๐บ๐ธ
TPI-Abuse
2026-08-01 01:39:04
(5 hours ago)
(mod_security) mod_security (id:225170) triggered by 45.136.26.182 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.136.26.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 21:38:58.359156 2026] [security2:error] [pid 4153284:tid 4153284] [client 45.136.26.182:47611] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bartholow.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bartholow.net"] [uri "/wp-json/wp/v2/users"] [unique_id "am1OMmS3LNVOLUS2iV3afAAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 06:23:44
(1 day ago)
(mod_security) mod_security (id:225170) triggered by 45.136.26.182 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.136.26.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 02:23:41.268254 2026] [security2:error] [pid 204883:tid 204907] [client 45.136.26.182:25847] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||aiegroup.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "aiegroup.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amw_bYJkA3lUU4ZIkkF37QAAAVA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Oakley
2026-07-23 01:17:08
(1 week ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-04 00:17:40
(4 weeks ago)
(mod_security) mod_security (id:210730) triggered by 45.136.26.182 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.136.26.182 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 20:17:34.998442 2026] [security2:error] [pid 30154:tid 30154] [client 45.136.26.182:59155] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Churchill II Recliner/Art Burl 2/originals/Thumbs.db"] [unique_id "akhRHgYAEKmKPgvX4Wj4GAAAABA"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Churchill%20II%20Recliner/Art%20Burl%202/originals/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-08 22:32:46
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐จ๐ญ
backslash
2026-05-20 07:12:00
(2 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐จ๐ญ
backslash
2026-04-16 12:03:03
(3 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ง๐ช
voormedia
2026-02-09 05:09:15
(5 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ง๐ช
voormedia
2026-02-05 21:20:27
(5 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐ช๐ธ
el-brujo
2026-02-05 13:35:48
(5 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0 Action: managed_challenge Source: firewallManaged ASN Description: PUREVOLTAGE-INC - PureVoltage Hosting Inc. Country: US Method: POST Timestamp: 2026-02-05T13:35:48Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-02-05 09:00:31
(5 months ago)
Reported by TangerangKota-CSIRT. Status: MALICIOUS
Hacking
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-02-05 08:15:19
(5 months ago)
[WAZUH] Mixed case extension detected (case variation bypass)
Hacking
Web App Attack
๐ซ๐ท
Tilellit.PRO
2026-02-05 06:23:06
(5 months ago)
Fail2Ban banned 45.136.26.182 for security violations in jail wp-armour. Log: 2026/02/05 06:23:06 [e ...
show more
Fail2Ban banned 45.136.26.182 for security violations in jail wp-armour. Log: 2026/02/05 06:23:06 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.136.26.182 | Target: wplogin" , client: 45.136.26.182, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
๐บ๐ธ
Penny Packer
2026-02-03 17:38:15
(5 months ago)
Fail2Ban apache-tripwires
Web App Attack