๐บ๐ธ
TPI-Abuse
2026-05-21 13:42:22
(2 weeks ago)
(mod_security) mod_security (id:225170) triggered by 45.148.235.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.235.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 09:42:14.807400 2026] [security2:error] [pid 21897:tid 21897] [client 45.148.235.200:40747] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gransla.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gransla.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ag8LtjnHN3bJWmBInbYZJQAAABk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-20 11:47:19
(2 weeks ago)
FPROCO WEBEXPLOIT 45.148.235.200 (45.148.235.200)
Web App Attack
๐บ๐ธ
nationaleventpros.com
2026-05-14 19:44:21
(3 weeks ago)
WordPress login attempt
Brute-Force
๐ง๐ช
voormedia
2026-05-04 04:25:18
(1 month ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-01 12:32:00
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.148.235.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.235.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 01 08:31:56.909887 2026] [security2:error] [pid 19243:tid 19243] [client 45.148.235.200:25679] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||disio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "disio.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afSdPDw6z5NmcujmintOlwAAAAc"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-30 16:34:19
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.148.235.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.235.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 30 12:34:13.806832 2026] [security2:error] [pid 17352:tid 17391] [client 45.148.235.200:58047] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||tomskrodzki.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "tomskrodzki.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afOEhYCZWrVoMr1i3mJl8QAAAYo"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
MAGIC
2026-04-21 01:23:02
(1 month ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-15 12:08:34
(1 month ago)
(mod_security) mod_security (id:225170) triggered by 45.148.235.200 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.235.200 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 15 08:08:29.930093 2026] [security2:error] [pid 275254:tid 275254] [client 45.148.235.200:62259] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||goodpage.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "goodpage.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ad9_vUjLCWb2kqdVdEOFbQAAABI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ptlab
2026-04-09 20:45:56
(1 month ago)
Detected wp_login attack from WP-host.
Hacking
Web App Attack
Anonymous
2026-03-29 03:07:40
(2 months ago)
[Firewall Canary] Temporary ban due to firewall rule match [URI canary:*/xmlrpc.php]
Web App Attack
๐ช๐ธ
el-brujo
2026-03-28 00:45:00
(2 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Chrome/ ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Chrome/94.4 Safari/534.54 Action: managed_challenge Source: firewallManaged ASN Description: PUREVOLTAGE-INC - PureVoltage Hosting Inc. Country: US Method: POST Timestamp: 2026-03-28T00:45:00Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐น๐ท
ceyhun_kivanc_demir
2026-03-25 12:01:00
(2 months ago)
Web App Attack
Hacking
SQL Injection
๐ฉ๐ช
london2038.com
2026-03-24 13:07:39
(2 months ago)
Malformed or malicious web request
45.148.235.200 - - [24/Mar/2026:14:07:37 +0100] "POST /xmlrpc.php ...
show more
Malformed or malicious web request
45.148.235.200 - - [24/Mar/2026:14:07:37 +0100] "POST /xmlrpc.php HTTP/1.1" 404 4187 "-" "Chrome/99.9 Safari/539.59"
show less
Hacking
Web App Attack
Anonymous
2026-03-24 01:17:22
(2 months ago)
"POST /xmlrpc.php HTTP/1.1"
Hacking
Web App Attack
๐ฎ๐ฉ
BPS-StatisticsIndonesia
2026-03-21 11:25:32
(2 months ago)
XML RPC Scan Activities: "2026-03-21T18:25:32.430+07:00" "/xmlrpc.php" "45.148.235.200" "AppleWebKit ...
show more
XML RPC Scan Activities: "2026-03-21T18:25:32.430+07:00" "/xmlrpc.php" "45.148.235.200" "AppleWebKit/535.35 (KHTML, like Gecko111)"
show less
Web App Attack
Brute-Force