🇩🇪
Ilop
2026-09-02 11:30:07
(1 week ago)
[hp-100] 19 unsolicited packets to honeypot ports 9000 (OCI DShield sensor)
Port Scan
🇳🇱
DonAtari
2026-08-27 00:10:13
(2 weeks ago)
DShield firewall scan - TCP to port 8000
Brute-Force
SSH
🇺🇸
mkorthuis
2026-08-25 12:04:39
(2 weeks ago)
SSH Brute-Force Attempt
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-06-05 09:37:52
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 45.148.232.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 45.148.232.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 05:37:31.843576 2026] [security2:error] [pid 29494:tid 29494] [client 45.148.232.172:61843] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.evolute.io"] [uri "/wp-config.php.original"] [unique_id "aiKY2yDTNwSe3ynTAj1VLAAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
inlink.ltd
2026-05-20 07:08:10
(3 months ago)
Known malicious PHP file or CMS probe
Web App Attack
🇧🇪
cmbplf
2025-12-25 06:23:21
(8 months ago)
5.273 POST requests with url.path */wp-login.php
Brute-Force
Bad Web Bot
Anonymous
2025-10-09 06:51:47
(11 months ago)
2025-10-09T08:51:46.748253+02:00 zanati wp(www.sahpa.co.za)[3084317]: Blocked authentication attempt ...
show more
2025-10-09T08:51:46.748253+02:00 zanati wp(www.sahpa.co.za)[3084317]: Blocked authentication attempt for [email protected] from 45.148.232.172
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2025-10-05 22:55:35
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.232.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.232.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 18:55:26.452921 2025] [security2:error] [pid 2923261:tid 2923261] [client 45.148.232.172:19595] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.michaelmoorefield.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.michaelmoorefield.com"] [uri "/new/wp-json/wp/v2/users"] [unique_id "aOL3XkKoDC_bYfQFLL41pwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-10-05 11:51:57
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.232.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.232.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 05 07:51:52.997371 2025] [security2:error] [pid 10017:tid 10017] [client 45.148.232.172:58299] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||staben.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "staben.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aOJb2GrBRVgLFV-bz_ex7AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
MM-bot
2025-10-05 03:39:31
(11 months ago)
URL-probe: HTTP/1.1 GET request on /wp-login.php (2025-10-05 05:39:31 UTC+2)
Hacking
Web App Attack
🇺🇸
kosada.com
2025-10-04 18:15:07
(11 months ago)
Web password guessing
Brute-Force
🇺🇸
TPI-Abuse
2025-10-04 08:35:56
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.232.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.232.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 04 04:35:49.129913 2025] [security2:error] [pid 24154:tid 24154] [client 45.148.232.172:51543] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||interiorsolutions-stuart.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "interiorsolutions-stuart.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aODcZeJjD2QjqGApCYJf5AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
octageeks.com
2025-10-03 04:06:04
(11 months ago)
Wordpress malicious attack:[octaflood]
Web App Attack
🇺🇸
TPI-Abuse
2025-10-02 21:42:55
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.232.172 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.232.172 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 17:42:49.946744 2025] [security2:error] [pid 25624:tid 25624] [client 45.148.232.172:14165] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||whodatnation.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "whodatnation.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aN7x2Rm6rk21Cpro9pW74AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-06-20 12:33:02
(1 year ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH