๐บ๐ธ
ambor
2026-04-04 01:31:45
(2 months ago)
Honeypot access: WordPress admin access attempt. Path: /wp-login.php
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-28 09:13:06
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.126.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.126.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 05:12:59.157195 2026] [security2:error] [pid 25994:tid 25994] [client 45.148.126.146:37335] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tanny.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tanny.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acebm4ScvHyLVykz-AOFIgAAAAo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-27 21:46:49
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.126.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.126.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 27 17:46:45.277133 2026] [security2:error] [pid 28323:tid 28331] [client 45.148.126.146:20331] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||atechtransmission.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "atechtransmission.com"] [uri "/wp-json/wp/v2/users"] [unique_id "acb6xVjUrsRGZF1hTR1W8wAAAAY"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-02-07 17:12:28
(4 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐จ๐ฆ
SSH-Admin
2025-12-27 13:45:08
(5 months ago)
Probing for Exploits
Exploited Host
Web App Attack
๐จ๐ฟ
lp
2025-11-23 08:50:31
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 45.148.126.146
2025-11-23T09:38:30+01 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 45.148.126.146
2025-11-23T09:38:30+01:00 vpn Access-Reject 'Kai.Murphy' station: 45.148.126.146 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-11-13 16:21:43
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 45.148.126.146
2025-11-13T16:20:03+01 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 45.148.126.146
2025-11-13T16:20:03+01:00 vpn Access-Reject 'Grayson.Davis' station: 45.148.126.146 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐จ๐ฟ
lp
2025-11-11 14:50:51
(6 months ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 45.148.126.146
2025-11-11T15:34:51+01 ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 45.148.126.146
2025-11-11T15:34:51+01:00 vpn Access-Reject 'reporters' station: 45.148.126.146 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-07 15:41:03
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.126.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.126.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 07 11:40:56.408520 2025] [security2:error] [pid 26413:tid 26413] [client 45.148.126.146:26815] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||mdsshop.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "mdsshop.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aOU0iGpsl0NzjCX0TiMDdwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2025-10-06 07:02:09
(8 months ago)
Accessed trap at '/wp-login.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-05 11:35:03
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.126.146 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.126.146 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 07:34:54.665501 2025] [security2:error] [pid 31566:tid 31566] [client 45.148.126.146:13623] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||humbliaslaw.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "humbliaslaw.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aOJX3lcAZh-8K4FSZ4hMTQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-10-04 05:27:09
(8 months ago)
wordpress-trap
Web App Attack
๐ธ๐ช
OnTheEdge
2025-02-27 16:34:08
(1 year ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
Anonymous
2024-12-20 10:21:42
(1 year ago)
Unauthorized VPN login attempt
VPN IP
Hacking
Anonymous
2024-12-19 07:17:52
(1 year ago)
Unauthorized VPN login attempt
VPN IP
Hacking