🇺🇸
nationaleventpros.com
2026-09-05 05:33:04
(1 week ago)
WordPress login attempt
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 21:07:22
(1 week ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:07:15.253863 2026] [security2:error] [pid 30541:tid 30541] [client 45.140.206.14:47177] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||beautyradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "beautyradio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "apszAystcZLERgSeU4-GSwAAABw"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-03 03:35:23
(1 week ago)
WordPress login attempt
Brute-Force
🇩🇪
4server
2026-08-18 10:59:32
(3 weeks ago)
[TueAug1812:59:26.9495072026][security2:error][pid940123:tid940250][client45.140.206.14:0]ModSecurit ...
show more
[TueAug1812:59:26.9495072026][security2:error][pid940123:tid940250][client45.140.206.14:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Stringmatch\"/xmlrpc.php\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"170\"][id\"960024\"][msg\"XML-RPCdisabled\"][hostname\"alessandrolucchini.ch\"][uri\"/xmlrpc.php\"][unique_id\"aoQ7Dtk2RWvU8LxBP2bg-QAAAk0\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-07-27 15:57:37
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:57:32.925053 2026] [security2:error] [pid 535102:tid 535102] [client 45.140.206.14:50965] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||333w88.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "333w88.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amd_7FiDwNurxeUY2HkzpAAAAAM"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Tilellit.PRO
2026-07-05 04:28:27
(2 months ago)
WP Armour Plugin detection
Web Spam
Brute-Force
🇫🇷
Tilellit.PRO
2026-06-28 08:17:52
(2 months ago)
Fail2Ban banned 45.140.206.14 for security violations in jail wp-armour. Log: 2026/06/28 08:17:51 [e ...
show more
Fail2Ban banned 45.140.206.14 for security violations in jail wp-armour. Log: 2026/06/28 08:17:51 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.140.206.14 | Target: wplogin" , client: 45.140.206.14, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇫🇷
Tilellit.PRO
2026-06-27 11:23:08
(2 months ago)
Fail2Ban banned 45.140.206.14 for security violations in jail wp-armour. Log: 2026/06/27 11:23:07 [e ...
show more
Fail2Ban banned 45.140.206.14 for security violations in jail wp-armour. Log: 2026/06/27 11:23:07 [error] FastCGI sent in stderr: "PHP message: [WP_ARMOUR_BAN] IP: 45.140.206.14 | Target: wplogin" , client: 45.140.206.14, server: [REDACTED], request: "POST /wp-login.php HTTP/1.1", upstream: [REDACTED], host: [REDACTED], referrer: "https://comerciogallego.es/wp-login.php"
...
show less
Web Spam
🇺🇸
TPI-Abuse
2026-04-29 16:38:02
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 12:37:54.495225 2026] [security2:error] [pid 9375:tid 9375] [client 45.140.206.14:19381] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gonzalez.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gonzalez.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afIz4quLn8g2Tiv5HkFiQQAAACA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-25 16:09:23
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 25 12:09:18.225325 2026] [security2:error] [pid 20519:tid 20519] [client 45.140.206.14:64069] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||steinmetzjewelers.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "steinmetzjewelers.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aeznLvNlwUItA3SDivgprQAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-17 01:26:30
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 21:26:25.476471 2026] [security2:error] [pid 3773041:tid 3773041] [client 45.140.206.14:44783] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||pages4you.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "pages4you.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aeGMQUpeyE8k7Otip6i26QAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-14 01:01:58
(5 months ago)
FPROCO WEBEXPLOIT 45.140.206.14 (45.140.206.14)
Web App Attack
🇺🇸
TPI-Abuse
2026-01-22 18:16:28
(7 months ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.14 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jan 22 13:16:24.135047 2026] [security2:error] [pid 18132:tid 18138] [client 45.140.206.14:12685] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||npaccountants.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "npaccountants.org"] [uri "/wp-json/wp/v2/users/2"] [unique_id "aXJpeDF6X_NCMLVjDTBY6QAAAMQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2025-06-17 17:10:08
(1 year ago)
Detected attack by Imunify360
Brute-Force
Web App Attack
🇨🇦
wil.com
2025-03-28 08:36:49
(1 year ago)
GlobalProtect login attempts with user sgreeve.
VPN IP
Brute-Force