๐ง๐ช
cmbplf
2026-10-08 10:40:56
(1 day ago)
24.037 requests with url.path */xmlrpc.php
23.945 requests with url.path //xmlrpc.php
Brute-Force
Bad Web Bot
๐บ๐ธ
mnsf
2026-10-08 10:05:18
(1 day ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
๐ณ๐ด
jad-abuse
2026-10-08 09:09:00
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. O ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: xmlrpc. Observed by 1 sensor(s); 16 hits.
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-08 09:07:57
(1 day ago)
Repeated wp-login/xmlrpc attempts
Brute-Force
SSH
๐ณ๐ฑ
Savvii
2026-10-08 09:04:08
(1 day ago)
10 attempts against mh-misc-ban on eris
Web App Attack
๐ธ๐ฌ
anotherwatcher
2026-10-08 08:58:34
(1 day ago)
bad bot
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-08 08:52:30
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 8.235.126.228 (228.126.235.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:225170) triggered by 8.235.126.228 (228.126.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 04:52:26.581299 2026] [security2:error] [pid 8519:tid 8519] [client 8.235.126.228:59643] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theseventhcongregationofladderdayvixens.org.tortoisehosting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theseventhcongregationofladderdayvixens.org.tortoisehosting.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "asdZyqtYtPXep_d3l2_erwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-08 08:50:48
(1 day ago)
WordPress attack-tool calls | method: POST | path: //xmlrpc.php | ua: Mozilla/5.0 (Windows NT 10.0; ...
show more
WordPress attack-tool calls | method: POST | path: //xmlrpc.php | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36
show less
Web App Attack
Hacking
๐ฉ๐ช
ghostwarriors
2026-10-08 08:50:07
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-08 08:39:15
(1 day ago)
10 attempts against mh-misc-ban on frost
Web App Attack
๐ณ๐ฑ
thedreamer.nl
2026-10-08 08:35:57
(1 day ago)
8.235.126.228 - - [08/Oct/2026:10:33:34 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 ...
show more
8.235.126.228 - - [08/Oct/2026:10:33:34 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "The Dalles" "45.59990" "-121.18710"
8.235.126.228 - - [08/Oct/2026:10:33:35 +0200] "GET //feed/ HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "The Dalles" "45.59990" "-121.18710"
8.235.126.228 - - [08/Oct/2026:10:33:35 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 27 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "The Dalles" "45.59990" "-121.18710"
8.235.126.228 - - [08/Oct/2026:10:33:35 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" "US" "The Dalles" "45
...
show less
Brute-Force
Bad Web Bot
๐ฉ๐ช
thesimonmanuel
2026-10-08 08:35:07
(1 day ago)
8.235.126.228 - - [08/Oct/2026:14:05:06 +0530] "GET //wp-includes/ID3/license.txt HTTP/1.1" 200 1396 ...
show more
8.235.126.228 - - [08/Oct/2026:14:05:06 +0530] "GET //wp-includes/ID3/license.txt HTTP/1.1" 200 1396 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
show less
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-08 08:34:34
(1 day ago)
8.235.126.228 - - [08/Oct/2026:10:34:28 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 ...
show more
8.235.126.228 - - [08/Oct/2026:10:34:28 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
8.235.126.228 - - [08/Oct/2026:10:34:28 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
8.235.126.228 - - [08/Oct/2026:10:34:29 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
8.235.126.228 - - [08/Oct/2026:10:34:29 +0200] "GET //wp/wp-includes/wlwmanifest.xml HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
8.235.126.228 - - [08/Oct/2026:10:34:29 +0200] "GET //2020/wp-includes/wlwmanifest.xml HTTP/1.
show less
Web App Attack
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-08 08:33:53
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
kosada.com
2026-10-08 08:28:20
(1 day ago)
Repeated requests for suspicious nonexistent URLs, for example: /[redacted]/wordpress/wp-includes/wl ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /[redacted]/wordpress/wp-includes/wlwmanifest.xml (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36")
show less
Web App Attack