๐บ๐ธ
factor1
2026-06-25 02:53:50
(1 day ago)
Fail2ban at churndash Reports Abuse.
Brute-Force
Web App Attack
๐ฌ๐ง
Steve
2025-10-06 10:50:11
(8 months ago)
Repeated attempts against wordpress site
Brute-Force
Web App Attack
๐บ๐ธ
ne1for23
2025-10-04 14:58:25
(8 months ago)
45.159.20.228 - - [04/Oct/2025:14:58:20 +0000] "GET /wp-login.php HTTP/1.1" 403 555 "-" "Mozilla/5.0 ...
show more
45.159.20.228 - - [04/Oct/2025:14:58:20 +0000] "GET /wp-login.php HTTP/1.1" 403 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/115.0.0.0 Safari/537.36 Edg/115.0.1901.203"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-02 18:39:44
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 45.159.20.228 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.20.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 02 14:39:40.931752 2025] [security2:error] [pid 25105:tid 25105] [client 45.159.20.228:61421] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||engineeringarts.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "engineeringarts.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aN7G7M7QFaL-iHBDKSsV0wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-01 14:25:59
(8 months ago)
(mod_security) mod_security (id:225170) triggered by 45.159.20.228 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.20.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 01 10:25:52.625944 2025] [security2:error] [pid 21673:tid 21673] [client 45.159.20.228:27659] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||salernospizza.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "salernospizza.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aN058DSBActGQZ6U0tx8fQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
SilverZippo
2025-10-01 12:44:40
(8 months ago)
Web App Attack
Web App Attack
๐ฉ๐ช
F242
2025-09-29 14:44:04
(8 months ago)
Wordpress Login or XMLRPC abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-20 16:12:25
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 45.159.20.228 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210492) triggered by 45.159.20.228 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 20 12:12:16.155605 2025] [security2:error] [pid 3195746:tid 3195746] [client 45.159.20.228:44137] [client 45.159.20.228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theavgroup.com"] [uri "/1/wp-config.php.3"] [unique_id "aCyp4Oe8AnVZMKeRUfb-fQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
bigscoots.com
2024-10-10 18:49:55
(1 year ago)
(smtpauth) Failed SMTP AUTH login from 45.159.20.228 (US/United States/-): 5 in the last 3600 secs; ...
show more
(smtpauth) Failed SMTP AUTH login from 45.159.20.228 (US/United States/-): 5 in the last 3600 secs; Ports: 25,465,587; Direction: 0; Trigger: LF_SMTPAUTH; Logs: 2024-10-10 14:49:00 dovecot_login authenticator failed for (NMqgjqDm1) [45.159.20.228]:34853: 535 Incorrect authentication data (set_id=donny)
2024-10-10 14:49:07 dovecot_login authenticator failed for (al9Sr9DHm) [45.159.20.228]:53931: 535 Incorrect authentication data (set_id=donny)
2024-10-10 14:49:17 dovecot_login authenticator failed for (SWB6mq) [45.159.20.228]:38607: 535 Incorrect authentication data (set_id=donny)
2024-10-10 14:49:35 dovecot_login authenticator failed for (h8RGfJPz) [45.159.20.228]:63251: 535 Incorrect authentication data (set_id=donny)
2024-10-10 14:49:53 dovecot_login authenticator failed for (WPx9vM3) [45.159.20.228]:58155: 535 Incorrect authentication data (set_id=donny)
show less
Brute-Force
SSH
๐ต๐ฑ
sefinek.net
2024-08-29 22:12:43
(1 year ago)
This IP address has been identified as generating artificial traffic on websites following the purch ...
show more
This IP address has been identified as generating artificial traffic on websites following the purchase of a specific service from a Fiverr gig. User-Agent and Referrer: Mozilla/5.0 (iPhone; CPU iPhone OS 11_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/76.0.3809.87 Mobile/15E302 Safari/604.1 - -
show less
Bad Web Bot
๐ฉ๐ช
Packets-Decreaser.NET
2024-02-01 03:03:02
(2 years ago)
Incoming Layer 7 Flood Detected
DDoS Attack
Web Spam