๐ฑ๐ป
garmtech.com
2026-05-17 03:16:21
(2 weeks ago)
Attempted access to sensitive endpoint (/xmlrpc.php) detected. Automated scan or unauthorized probin ...
show more
Attempted access to sensitive endpoint (/xmlrpc.php) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 15:40:36
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.145.131.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.145.131.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 11:40:31.164849 2026] [security2:error] [pid 26655:tid 26655] [client 45.145.131.18:20473] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tradersworldmarket.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tradersworldmarket.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afN370PEvM4ugA6SkffnngAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 19:43:00
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.145.131.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.145.131.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 15:42:52.967261 2026] [security2:error] [pid 7955:tid 7955] [client 45.145.131.18:19735] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||puckerbottombikinis.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "puckerbottombikinis.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afJfPMZ0V_rMfkVkpFZragAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 22:16:43
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.145.131.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.145.131.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 18:16:39.312953 2026] [security2:error] [pid 24222:tid 24222] [client 45.145.131.18:37397] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||geckoturner.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "geckoturner.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ae_gR5lc7IzgWVMXS1rCvwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-08-28 01:15:38
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2025-08-20 00:52:32
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐จ๐ญ
backslash
2025-05-24 05:02:12
(1 year ago)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-03-05 10:17:19
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 45.145.131.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.145.131.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 05 05:17:10.779581 2025] [security2:error] [pid 53503:tid 53503] [client 45.145.131.18:57465] [client 45.145.131.18] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Briarwood II/Stetson Bordeaux/Thumbs.db"] [unique_id "Z8gkpvCeNKksuQlp5xhZMwAAAAg"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Briarwood%20II/Stetson%20Bordeaux/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2024-09-27 16:30:14
(1 year ago)
Automatic report - Vulnerability scan
/RDWeb/Pages/en-US/login.aspx
Web App Attack
๐จ๐ฆ
wil.com
2024-09-23 08:07:25
(1 year ago)
GlobalProtect login attempts with user pgrant.
VPN IP
Brute-Force
๐จ๐ญ
backslash
2024-05-23 00:30:08
(2 years ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
Anonymous
2024-05-14 13:03:30
(2 years ago)
Malicious activity detected
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-04-14 08:29:17
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 45.145.131.18 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 45.145.131.18 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 14 04:29:11.775179 2024] [security2:error] [pid 1008] [client 45.145.131.18:17889] [client 45.145.131.18] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Barcalounger/Images/Carrington/Thumbs.db"] [unique_id "ZhuT16qCLRiQwVsBUKEZ3AAAAAI"], referer: https://vitalitywebb.com/backstore/Barcalounger/Images/Carrington/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2024-04-12 00:25:08
(2 years ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
WhiteFireOCN1
2023-05-23 20:32:45
(3 years ago)
Targeted credential stuffing attack, observed 2023-05-23T06:52:45. Part of an attack that included 1 ...
show more
Targeted credential stuffing attack, observed 2023-05-23T06:52:45. Part of an attack that included 130 logins from 121 IPs. Likely being used as a proxy/tor exit node.
show less
Hacking
Brute-Force
Exploited Host