Anonymous
2026-06-28 05:25:47
(1 day ago)
This IP was involved in an brute force and password spray attack on 2026/06/27 20:16:52
Port Scan
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 03:31:14
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 104.245.240.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 104.245.240.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 23:31:08.964682 2026] [security2:error] [pid 16494:tid 16494] [client 104.245.240.229:24481] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||faeriefeelers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "faeriefeelers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aior_JUojCvsPdqMCaYJvAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-06-08 16:57:00
(2 weeks ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-21 22:34:49
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 104.245.240.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 104.245.240.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 18:34:42.161806 2026] [security2:error] [pid 430:tid 430] [client 104.245.240.229:64047] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.manosentuayuda.imerka.com.mx|F|2"] [data ".inc"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.manosentuayuda.imerka.com.mx"] [uri "/wp-config.inc"] [unique_id "ag-Igs6TiiPPHIh4GoNiJgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 21:41:12
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.245.240.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 104.245.240.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 17:41:07.714711 2026] [security2:error] [pid 11445:tid 11445] [client 104.245.240.229:32361] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fattoria-rendena.it"] [uri "/wp-config.php~"] [unique_id "ag4qc1hGn6sWzB00Z5-m5gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-20 03:01:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 104.245.240.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 104.245.240.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 19 23:01:04.648120 2026] [security2:error] [pid 16270:tid 16316] [client 104.245.240.229:28487] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "almerirock.com"] [uri "/wp-config.php.dist"] [unique_id "ag0j8PrK9qWv9YDAWKo_KQAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-04 08:24:33
(1 month ago)
104.245.240.229 - - [04/May/2026:16:24:33 +0800] "GET /xmlrpc.php HTTP/1.1" 405 42 "-" "Mozilla/5.0 ...
show more
104.245.240.229 - - [04/May/2026:16:24:33 +0800] "GET /xmlrpc.php HTTP/1.1" 405 42 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-24 05:07:22
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 104.245.240.229 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:225170) triggered by 104.245.240.229 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 24 01:07:15.911935 2026] [security2:error] [pid 830437:tid 830437] [client 104.245.240.229:61627] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||solucionesmercadeodigital.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "solucionesmercadeodigital.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aer6gxsCBiVPwYBNLz8-XQAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-02-03 15:28:28
(4 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 104.245.240.229 (NL/The Netherlands/-): 1 in t ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 104.245.240.229 (NL/The Netherlands/-): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ซ๐ท
masterguru
2026-02-03 15:04:53
(4 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 104.245.240.229 (NL/The Netherlands/-): 1 in t ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 104.245.240.229 (NL/The Netherlands/-): 1 in the last 3600 secs (0-193)
show less
Hacking