๐ซ๐ท
DUBREUIL
2026-07-14 13:12:00
(1 week ago)
wp-admin.php And many attacks
DDoS Attack
Open Proxy
Port Scan
Brute-Force
Web App Attack
SSH
Hacking
SQL Injection
Anonymous
2026-07-11 10:15:54
(1 week ago)
"GET /wp-content/plugins/fix/up.php HTTP/1.1"
Hacking
Web App Attack
Anonymous
2026-07-10 21:47:28
(1 week ago)
45.13.191.106 - - [10/Jul/2026:23:47:27 +0200] "GET /wp-content/plugins/SecurityFin/SecurityFin.php ...
show more
45.13.191.106 - - [10/Jul/2026:23:47:27 +0200] "GET /wp-content/plugins/SecurityFin/SecurityFin.php HTTP/1.1" 404 444 "-" "Go-http-client/1.1"
45.13.191.106 - - [10/Jul/2026:23:47:27 +0200] "GET /wp-content/plugins/SecurityFin/SecurityFin.php HTTP/1.1" 404 248 "-" "Go-http-client/1.1"
45.13.191.106 - - [10/Jul/2026:23:47:27 +0200] "GET /wp-content/plugins/file-upload-types/assets/css/403x.php HTTP/1.1" 404 444 "-" "Go-http-client/1.1"
45.13.191.106 - - [10/Jul/2026:23:47:27 +0200] "GET /wp-content/plugins/file-upload-types/assets/css/403x.php HTTP/1.1" 404 248 "-" "Go-http-client/1.1"
45.13.191.106 - - [10/Jul/2026:23:47:28 +0200] "GET /wp-content/plugins/penci-bookmark-follow/inc/admin/forms/penci-bf-users-logs-profile.php HTTP/1.1" 404 444 "-" "Go-http-client/1.1"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-05-12 03:05:17
(2 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-05-11 02:05:12
(2 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ซ๐ท
Octopuce
2026-05-04 10:36:51
(2 months ago)
Aggressive web search of vulnerable pages: /.well-known/dropdown.php /wp-includes/js/index.php /wp-a ...
show more
Aggressive web search of vulnerable pages: /.well-known/dropdown.php /wp-includes/js/index.php /wp-admin/maint/about.php /wp-admin/maint/index. ...
show less
Web App Attack
๐ซ๐ท
ISPLtd
2026-04-28 08:56:08
(2 months ago)
Apr 28 05:56:05 45.13.191.106 TCP SPT=49277 DPT=8080 SYN
Apr 28 05:56:06 45.13.191.106 TCP SPT=49277 ...
show more
Apr 28 05:56:05 45.13.191.106 TCP SPT=49277 DPT=8080 SYN
Apr 28 05:56:06 45.13.191.106 TCP SPT=49277 DPT=8080 SYN
Apr 28 05:56:08 45.13.191.106 TCP SPT=49277 DPT=8080
...
show less
Port Scan
๐ฆ๐บ
MAGIC
2026-04-15 02:00:53
(3 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
myagent.site
2026-04-04 20:17:33
(3 months ago)
Blocking for trying to access an exploit file: /wp-admin/maint/index.php
Hacking
๐ฏ๐ต
Valhalla
2026-03-13 06:52:05
(4 months ago)
/bak/wallet.zip
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-26 00:11:38
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.13.191.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.13.191.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 19:11:31.906183 2026] [security2:error] [pid 17371:tid 17384] [client 45.13.191.106:45129] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||magazineofwallstreet.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "magazineofwallstreet.com"] [uri "/back/dump.sql"] [unique_id "aZ-PsxBoLHeUIsWeVo1nMQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-24 15:20:18
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.13.191.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.13.191.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 10:20:14.348209 2026] [security2:error] [pid 27182:tid 27182] [client 45.13.191.106:64915] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lundtrading.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lundtrading.com"] [uri "/back/backup.sql"] [unique_id "aZ3BrmtRbXhBRllvhXfZiQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
gnom4ik
2026-02-22 03:57:42
(5 months ago)
ban-reviewer auto report; ip=45.13.191.106; scenario=http:scan; verdict=valid_ban; confidence=0.85; ...
show more
ban-reviewer auto report; ip=45.13.191.106; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP scanning activity (scenario: http:scan); Decision is based on port scan detection (abuseipdb category 14); IP has active decisions total of 1, indicating potential ongoing threat
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-02-13 18:37:50
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 45.13.191.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.13.191.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 13 13:37:43.981898 2026] [security2:error] [pid 2774:tid 2774] [client 45.13.191.106:36375] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mpaexchangeinc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mpaexchangeinc.com"] [uri "/backups/sql.sql"] [unique_id "aY9vd0eoD-NbbmMKGh-OmAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-03 18:39:07
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 45.13.191.106 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.13.191.106 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 03 13:39:02.189602 2026] [security2:error] [pid 14876:tid 14876] [client 45.13.191.106:36925] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||powderriverinc.com|F|2"] [data ".dat"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "powderriverinc.com"] [uri "/bak/wallet.dat"] [unique_id "aYJAxhWjg_wJDZ_mNK0_JgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack