Anonymous
2026-07-11 12:02:01
(2 weeks ago)
"GET /wp-admin/js/index.php HTTP/1.1"
Hacking
Web App Attack
๐ฎ๐น
VHosting
2026-07-10 09:15:04
(2 weeks ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-05-24 10:27:37
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐ณ
dineshskt4all
2026-05-10 17:59:37
(2 months ago)
[Sun May 10 17:59:35.279334 2026] [proxy_fcgi:error] [pid 692121:tid 129571539080896] [client 45.13. ...
show more
[Sun May 10 17:59:35.279334 2026] [proxy_fcgi:error] [pid 692121:tid 129571539080896] [client 45.13.191.68:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ซ๐ท
Octopuce
2026-05-04 12:19:01
(2 months ago)
Aggressive web search of vulnerable pages: /wp-content/plugins/dummyyummy/wp-signup.php /wp-content/ ...
show more
Aggressive web search of vulnerable pages: /wp-content/plugins/dummyyummy/wp-signup.php /wp-content/plugins/dzs-zoomsounds/1877.php /wp-content ...
show less
Web App Attack
Anonymous
2026-04-24 14:05:42
(3 months ago)
Blocked: Reason='Suspicious traffic score=75 (review-based detection)'; Requests=6
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-15 06:07:36
(3 months ago)
(mod_security) mod_security (id:225170) triggered by 45.13.191.68 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.13.191.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 02:07:29.976867 2026] [security2:error] [pid 2324989:tid 2325084] [client 45.13.191.68:30729] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||alancphotography.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "alancphotography.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ad8rIdM_xhdvzf8zWxloBgAAAcw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-04-15 02:01:05
(3 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ซ๐ท
bazter.pro
2026-04-08 19:59:49
(3 months ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-14 12:41:02
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 45.13.191.68 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.13.191.68 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 14 08:40:54.732827 2026] [security2:error] [pid 28128:tid 28128] [client 45.13.191.68:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kryptonome.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kryptonome.com"] [uri "/backup/www.sql"] [unique_id "abVXVuz2t58VHjWnscBNkwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-02-28 06:50:00
(4 months ago)
Security scan or malicious bot activity detected by Fail2Ban
Bad Web Bot
Web App Attack
๐ฌ๐ง
pinguin
2026-02-25 00:43:25
(5 months ago)
Triggered Cloudflare WAF (firewallManaged) from NO.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD metho ...
show more
Triggered Cloudflare WAF (firewallManaged) from NO.
Action taken: LOG
Protocol: HTTP/1.1 (HEAD method)
Endpoint: /restore/wallet.dat
UA: Empty string
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฌ๐ง
Axel
2026-02-23 19:33:23
(5 months ago)
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by pol ...
show more
Blocked by ModSecurity. Rule ID: 210730 Message: COMODO WAF: URL file extension is restricted by policy||ipvi.network|F|2 Phase: 2 Severity: CRITICAL URI: /backup/www.sql Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ซ๐ฎ
gnom4ik
2026-02-22 04:26:48
(5 months ago)
ban-reviewer auto report; ip=45.13.191.68; scenario=http:scan; verdict=valid_ban; confidence=0.85; c ...
show more
ban-reviewer auto report; ip=45.13.191.68; scenario=http:scan; verdict=valid_ban; confidence=0.85; categories=14,15,22; active_decisions=1; lookback_decisions=1; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=IP flagged for HTTP scanning activity (scenario: http:scan); AbuseIPDB category 14 (Port Scan) is applicable; AbuseIPDB category 15 (Hacking) is applicable; AbuseIPDB category 22 (SSH) is applicable
show less
Port Scan
Hacking
SSH
๐บ๐ฆ
URAN Publishing Service
2026-02-12 10:41:57
(5 months ago)
45.13.191.68 - - [12/Feb/2026:12:41:55 +0200] "GET //wp-content/admin.php HTTP/1.1" 404 280 "-" "Go- ...
show more
45.13.191.68 - - [12/Feb/2026:12:41:55 +0200] "GET //wp-content/admin.php HTTP/1.1" 404 280 "-" "Go-http-client/1.1"
45.13.191.68 - - [12/Feb/2026:12:41:56 +0200] "GET //wp-content/plugins/schema/geckos.php HTTP/1.1" 404 280 "-" "Go-http-client/1.1"
...
show less
Web App Attack