🇧🇪
Ivo Vynckier
2026-09-09 14:13:00
(4 hours ago)
45.13.191.86 - - [09/Sep/2026:06:42:26 +0200] "GET /wp-content/plugins/neoncore-themes/O/SrHD3odefau ...
show more
45.13.191.86 - - [09/Sep/2026:06:42:26 +0200] "GET /wp-content/plugins/neoncore-themes/O/SrHD3odefault.php?p= HTTP/2.0" 301 331 "http://www.spielberg-ocr.com/wp-content/plugins/neoncore-themes/O/SrHD3odefault.php?p=" "Go-http-client/2.0"
45.13.191.86 - - [09/Sep/2026:06:42:27 +0200] "GET /wp-content/plugins/bbpress/file5.php HTTP/2.0" 301 310 "http://www.spielberg-ocr.com/wp-content/plugins/bbpress/file5.php" "Go-http-client/2.0"
45.13.191.86 - - [09/Sep/2026:06:42:28 +0200] "GET /wp-includes/core.php HTTP/2.0" 301 294 "http://www.spielberg-ocr.com/wp-includes/core.php" "Go-http-client/2.0"
show less
Web App Attack
🇮🇹
VHosting
2026-09-09 06:05:03
(12 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-09 05:20:29
(13 hours ago)
[09/Sep/2026:08:20:29 +0300] -- 45.13.191.86 Ban reason: User-Agent Go-http-client
Bad Web Bot
Web App Attack
Anonymous
2026-07-10 21:47:21
(1 month ago)
45.13.191.86 - - [10/Jul/2026:23:47:20 +0200] "GET /wp-content/themes/Divi/404.php HTTP/1.1" 404 444 ...
show more
45.13.191.86 - - [10/Jul/2026:23:47:20 +0200] "GET /wp-content/themes/Divi/404.php HTTP/1.1" 404 444 "-" "Go-http-client/1.1"
45.13.191.86 - - [10/Jul/2026:23:47:20 +0200] "GET /wp-content/themes/Divi/404.php HTTP/1.1" 404 248 "-" "Go-http-client/1.1"
45.13.191.86 - - [10/Jul/2026:23:47:20 +0200] "GET /wp-content/themes/bltm/wp-login.php HTTP/1.1" 404 444 "-" "Go-http-client/1.1"
45.13.191.86 - - [10/Jul/2026:23:47:20 +0200] "GET /wp-content/themes/bltm/wp-login.php HTTP/1.1" 404 248 "-" "Go-http-client/1.1"
45.13.191.86 - - [10/Jul/2026:23:47:21 +0200] "GET /wp-content/themes/seotheme/db.php?u HTTP/1.1" 404 444 "-" "Go-http-client/1.1"
...
show less
Brute-Force
Web App Attack
🇺🇦
URAN Publishing Service
2026-07-10 20:22:46
(1 month ago)
45.13.191.86 - - [10/Jul/2026:23:22:45 +0300] "GET /wp-admin/js/index.php HTTP/1.1" 404 706 "-" "Go- ...
show more
45.13.191.86 - - [10/Jul/2026:23:22:45 +0300] "GET /wp-admin/js/index.php HTTP/1.1" 404 706 "-" "Go-http-client/1.1"
45.13.191.86 - - [10/Jul/2026:23:22:46 +0300] "GET /wp-admin/css/index.php HTTP/1.1" 404 706 "-" "Go-http-client/1.1"
...
show less
Web App Attack
🇺🇸
nyt
2026-05-11 03:46:10
(3 months ago)
404 flood (16/60s), 404 flood (17/60s)
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-04 12:47:19
(4 months ago)
(mod_security) mod_security (id:234930) triggered by 45.13.191.86 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:234930) triggered by 45.13.191.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 08:47:14.553616 2026] [security2:error] [pid 15397:tid 15405] [client 45.13.191.86:41455] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\/lib\\\\/php\\\\/connector\\\\.minimal\\\\.php$" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/27_Apps_WPPlugin.conf"] [line "6778"] [id "234930"] [rev "2"] [msg "COMODO WAF: File upload vulnerability in the file manager plugin before 6.9 for WordPress (CVE-2020-25213)||behaviorhealth.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WPPlugin"] [hostname "behaviorhealth.org"] [uri "/wp-content/plugins/wp-file-manager/lib/php/connector.minimal.php"] [unique_id "afiVUqgm-GkFqteC4_4rNgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-05-04 04:08:11
(4 months ago)
Aggressive web search of vulnerable pages: /wp-content/plugins/wpcall-button/button-image.php /wp-co ...
show more
Aggressive web search of vulnerable pages: /wp-content/plugins/wpcall-button/button-image.php /wp-content/plugins/SecurityFin/SecurityFin.php / ...
show less
Web App Attack
🇲🇹
Malta
2026-04-29 14:30:01
(4 months ago)
45.13.191.86 - - [29/Apr/2026:16:30:00 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT ...
show more
45.13.191.86 - - [29/Apr/2026:16:30:00 +0200] "POST /wp-login.php HTTP/1.1" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 Chrome/129.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-04-15 09:15:31
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.13.191.86 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:225170) triggered by 45.13.191.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 05:15:26.852929 2026] [security2:error] [pid 1054944:tid 1054944] [client 45.13.191.86:27983] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||allotrope.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "allotrope.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ad9XLpQpgujLlWgOiQe4EwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Kenshin869
2026-04-05 04:31:18
(5 months ago)
Wordpress unauthorized access attempt
Brute-Force
🇩🇪
ghostwarriors
2026-04-04 17:50:26
(5 months ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
myagent.site
2026-03-14 16:05:13
(5 months ago)
Blocking for trying to access an exploit file: //xmlrpc.php?rsd
Hacking
🇺🇸
TPI-Abuse
2026-03-04 16:57:45
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 45.13.191.86 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 45.13.191.86 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 04 11:57:38.693406 2026] [security2:error] [pid 15355:tid 15355] [client 45.13.191.86:43607] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bitcoinsquaretrader.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bitcoinsquaretrader.com"] [uri "/old/sql.sql"] [unique_id "aahkgtIB5lK-GXX89Y_5kQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-02-28 04:45:04
(6 months ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot