127-129-214.datapacket.com): (CF_E ...
show more
(y3) Failed access -byebye- from 79.127.129.214 (JP/Japan/unn-79-127-129-214.datapacket.com): (CF_ENABLE)
show less
Hacking
Anonymous
2026-06-03 06:07:31
(1 month ago)
IP banned by Fail2Ban due to multiple malicious requests on Nginx
Brute-Force
SSH
Web App Attack
Anonymous
2026-06-01 21:58:41
(1 month ago)
IP banned by Fail2Ban due to multiple malicious requests on Nginx
Brute-Force
SSH
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-01 19:26:39
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 79.127.129.214 (unn-79-127-129-214.datapacket.c ...
show more
(mod_security) mod_security (id:225170) triggered by 79.127.129.214 (unn-79-127-129-214.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 01 15:26:32.991132 2026] [security2:error] [pid 26104:tid 26104] [client 79.127.129.214:50448] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||cynosurephotography.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cynosurephotography.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "ah3c6P9g5Fnjg9aMXeFJUwAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-06-01 17:21:37
(1 month ago)
Web scanning / probing for vulnerable paths | URL: //site/wp-includes/wlwmanifest.xml | Evidence: mi ...
show more
Web scanning / probing for vulnerable paths | URL: //site/wp-includes/wlwmanifest.xml | Evidence: microsites.grupoeuropa.com 79.127.129.214 - - [01/Jun/2026:19:19:17 +0200] \"GET //site/wp-includes/wlwmanifest.xml HTTP/1.1\" 404 12541 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/88.0.4240.193 Safari/537.36\" GEOIP_COUNTRY_CODE=JP | ASN: Datacamp Limited | Country: JP
show less
Port Scan
Web App Attack