๐ฌ๐ง
abivia
2026-10-03 09:38:00
(17 hours ago)
Abivia WAF trigger: Rule scriptKiddies: wp2shell exploit uri: /?rest_route=/batch/v1
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-10-01 17:04:15
(2 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-25 15:31:46
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐จ๐ญ
backslash
2026-08-25 17:33:02
(1 month ago)
block ruleset AA06B7315BA6AEB6421B52F0B32E14B509FD5FF0
SQL Injection
๐ช๐ธ
librebit
2026-07-07 18:19:51
(2 months ago)
Brute force
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-04-08 10:00:56
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 06:00:52.494640 2026] [security2:error] [pid 2034034:tid 2034034] [client 45.140.206.31:60003] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sigiweb.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sigiweb.net"] [uri "/wp-json/wp/v2/users"] [unique_id "adYnVLZJGvCY36C1XIj_fgAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 19:44:07
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 07 15:44:00.060954 2026] [security2:error] [pid 1030521:tid 1030525] [client 45.140.206.31:23039] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||ardentsi.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "ardentsi.com"] [uri "/wp-json/wp/v2/users"] [unique_id "adVegGwDxZCN0xCq71P7EwAAAMI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-03-26 20:15:26
(6 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
Anonymous
2025-12-03 08:08:32
(10 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-10-31 19:50:10
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 31 15:50:05.502071 2025] [security2:error] [pid 24529:tid 24529] [client 45.140.206.31:35965] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.impressionsinthread.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.impressionsinthread.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aQUS7YfnG9eiTCDk2MJ8-gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-29 11:41:06
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 45.140.206.31 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.140.206.31 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 29 07:41:02.027434 2025] [security2:error] [pid 4674:tid 4760] [client 45.140.206.31:45869] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||richardleeweatherman.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "richardleeweatherman.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aQH9TjbWKj9xP2CqSeeH-gAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
lp
2025-05-31 18:20:56
(1 year ago)
Unauthorized VPN login attempts: 2 attempts were recorded from 45.140.206.31
2025-05-31T18:58:33+02: ...
show more
Unauthorized VPN login attempts: 2 attempts were recorded from 45.140.206.31
2025-05-31T18:58:33+02:00 vpn Access-Reject 'elida' station: 45.140.206.31 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
2025-05-31T19:20:20+02:00 vpn Access-Reject 'cosmologist' station: 45.140.206.31 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-05-31 00:21:24
(1 year ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 45.140.206.31
2025-05-31T01:13:25+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 45.140.206.31
2025-05-31T01:13:25+02:00 vpn Access-Reject 'agnostic' station: 45.140.206.31 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-05-25 00:20:52
(1 year ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 45.140.206.31
2025-05-25T02:12:43+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 45.140.206.31
2025-05-25T02:12:43+02:00 vpn Access-Reject 'aeronautic' station: 45.140.206.31 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐ธ๐ช
OnTheEdge
2025-03-18 21:26:32
(1 year ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack