🇺🇸
ArturShelby
2026-09-07 21:45:55
(1 hour ago)
Suspicious path access: //wp-includes/ID3/license.txt
Web App Attack
Anonymous
2026-09-07 21:00:03
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /wp-login.php HTTP/1.1, GET /readme.html HTTP/1.1, GET / ...
show more
Bot / scanning and/or hacking attempts: GET /wp-login.php HTTP/1.1, GET /readme.html HTTP/1.1, GET /nl/assortiment HTTP/1.1, GET /wp-json/ HTTP/1.1
show less
Hacking
Web App Attack
🇫🇷
david.houstin
2026-09-07 20:59:37
(2 hours ago)
82.197.69.56 - - [07/Sep/2026:22:59:16 +0200] "GET /mandarin/dictionnaire/wp-login.php HTTP/1.1" 404 ...
show more
82.197.69.56 - - [07/Sep/2026:22:59:16 +0200] "GET /mandarin/dictionnaire/wp-login.php HTTP/1.1" 404 8477 "-" "Mozilla/5.0" 16581 -
82.197.69.56 - - [07/Sep/2026:22:59:35 +0200] "GET /wp-login.php HTTP/1.1" 404 8477 "-" "Mozilla/5.0 WP-Async-Scanner" 27269 -
82.197.69.56 - - [07/Sep/2026:22:59:35 +0200] "GET /wp-login.php HTTP/1.1" 404 8477 "-" "Mozilla/5.0 WP-Async-Scanner" 27269 -
82.197.69.56 - - [07/Sep/2026:22:59:35 +0200] "GET /wp-json/ HTTP/1.1" 404 8477 "-" "Mozilla/5.0 WP-Async-Scanner" 24693 -
82.197.69.56 - - [07/Sep/2026:22:59:35 +0200] "GET /wp-json/ HTTP/1.1" 404 8477 "-" "Mozilla/5.0 WP-Async-Scanner" 24693 -
...
show less
Web App Attack
Bad Web Bot
🇫🇷
Stara
2026-09-07 20:55:08
(2 hours ago)
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kinesk ...
show more
Automated block - Joomla/WordPress/OpenCart vulnerability scanner exploitation detected (Mala Kineskinja)
show less
Hacking
Brute-Force
Web App Attack
🇧🇪
voormedia
2026-09-07 20:34:24
(2 hours ago)
Accessed trap at '/wp-login.php'
Web App Attack
🇨🇭
lufi
2026-09-07 19:49:35
(3 hours ago)
2026-09-07 21:49:34 82.197.69.56: blacklisted Pattern: wp-includes/
...
Web Spam
Brute-Force
Hacking
Web App Attack
Anonymous
2026-09-07 18:19:11
(4 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-07 17:51:43
(5 hours ago)
XSS Attempt
Hacking
🇷🇴
clauss
2026-09-07 17:25:10
(5 hours ago)
82.197.69.56 - - [07/Sep/2026:20:25:10 +0300] "GET /de_citit/recomandari/.vscode/ftp-kr.json HTTP/2. ...
show more
82.197.69.56 - - [07/Sep/2026:20:25:10 +0300] "GET /de_citit/recomandari/.vscode/ftp-kr.json HTTP/2.0" 403 146 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
82.197.69.56 - - [07/Sep/2026:20:25:10 +0300] "GET /de_citit/recomandari/.vscode/sftp.json HTTP/2.0" 403 146 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Web App Attack
🇳🇱
Eric
2026-09-07 16:31:33
(6 hours ago)
[Mon Sep 07 16:31:26.805953 2026] [security2:error] [pid 2362814:tid 2362814] [client 82.197.69.56:0 ...
show more
[Mon Sep 07 16:31:26.805953 2026] [security2:error] [pid 2362814:tid 2362814] [client 82.197.69.56:0] [client 82.197.69.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/free-chips/pop-slots/sftp-config.json"] [unique_id "ap7m3peOhNR3UHLqikvDjAAAABc"]
[Mon Sep 07 16:31:31.996540 2026] [security2:error] [pid 2358422:tid 2358422] [client 82.197.69.56:0] [client 82.197.69.56] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceede
...
show less
Hacking
Web App Attack
🇨🇭
zynex
2026-09-07 16:29:31
(6 hours ago)
URL Probing: /xmlrpc.php
Web App Attack
🇫🇷
david.houstin
2026-09-07 15:32:54
(7 hours ago)
82.197.69.56 - - [07/Sep/2026:17:32:40 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 40054 ...
show more
82.197.69.56 - - [07/Sep/2026:17:32:40 +0200] "GET //wp-includes/ID3/license.txt HTTP/1.1" 404 40054 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 63036 -
82.197.69.56 - - [07/Sep/2026:17:32:45 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 4533 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 13594 -
82.197.69.56 - - [07/Sep/2026:17:32:45 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 4533 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 38931 -
82.197.69.56 - - [07/Sep/2026:17:32:45 +0200] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/1.1" 404 4533 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36" 13977 -
82.197.69.56 - - [07/Sep/2026:17:32:46 +0200] "GET //wp/wp-inclu
...
show less
Web App Attack
Bad Web Bot
🇪🇸
pipeline.es
2026-09-07 12:42:35
(10 hours ago)
Web scanning / probing for vulnerable paths | URL: /wp-content/plugins/molongui-authorship/readme.tx ...
show more
Web scanning / probing for vulnerable paths | URL: /wp-content/plugins/molongui-authorship/readme.txt | Evidence: 82.197.69.56 - - [07/Sep/2026:14:40:41 +0200] \"GET /wp-content/plugins/molongui-authorship/readme.txt HTTP/1.1\" 404 196 \"-\" \"Mozilla/5.0 WP-Async-Scanner\" GEOIP_COUNTRY_CODE=SG | ASN: Contabo Asia Private Limited | Country: SG
show less
Port Scan
Web App Attack
🇷🇴
clauss
2026-09-07 12:16:18
(10 hours ago)
82.197.69.56 - - [07/Sep/2026:15:16:08 +0300] "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0" 301 ...
show more
82.197.69.56 - - [07/Sep/2026:15:16:08 +0300] "GET //blog/wp-includes/wlwmanifest.xml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
82.197.69.56 - - [07/Sep/2026:15:16:09 +0300] "GET //web/wp-includes/wlwmanifest.xml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
82.197.69.56 - - [07/Sep/2026:15:16:10 +0300] "GET //wordpress/wp-includes/wlwmanifest.xml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
82.197.69.56 - - [07/Sep/2026:15:16:12 +0300] "GET //wp/wp-includes/wlwmanifest.xml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/95.0.4638.69 Safari/537.36"
82.197.69.56 - - [07/Sep/2026:15:16:13 +0300] "GET //2020/wp-includes/wlwmanifest.xml HTTP/2.0" 301 0 "-"
...
show less
Web App Attack
🇩🇪
SCHAPPY
2026-09-07 12:13:55
(10 hours ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack