๐ง๐ช
Saec
2026-08-09 19:24:04
(3 weeks ago)
Jarvis auto-ban: CF honeypot path /xmlrpc.php (3ร on saec.me)
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 07:30:13
(2 months ago)
(mod_security) mod_security (id:225170) triggered by 45.148.235.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.148.235.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 03:30:05.929263 2026] [security2:error] [pid 16472:tid 16472] [client 45.148.235.72:20511] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||waterjetsolutions.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "waterjetsolutions.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aiu1fUgLSPr4Xy_BN05xwgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-05-26 09:02:13
(3 months ago)
Multiple WAF Violations
Web App Attack
๐ช๐ธ
el-brujo
2026-02-05 13:35:46
(6 months ago)
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla ...
show more
Cloudflare WAF: Request Path: /xmlrpc.php Request Query: Host: foro.elhacker.net userAgent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:146.0) Gecko/20100101 Firefox/146.0 Action: managed_challenge Source: firewallManaged ASN Description: PUREVOLTAGE-INC - PureVoltage Hosting Inc. Country: US Method: POST Timestamp: 2026-02-05T13:35:46Z ruleId: 5de7edfa648c4d6891dc3e7f84534ffa. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
Penny Packer
2026-02-05 03:05:36
(6 months ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฌ๐ง
relianoid.com
2026-01-29 22:05:37
(7 months ago)
POST Abuse detected by Relianoid OSS Load Balancer - relianoid.com
Web Spam
Anonymous
2026-01-25 01:45:54
(7 months ago)
wordpress-trap
Web App Attack
๐ช๐ธ
10dencehispahard SL
2026-01-12 07:18:44
(7 months ago)
Wordpress probing for vulnerabilities
Hacking
Exploited Host
๐ฎ๐ฉ
Burayot
2025-12-24 22:37:28
(8 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.148.235.72 (IL/Israel/-): 1 in t ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 45.148.235.72 (IL/Israel/-): 1 in the last 3600 secs
show less
Web App Attack
๐ซ๐ท
masterguru
2025-12-24 13:48:56
(8 months ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 45.148.235.72 (US/United States/-): 1 in the l ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 45.148.235.72 (US/United States/-): 1 in the last 3600 secs (0-197)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2025-05-31 11:44:05
(1 year ago)
(mod_security) mod_security (id:217200) triggered by 45.148.235.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217200) triggered by 45.148.235.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 31 07:43:58.965068 2025] [security2:error] [pid 1849924:tid 1849924] [client 45.148.235.72:11385] ModSecurity: Access denied with code 403 (phase 1). Match of "endsWith /wp-cron.php" against "REQUEST_FILENAME" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "103"] [id "217200"] [rev "2"] [msg "COMODO WAF: HTTP/1.1 POST request missing Content-Length Header||www.thesalonx.com|F|2"] [data "/xmlrpc.php"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "www.thesalonx.com"] [uri "/xmlrpc.php"] [unique_id "aDrrfolPEKAL3iKf5Wk0jwAAAAc"], referer: https://www.thesalonx.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-09 13:13:34
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.148.235.72 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.148.235.72 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 09 09:13:30.017632 2025] [security2:error] [pid 29433:tid 29433] [client 45.148.235.72:49511] [client 45.148.235.72] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maddiekjones.com"] [uri "/.env"] [unique_id "Z82T-tRHwoKJVmIy3ahZiQAAAAE"], referer: https://tasamm.com/about/mmm23.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
sms.ru
2024-09-21 00:10:08
(1 year ago)
SMS pumping attack from foreign country
DDoS Attack
Anonymous
2024-08-12 01:14:47
(2 years ago)
Ports: 80,443; Direction: 0; Trigger: LF_CUSTOMTRIGGER
Brute-Force
SSH
Anonymous
2023-11-13 02:30:15
(2 years ago)
opencart admin attack from fail2ban
...
DDoS Attack
Brute-Force
SSH