๐บ๐ธ
nationaleventpros.com
2026-07-09 17:46:28
(2 months ago)
WordPress login attempt
Brute-Force
๐ง๐ช
voormedia
2026-06-30 02:19:23
(3 months ago)
Accessed trap at '/wp-login.php'
Web App Attack
๐ฉ๐ช
LRob
2026-06-15 19:45:04
(3 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
Anonymous
2026-05-04 11:43:11
(4 months ago)
[redacted] 45.132.186.12 - - [04/May/2026:13:42:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "A ...
show more
[redacted] 45.132.186.12 - - [04/May/2026:13:42:43 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 45.132.186.12 - - [04/May/2026:13:42:44 +0200] "POST /xmlrpc.php HTTP/1.1" 200 222 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 45.132.186.12 - - [04/May/2026:13:43:01 +0200] "POST /xmlrpc.php HTTP/1.1" 200 132 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 45.132.186.12 - - [04/May/2026:13:43:02 +0200] "POST /xmlrpc.php HTTP/1.1" 200 245 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 45.132.186.12 - - [04/May/2026:13:43:04 +0200] "POST /xmlrpc.php HTTP/1.1" 200 245 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 45.132.186.12 - - [04/May/2026:13:43:05 +0200] "POST /xmlrpc.php HTTP/1.1" 200 245 "-" "Apache-HttpClient/4.5.13 (Java/11.0.30)"
[redacted] 45.132.186.12 - - [04/May/2026:13:43:06 +0200] "POST /xmlrpc.php HTTP/1.1" 200 245 "-" "Apache-HttpClient/4.5.13 (Java/11.
...
show less
Hacking
Web App Attack
๐บ๐ธ
kosada.com
2026-05-01 11:15:48
(4 months ago)
Web password guessing
Brute-Force
๐จ๐ฟ
ptlab
2026-04-21 02:48:03
(5 months ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 10:32:16
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.132.186.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.132.186.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 06:32:09.007907 2026] [security2:error] [pid 2587248:tid 2587248] [client 45.132.186.12:18335] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||garysgates.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "garysgates.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aeSvKSvmS1yNSd-6UfkPSwAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-04-18 04:06:40
(5 months ago)
WordPress login attempt
Brute-Force
Anonymous
2026-04-14 00:55:23
(5 months ago)
FPROCO WEBEXPLOIT 45.132.186.12 (45.132.186.12)
Web App Attack
Anonymous
2026-03-31 08:35:15
(5 months ago)
FPROCO WEBEXPLOIT 45.132.186.12 (45.132.186.12)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 02:28:53
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.132.186.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.132.186.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 22:28:48.271388 2026] [security2:error] [pid 15768:tid 15768] [client 45.132.186.12:64635] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pages4you.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pages4you.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acsxYHdn8ViADCZUnc1bzQAAABg"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 00:33:11
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.132.186.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.132.186.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 30 20:33:03.354852 2026] [security2:error] [pid 17289:tid 17289] [client 45.132.186.12:40865] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aeongames.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aeongames.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acsWP0SURTP0LTKKeUhrsAAAAA8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-03-15 05:34:52
(6 months ago)
IM360 WAF: WordPress plugin/theme install or edit. Block empty Referer
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-23 00:25:54
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 45.132.186.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.132.186.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 19:25:49.980304 2026] [security2:error] [pid 12560:tid 12560] [client 45.132.186.12:39245] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||natickvillagerentals.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "natickvillagerentals.com"] [uri "/wp-json/wp/v2/users/3"] [unique_id "aXLADbhWtw9-kp_gHYNmsgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-22 13:44:10
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 45.132.186.12 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.132.186.12 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 08:44:05.217550 2026] [security2:error] [pid 2914881:tid 2914919] [client 45.132.186.12:39705] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||teresahagadorn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "teresahagadorn.com"] [uri "/wp-json/wp/v2/users/2"] [unique_id "aXIppXzt0syQMPcATJwKzgAAAkk"]
show less
Brute-Force
Bad Web Bot
Web App Attack