๐ฉ๐ช
8legz.net
2026-06-20 13:21:53
(12 hours ago)
[Sat Jun 20 14:21:47.049938 2026] [php:error] [pid 1538901] [client 45.148.233.72:33777] script '/va ...
show more
[Sat Jun 20 14:21:47.049938 2026] [php:error] [pid 1538901] [client 45.148.233.72:33777] script '/var/www/html/xmlrpc.php' not found or unable to stat
[Sat Jun 20 14:21:51.055499 2026] [php:error] [pid 1538652] [client 45.148.233.72:30743] script '/var/www/html/wp-login.php' not found or unable to stat, referer: https://www.google.com
[Sat Jun 20 14:21:53.068479 2026] [php:error] [pid 1538651] [client 45.148.233.72:29705] script '/var/www/html/wp-login.php' not found or unable to stat, referer: https://www.google.com
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-20 11:19:47
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 45.148.233.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.233.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 07:19:44.404178 2026] [security2:error] [pid 27036:tid 27036] [client 45.148.233.72:27701] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||studioarts.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "studioarts.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajZ3UATHqg9GnPHU6oIn3AAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 07:53:34
(18 hours ago)
(mod_security) mod_security (id:225170) triggered by 45.148.233.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.233.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 03:53:27.791675 2026] [security2:error] [pid 13974:tid 13974] [client 45.148.233.72:13347] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||theholleys.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "theholleys.net"] [uri "/wp-json/wp/v2/users"] [unique_id "ajZG9_7hn3DaEQkPf2iIMQAAAAA"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
artful
2026-05-23 04:58:00
(4 weeks ago)
Excessive errors in recent hours
Web App Attack
๐ฌ๐ง
[email protected]
2026-05-17 00:06:46
(1 month ago)
45.148.233.72 - - [17/May/2026:00:06:43 +0000] "GET /badges/badge.php?hash=2a8d95eb294d52604f68eb59a ...
show more
45.148.233.72 - - [17/May/2026:00:06:43 +0000] "GET /badges/badge.php?hash=2a8d95eb294d52604f68eb59a948200abbf02d4cAND%250E4030%2509IN%2504%28SELECT%250C%28%2527~%2527%2B%28SELECT%2509%28CASE%250CWHEN%250B%284030%3D4030%29%2501THEN%250D%25271%2527%2507ELSE%2503%25270%2527%250FEND%29%29%2B%2527~%2527%29%29+AND+1%3D1--+- HTTP/1.1" 301 644 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
45.148.233.72 - - [17/May/2026:00:06:44 +0000] "GET /badges/badge.php?hash=2a8d95eb294d52604f68eb59a948200abbf02d4c%27AND%2F%2A%2A%2F8403%3D%28SELECT%2F%2A%2A%2FUPPER%28XMLType%28CHR%2860%29%7C%7CCHR%2858%29%7C%7C%27~%27%7C%7C%28SELECT%2F%2A%2A%2F%28CASE%2F%2A%2A%2FWHEN%2F%2A%2A%2F%288403%3D8403%29%2F%2A%2A%2FTHEN%2F%2A%2A%2F1%2F%2A%2A%2FELSE%2F%2A%2A%2F0%2F%2A%2A%2FEND%29%2F%2A%2A%2FFROM%2F%2A%2A%2FDUAL%29%7C%7C%27~%27%7C%7CCHR%2862%29%29%29%2F%2A%2A%2FFROM%2F%2A%2A%2FDUAL%29--+- HTTP/1.1" 301 809 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
45.148.233.72 - - [17/M
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-03-26 20:24:48
(2 months ago)
Detected attack and reported by a human
Brute-Force
Web App Attack
SSH
DDoS Attack
Exploited Host
Bad Web Bot
๐ฎ๐ฉ
Burayot
2026-02-13 02:39:29
(4 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.148.233.72 (NL/The Netherlands/- ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.148.233.72 (NL/The Netherlands/-): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-02-12 20:11:12
(4 months ago)
wordpress-trap
Web App Attack
๐ฉ๐ช
iNetWorker
2026-02-12 09:36:26
(4 months ago)
trolling for resource vulnerabilities
Web App Attack
Anonymous
2025-12-04 20:19:07
(6 months ago)
Forum/form spam
Web Spam
Anonymous
2025-09-14 01:12:39
(9 months ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2025-03-09 21:21:00
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.148.233.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.148.233.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 09 17:20:55.613407 2025] [security2:error] [pid 7532:tid 7532] [client 45.148.233.72:26633] [client 45.148.233.72] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mewebdesign.buffaloweddingdeejay.com"] [uri "/.env"] [unique_id "Z84GNzjROuAk46OaylY1wwAAABA"], referer: https://tasamm.com/about/mmm164.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ป๐ณ
Xuan Can
2025-03-09 12:43:59
(1 year ago)
(mod_security) mod_security (id:77316757) triggered by 45.148.233.72 (NL/The Netherlands/-): 1 in th ...
show more
(mod_security) mod_security (id:77316757) triggered by 45.148.233.72 (NL/The Netherlands/-): 1 in the last 3600 secs; Ports: 80,443; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 09 19:43:52.837496 2025] [security2:error] [pid 26119:tid 26160] [client 45.148.233.72:39317] [client 45.148.233.72] ModSecurity: Access denied with code 403 (phase 2). String match "/.env" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/imunify360-full-apache/007_i360_custom.conf"] [line "343"] [id "77316757"] [msg "IM360 WAF: Laravel .env file access||RSV:6.33||T:APACHE||QS:||"] [severity "CRITICAL"] [tag "service_custom"] [hostname "mail.nhadangky.info.vn"] [uri "/.env"] [unique_id "Z82NCMgg2sf4v_q8Q1AYIwAAAQ4"], referer: https://tasamm.com/about/mmm85.html
show less
Brute-Force
SSH
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2025-02-12 05:55:28
(1 year ago)
WP Login Scan Activities
Web App Attack
๐ฉ๐ช
Bedios GmbH
2025-02-11 17:46:48
(1 year ago)
Wordpress hacking attempt
Web App Attack