๐บ๐ฆ
URAN Publishing Service
2026-08-08 07:32:48
(2 weeks ago)
[08/Aug/2026:10:32:47 +0300] -- 45.13.191.13 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-js ...
show more
[08/Aug/2026:10:32:47 +0300] -- 45.13.191.13 Ban reason: Scanner [CMS_GENERIC] | Request: GET /wp-json/ HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-07-14 13:47:38
(1 month ago)
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 45.13.191.13 (NO/Norway/-): 1 in the last 3600 secs ...
show more
(backdoor_scan) REGOLA 7 - Backdoor Scan Attempt 45.13.191.13 (NO/Norway/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 45.13.191.13 - - [14/Jul/2026:15:47:28 +0200] "GET /wp-content/themes/pridmag/db.php?u HTTP/1.1" 301 298 "-" "Go-http-client/1.1" "-" host=orem.it
show less
Port Scan
๐ฌ๐ง
consul.to
2026-07-14 06:28:17
(1 month ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-07-11 11:32:03
(1 month ago)
"GET /wp-content/plugins/pwnd-1/pwnd.php HTTP/1.1"
Hacking
Web App Attack
Anonymous
2026-07-10 21:47:50
(1 month ago)
45.13.191.13 - - [10/Jul/2026:23:47:47 +0200] "GET /wp-content/fonts/index.php HTTP/1.1" 404 444 "-" ...
show more
45.13.191.13 - - [10/Jul/2026:23:47:47 +0200] "GET /wp-content/fonts/index.php HTTP/1.1" 404 444 "-" "Go-http-client/1.1"
45.13.191.13 - - [10/Jul/2026:23:47:47 +0200] "GET /wp-content/fonts/index.php HTTP/1.1" 404 248 "-" "Go-http-client/1.1"
45.13.191.13 - - [10/Jul/2026:23:47:48 +0200] "GET /wp-content/index.php HTTP/1.1" 404 444 "-" "Go-http-client/1.1"
45.13.191.13 - - [10/Jul/2026:23:47:48 +0200] "GET /wp-content/index.php HTTP/1.1" 404 248 "-" "Go-http-client/1.1"
45.13.191.13 - - [10/Jul/2026:23:47:50 +0200] "GET /wp-includes/assets/index.php HTTP/1.1" 404 444 "-" "Go-http-client/1.1"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-04 15:58:20
(3 months ago)
(mod_security) mod_security (id:234930) triggered by 45.13.191.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:234930) triggered by 45.13.191.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 11:58:14.471501 2026] [security2:error] [pid 15282:tid 15282] [client 45.13.191.13:54125] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||belgiophar.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "belgiophar.org"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "afjCFkGLjk-PSgAGUcTf8AAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-05-04 12:19:37
(3 months ago)
Aggressive web search of vulnerable pages: /wp-content/themes/pridmag/db.php?u /wp-content/plugins/s ...
show more
Aggressive web search of vulnerable pages: /wp-content/themes/pridmag/db.php?u /wp-content/plugins/shell/noimg.php /wp-content/plugins/pwnd-2/p ...
show less
Web App Attack
๐บ๐ธ
WellSpring
2026-05-04 04:06:40
(3 months ago)
Automated probe detected by Ody Sentinel / WellSpr.ing. Type: wordpress_scan. Path: /wp-content/plug ...
show more
Automated probe detected by Ody Sentinel / WellSpr.ing. Type: wordpress_scan. Path: /wp-content/plugins/hello-plus/classes/ehp-sarang.php. Auto-blocked after threshold exceeded. Dossier: https://wellspr.ing/dossier/sentinel-45-13-191-13
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-17 20:06:23
(4 months ago)
(mod_security) mod_security (id:234930) triggered by 45.13.191.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:234930) triggered by 45.13.191.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 17 16:06:18.181124 2026] [security2:error] [pid 1575882:tid 1575882] [client 45.13.191.13:25737] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||reunionking.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "reunionking.com"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "aeKSukfPI7oZl9Qxp86rRgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-04-15 04:00:08
(4 months ago)
Repeated 403 errors, blocked by Fail2ban in custom-403 jail
Bad Web Bot
๐ซ๐ท
Octopuce
2026-04-04 19:40:51
(4 months ago)
Aggressive web search of vulnerable pages: /wp-content/plugins/enhanced-text-widget/analyst/src/403x ...
show more
Aggressive web search of vulnerable pages: /wp-content/plugins/enhanced-text-widget/analyst/src/403x.php /wp-content/plugins/semrush/x.php /wp- ...
show less
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-04-04 17:50:33
(4 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-16 09:30:12
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 45.13.191.13 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.13.191.13 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 16 05:30:05.538639 2026] [security2:error] [pid 27681:tid 27681] [client 45.13.191.13:49711] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dudleyanddudley.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dudleyanddudley.com"] [uri "/www.sql"] [unique_id "abfNnRBWI5URUWIeT7Z7dAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
Valhalla
2026-03-15 11:08:35
(5 months ago)
/restore/config.json
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-03-08 11:05:13
(5 months ago)
Request Overload (130)
Brute-Force
Web App Attack