Anonymous
2026-08-18 10:06:55
(14 minutes ago)
Blocked by ModSec and CSF
Port Scan
πΊπΈ
TPI-Abuse
2026-08-18 09:26:54
(54 minutes ago)
(mod_security) mod_security (id:225170) triggered by 85.204.70.98 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 85.204.70.98 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 05:26:45.832642 2026] [security2:error] [pid 21061:tid 21061] [client 85.204.70.98:0] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||abdulhameeds.art|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "abdulhameeds.art"] [uri "/ar/wp-json/wp/v2/users/"] [unique_id "aoQlVTUJDk5jbjKKLumb4AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-18 08:53:02
(1 hour ago)
[Tue Aug 18 10:53:01.547234 2026] [authz_core:error] [pid 350870] [client 85.204.70.98:54820] AH0163 ...
show more
[Tue Aug 18 10:53:01.547234 2026] [authz_core:error] [pid 350870] [client 85.204.70.98:54820] AH01630: client denied by server configuration: /var/www/html/default/
[Tue Aug 18 10:53:01.567131 2026] [authz_core:error] [pid 350870] [client 85.204.70.98:54820] AH01630: client denied by server configuration: /var/www/html/default/wp-includes
[Tue Aug 18 10:53:01.587295 2026] [authz_core:error] [pid 350870] [client 85.204.70.98:54820] AH01630: client denied by server configuration: /var/www/html/default/xmlrpc.php
[Tue Aug 18 10:53:01.611002 2026] [authz_core:error] [pid 350870] [client 85.204.70.98:54820] AH01630: client denied by server configuration: /var/www/html/default/
[Tue Aug 18 10:53:01.632476 2026] [authz_core:error] [pid 350870] [client 85.204.70.98:54820] AH01630: client denied by server configuration: /var/www/html/default/blog
...
show less
Web App Attack
πΊπΈ
ipblock.com
2026-08-18 07:50:00
(2 hours ago)
IPBlock protected site ID [3192-af][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-08-18 07:33:36
(2 hours ago)
(wordpress) Failed wordpress login from 85.204.70.98 (FR/France/-)
Brute-Force
Anonymous
2026-08-18 07:30:03
(2 hours ago)
CrowdSec decision: crowdsecurity/http-probing (origin: crowdsec)
Web App Attack
Anonymous
2026-08-18 07:00:33
(3 hours ago)
85.204.70.98 - - [18/Aug/2026:09:00:31 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 402 890 " ...
show more
85.204.70.98 - - [18/Aug/2026:09:00:31 +0200] "GET //wp-includes/wlwmanifest.xml HTTP/1.1" 402 890 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" ...
show less
Web App Attack
π©πͺ
rh24
2026-08-18 06:35:39
(3 hours ago)
(wordpress) Failed wordpress login from 85.204.70.98 (FR/France/-): (CF_ENABLE)
Brute-Force
π«π·
masterguru
2026-08-18 06:13:39
(4 hours ago)
(xmlrpc) Apache: Failed xmlrpc access from 85.204.70.98 (FR/France/-): 10 in the last 3600 secs (0-2 ...
show more
(xmlrpc) Apache: Failed xmlrpc access from 85.204.70.98 (FR/France/-): 10 in the last 3600 secs (0-201)
show less
Hacking
π¨π
Mario Bretscher
2026-08-18 06:08:32
(4 hours ago)
Aug 18 08:08:29 www.beat-band.ch Cerber(www.beat-band.ch)[1346692]: Authentication failure for admin ...
show more
Aug 18 08:08:29 www.beat-band.ch Cerber(www.beat-band.ch)[1346692]: Authentication failure for admin from 85.204.70.98
Aug 18 08:08:30 www.beat-band.ch Cerber(www.beat-band.ch)[1346698]: Authentication failure for admin from 85.204.70.98
...
show less
Web Spam
π³π±
tmiland
2026-08-18 06:08:04
(4 hours ago)
(wordpress_wlwmanifest) WordPress wlwmanifest.xml Attack 85.204.70.98 (FR/France/-): 3 in the last 3 ...
show more
(wordpress_wlwmanifest) WordPress wlwmanifest.xml Attack 85.204.70.98 (FR/France/-): 3 in the last 3600 secs; IP: 85.204.70.98; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 85.204.70.98 - - [18/Aug/2026:08:08:02 +0200] "GET //xmlrpc.php?rsd HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 85.204.70.98 - - [18/Aug/2026:08:08:02 +0200] "GET //blog/wp-includes/wlwmanifest.xml HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 85.204.70.98 - - [18/Aug/2026:08:08:02 +0200] "GET //web/wp-includes/wlwmanifest.xml HTTP/1.1" 404 2992 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Brute-Force
π©πͺ
Marc
2026-08-18 06:01:57
(4 hours ago)
85.204.70.98 - - [18/Aug/2026:08:01:55 +0200] "POST //xmlrpc.php HTTP/1.1" 200 846 "-" "Mozilla/5.0 ...
show more
85.204.70.98 - - [18/Aug/2026:08:01:55 +0200] "POST //xmlrpc.php HTTP/1.1" 200 846 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 85.204.70.98 - - [18/Aug/2026:08:01:55 +0200] "POST //xmlrpc.php HTTP/1.1" 200 884 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36" 85.204.70.98 - - [18/Aug/2026:08:01:55 +0200] "POST //xmlrpc.php HTTP/1.1" 200 884 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/78.0.3904.108 Safari/537.36"
show less
Brute-Force
Web App Attack
π©πͺ
big-cloud.nl
2026-08-18 05:43:12
(4 hours ago)
Try to access /xmlrpc.php?rsd
Web App Attack
π©πͺ
DocNetzwerk
2026-08-18 05:30:01
(4 hours ago)
85.204.70.98 (FR/France/-), more than 7 Apache 403 hits
Hacking
Anonymous
2026-08-18 04:10:54
(6 hours ago)
Aggressive web scan
Bad Web Bot
Web App Attack