π«π·
ELYAZ
2026-07-01 16:19:30
(1 month ago)
(wordpress) Failed wordpress login from 45.130.81.116 (UA/Ukraine/-): (CF_ENABLE)
Brute-Force
π¦πΊ
oncord
2026-06-18 17:21:10
(2 months ago)
Form spam
Web Spam
π±π»
garmtech.com
2026-06-14 01:50:49
(2 months ago)
IM360 WAF: Old style account creation and modification in Joomla! MV:registration
Web App Attack
π¦πΊ
MAGIC
2026-06-12 02:20:56
(2 months ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
Anonymous
2026-05-22 18:51:47
(2 months ago)
ASWEEDCO WEBFORM SPAM 45.130.81.116 (45.130.81.116)
Web Spam
πΊπΈ
TPI-Abuse
2026-05-22 13:30:26
(2 months ago)
(mod_security) mod_security (id:210350) triggered by 45.130.81.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 45.130.81.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 09:30:20.705775 2026] [security2:error] [pid 17258:tid 17258] [client 45.130.81.116:37211] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||43cambridge.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "43cambridge.com"] [uri "/archivarix.cms.php"] [unique_id "ahBabHDxl0Ja8dsn_lkBwAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-20 16:03:44
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 45.130.81.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 45.130.81.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 12:03:09.063284 2026] [security2:error] [pid 6765:tid 6775] [client 45.130.81.116:57097] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||www.tvpin.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.tvpin.com"] [uri "/index.cgi"] [unique_id "ag3bPQoKkrfPLengCjRdfAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
MPL
2026-05-20 13:36:44
(3 months ago)
tcp/443 (14 or more attempts)
Port Scan
π«π·
dynamix
2026-05-15 06:01:55
(3 months ago)
WordPress XMLRPC Brute Force Attack
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-12 07:39:28
(3 months ago)
(mod_security) mod_security (id:210350) triggered by 45.130.81.116 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210350) triggered by 45.130.81.116 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 12 03:39:20.072990 2026] [security2:error] [pid 7646:tid 7646] [client 45.130.81.116:51701] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||10mostwantedfugitives.net|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "10mostwantedfugitives.net"] [uri "/archivarix.cms.php"] [unique_id "agLZKH9AqW2ak6rdeaWuNQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-05-08 02:45:36
(3 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
π§πͺ
cmbplf
2026-05-05 03:33:13
(3 months ago)
63 requests with url.path //xmlrpc.php
Brute-Force
Bad Web Bot
π©πͺ
LRob
2026-04-17 06:00:12
(4 months ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
π©πͺ
Lino Project
2026-04-15 16:53:32
(4 months ago)
45.130.81.116 - - [15/Apr/2026:18:53:32 +0200] "GET /xmlrpc.php HTTP/1.1" 403 3963 "https://www.prim ...
show more
45.130.81.116 - - [15/Apr/2026:18:53:32 +0200] "GET /xmlrpc.php HTTP/1.1" 403 3963 "https://www.primobio.it/mio-account/" "Mozilla/5.0 (Windows NT 6.3; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/103.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
xserverx.ru
2026-03-29 20:05:28
(4 months ago)
Honeypot triggered:
IP: 45.130.81.116
Request to: https://xserverx.ru/archivarix.cms.php
Method: GET ...
show more
Honeypot triggered:
IP: 45.130.81.116
Request to: https://xserverx.ru/archivarix.cms.php
Method: GET
Host: xserverx.ru
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
Referer: Direct
Country: UA
ASN: Unknown
Triggered rules: (%[a-z0-9]+;|&#x?[a-f0-9]+;), \.php
Timestamp: 2026-03-29T20:05:26.571Z
show less
Hacking
Bad Web Bot
Web App Attack