๐ฏ๐ต
VXG-NET
2026-05-27 15:33:43
(1 week ago)
port=80, indicator_type=sql-injection
SQL Injection
๐จ๐ญ
backslash
2026-02-27 02:06:03
(3 months ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐ฉ๐ช
HandyTreff.de
2026-02-08 22:34:39
(3 months ago)
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -49.15 (Bad < -10 / Very Bad < -20 / ...
show more
Bot/Spam/Scrapper attack detected on www.handytreff.de - Score: -49.15 (Bad < -10 / Very Bad < -20 / Extreme < -35) | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/116.0.583.13
show less
Bad Web Bot
Web App Attack
Anonymous
2025-09-02 15:50:24
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-05-16 02:13:57
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.145.129.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.145.129.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 15 22:13:53.756324 2025] [security2:error] [pid 600759:tid 600759] [client 45.145.129.217:57653] [client 45.145.129.217] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||michaelmoorefield.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "michaelmoorefield.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aCafYe0eV_jrDe7ox4g-gAAAABI"], referer: https://michaelmoorefield.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Jason Howell
2025-05-09 04:45:35
(1 year ago)
45.145.129.217 - - [08/May/2025:23:45:13 -0500] "GET /wp-login.php HTTP/1.1" 301 558 "http://abstrac ...
show more
45.145.129.217 - - [08/May/2025:23:45:13 -0500] "GET /wp-login.php HTTP/1.1" 301 558 "http://abstractco.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36"
45.145.129.217 - - [08/May/2025:23:45:17 -0500] "GET /wp-login.php HTTP/1.1" 200 4724 "https://abstractco.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36"
45.145.129.217 - - [08/May/2025:23:45:26 -0500] "POST /wp-login.php HTTP/1.1" 200 4855 "https://www.abstractco.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36"
45.145.129.217 - - [08/May/2025:23:45:30 -0500] "POST /wp-login.php HTTP/1.1" 200 4826 "https://www.abstractco.com/wp-login.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.198 Safari/537.36"
45.145.129.217 - - [08/M
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-07 22:56:50
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 45.145.129.217 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.145.129.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 07 18:56:47.077113 2025] [security2:error] [pid 2793531:tid 2793531] [client 45.145.129.217:35101] [client 45.145.129.217] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||fuentevictoria.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "fuentevictoria.com"] [uri "/wp-json/wp/v2/users/"] [unique_id "aBvlL8lR3NNR0rrXV5a6CAAAAAc"], referer: https://fuentevictoria.com/wp-json/wp/v2/users/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
wil.com
2024-09-24 12:55:34
(1 year ago)
GlobalProtect login attempts with user cstephens.
VPN IP
Brute-Force
๐ฌ๐ง
essinghigh
2024-05-01 04:21:10
(2 years ago)
1714537270 # Service_probe # SIGNATURE_SEND # source_ip:45.145.129.217 # dst_port:5607
...
Port Scan
๐ง๐ท
hostseries
2024-04-29 19:39:21
(2 years ago)
Trigger: LF_DISTATTACK
Brute-Force
๐ฉ๐ช
iNetWorker
2024-02-11 14:06:20
(2 years ago)
trolling for resource vulnerabilities
Web App Attack
๐จ๐ญ
backslash
2023-10-12 04:50:22
(2 years ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐จ๐ญ
backslash
2023-09-08 10:57:24
(2 years ago)
honeypot
Bad Web Bot