|
Anonymous
|
|
"Packet Flood; Triggered WAF; Persistent 404 Attempts"
|
DDoS Attack
|
|
|
๐บ๐ธ
ipblock.com
|
|
IPBlock protected site ID [669-fx].
Exploit request, vulnerability scanner.
|
Hacking
Bad Web Bot
Web App Attack
|
|
|
๐ง๐ช
voormedia
|
|
Accessed trap at '/xmlrpc.php'
|
Web App Attack
|
|
|
๐ฉ๐ช
Tsumugi Kotobuki
|
|
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 109 | Len: 52B | Win: ...
show more
Port Scan on Honeypot | Ports: 80/HTTP | Proto: TCP(1) | Flags: all SYN | TTL: 109 | Len: 52B | Win: 64240(1) | F2B/ufw-honeypot@2026-07-15T11:16:01Z
show less
|
Port Scan
Hacking
|
|
|
Anonymous
|
|
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
|
Exploited Host
|
|
|
๐ญ๐บ
kranem
|
|
Triggered Cloudflare WAF from ID.
Action taken: BLOCK
ASN: 45102 (Alibaba (US) Technology Co., Ltd.) ...
show more
Triggered Cloudflare WAF from ID.
Action taken: BLOCK
ASN: 45102 (Alibaba (US) Technology Co., Ltd.)
Protocol: HTTP/1.1 (GET method)
Endpoint: /2020/wp-includes/wlwmanifest.xml
Timestamp: 2026-07-15T07:27:29Z
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
show less
|
Bad Web Bot
|
|
|
๐ฉ๐ช
london2038.com
|
|
Malformed or malicious web request
8.215.61.37 - - [15/Jul/2026:10:33:40 +0200] "" 400 0 "-" "-"
|
Hacking
Web App Attack
|
|
|
Anonymous
|
|
XSS Attempt
|
Hacking
|
|
|
๐ฎ๐ณ
evicky2002
|
|
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
|
Hacking
Brute-Force
SSH
|
|
|
๐บ๐ฆ
URAN Publishing Service
|
|
8.215.61.37 - - [15/Jul/2026:08:39:08 +0300] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 683 "-" ...
show more
8.215.61.37 - - [15/Jul/2026:08:39:08 +0300] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 683 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
8.215.61.37 - - [15/Jul/2026:08:39:09 +0300] "GET /xmlrpc.php?rsd HTTP/1.1" 404 683 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
...
show less
|
Web App Attack
|
|
|
๐ซ๐ท
LRNP
|
|
_:80 8.215.61.37 - - [15/Jul/2026:04:21:58 +0000] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 54 ...
show more
_:80 8.215.61.37 - - [15/Jul/2026:04:21:58 +0000] "GET /wp-includes/ID3/license.txt HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
_:80 8.215.61.37 - - [15/Jul/2026:04:21:59 +0000] "GET /feed/ HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
_:80 8.215.61.37 - - [15/Jul/2026:04:22:00 +0000] "GET /xmlrpc.php?rsd HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
_:80 8.215.61.37 - - [15/Jul/2026:04:22:01 +0000] "GET /blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
_:80 8.215.61.37 - - [15/Jul/2026:04:22:02 +0000] "GET /web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.
...
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐ฒ๐ฝ
octageeks.com
|
|
Wordpress malicious attack:[octamissingdomain]
|
Web App Attack
|
|
|
๐ฉ๐ช
AetherFox
|
|
AetherFox VoidGuard detected: [Tue Jul 14 19:03:50.554506 2026] [authz_core:error] [pid 903351:tid 9 ...
show more
AetherFox VoidGuard detected: [Tue Jul 14 19:03:50.554506 2026] [authz_core:error] [pid 903351:tid 903400] [client 8.215.61.37:64302] AH01630: client denied by server configuration: proxy:http://[MASKED]/
[Tue Jul 14 19:03:50.554711 2026] [authz_core:error] [pid 903351:tid 903400] [client 8.215.61.37:64302] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Tue Jul 14 19:03:50.734571 2026] [authz_core:error] [pid 903351:tid 903403] [client 8.215.61.37:64302] AH01630: client denied by server configuration: proxy:http://[MASKED]/wp-includes/ID3/license.txt
[Tue Jul 14 19:03:50.734775 2026] [authz_core:error] [pid 903351:tid 903403] [client 8.215.61.37:64302] AH01630: client denied by server configuration: /var/www/html/ERRORpages/403.html
[Tue Jul 14 19:03:50.915355 2026] [authz_core:error] [pid 903351:tid 903394] [client 8.215.61.37:64302] AH01630: client denied by server configuration: proxy:http://[MASKED]/feed/
...
show less
|
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
london2038.com
|
|
Malformed or malicious web request
8.215.61.37 - - [14/Jul/2026:18:55:12 +0200] "" 400 0 "-" "-"
|
Hacking
Web App Attack
|
|
|
๐บ๐ธ
H24
|
|
/cms/wp-includes/wlwmanifest.xml /wp1/wp-includes/wlwmanifest.xml /site/wp-includes/wlwmanifest.xml ...
show more
/cms/wp-includes/wlwmanifest.xml /wp1/wp-includes/wlwmanifest.xml /site/wp-includes/wlwmanifest.xml /2019/wp-includes/wlwmanifest.xml /test/wp-includes/wlwmanifest.xml /2021/wp-includes/wlwmanifest.xml /shop/wp-includes/wlwmanifest.xml /wordpress/wp-includes/wlwmanifest.xml /2020/wp-includes/wlwmanifest.xml /wp/wp-includes/wlwmanifest.xml
show less
|
Web App Attack
|
|