๐บ๐ธ
mw
2026-07-27 00:01:23
(2 months ago)
GET /wp-admin/images/bootstrap.php HTTP/1.1
Web App Attack
๐ฌ๐ง
consul.to
2026-07-22 11:38:52
(2 months ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-07-15 04:22:24
(2 months ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
Octopuce
2026-07-02 06:46:16
(3 months ago)
Aggressive web search of vulnerable pages: /bless.php /O-Simple.php /lock360.php /zwso.php /chosen.p ...
show more
Aggressive web search of vulnerable pages: /bless.php /O-Simple.php /lock360.php /zwso.php /chosen.php /about.php /admin.php /mah.php /.wp/wso. ...
show less
Web App Attack
๐ซ๐ฎ
Some Body
2026-06-30 05:14:38
(3 months ago)
Aggressive web scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 19:21:58
(3 months ago)
(mod_security) mod_security (id:240000) triggered by 45.132.225.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.225.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 15:21:51.621232 2026] [security2:error] [pid 7882:tid 7882] [client 45.132.225.10:60427] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||robertprowse.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "robertprowse.net"] [uri "/images/stories/themes.php"] [unique_id "ajLzz--xfSg_ds1-IYLQ6AAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-06-14 11:29:04
(3 months ago)
trying wp-login.php/xmlrpc.php 111 times in 1 minutes
Brute-Force
Web App Attack
๐จ๐ญ
Sophie Nina
2026-04-22 00:00:01
(5 months ago)
Automatically blocked by server
Fraud Orders
๐บ๐ธ
TPI-Abuse
2026-04-20 20:14:20
(5 months ago)
(mod_security) mod_security (id:240000) triggered by 45.132.225.10 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:240000) triggered by 45.132.225.10 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 16:14:13.162479 2026] [security2:error] [pid 26603:tid 26603] [client 45.132.225.10:38947] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||dandpcreamery.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "dandpcreamery.com"] [uri "/images/stories/themes.php"] [unique_id "aeaJFdbwptAa5oWA10hPHQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-18 12:40:47
(5 months ago)
45.132.225.10 - - [18/Apr/2026:14:40:20 +0200] "GET /cong.php HTTP/1.1" 404 470 "-" "Mozilla/5.0 (Ma ...
show more
45.132.225.10 - - [18/Apr/2026:14:40:20 +0200] "GET /cong.php HTTP/1.1" 404 470 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4147.105 Safari/537.36 OPR/70.0.3728.95"
45.132.225.10 - - [18/Apr/2026:14:40:20 +0200] "GET /wp-includes/block-bindings/imagess.php HTTP/1.1" 404 470 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/58.0.3029.110 Safari/537.3"
45.132.225.10 - - [18/Apr/2026:14:40:20 +0200] "GET /wp-content/plugins/pwnd/adminfus.php HTTP/1.1" 404 470 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
45.132.225.10 - - [18/Apr/2026:14:40:21 +0200] "GET /wp-includes/default-filters-edit.php HTTP/1.1" 404 470 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:71.0) Gecko/20100101 Firefox/71.0"
45.132.225.10 - - [18/Apr/2026:14:40:21 +0200] "GET /css/install.php HTTP/1.1" 404 470 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/537.36
...
show less
DDoS Attack
Anonymous
2026-03-28 11:15:12
(6 months ago)
45.132.225.10 - - [28/Mar/2026:12:14:09 +0100] "POST /xmlrpc.php HTTP/1.1" 405 428
45.132.225.10 - - ...
show more
45.132.225.10 - - [28/Mar/2026:12:14:09 +0100] "POST /xmlrpc.php HTTP/1.1" 405 428
45.132.225.10 - - [28/Mar/2026:12:15:10 +0100] "POST /xmlrpc.php HTTP/1.1" 405 428
...
show less
Brute-Force
Bad Web Bot
๐ฆ๐บ
MAGIC
2026-03-25 02:06:25
(6 months ago)
VM5 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ณ๐ฟ
Tripwire
2026-03-25 00:29:58
(6 months ago)
Probing for Wordpress - /xmlrpc.php
Brute-Force
Web App Attack
๐บ๐ธ
mw
2026-03-13 03:10:22
(6 months ago)
GET /wp-admin/js/widgets/doc.php HTTP/1.1
Web App Attack
๐จ๐ญ
Origon
2026-03-13 00:32:21
(6 months ago)
http-backdoors-attempts - IP: 45.132.225.10 - time="2026-03-13T01:32:10+01:00" level=info msg="(555 ...
show more
http-backdoors-attempts - IP: 45.132.225.10 - time="2026-03-13T01:32:10+01:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-backdoors-attempts by ip 45.132.225.10 (AU/137409) : 4h ban on Ip 45.132.225.10" module=db
show less
Web App Attack