🇩🇪
FeG Deutschland
2026-09-14 19:01:25
(16 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 257
Exploited Host
Web App Attack
🇨🇿
Countryman
2026-09-14 00:10:01
(1 day ago)
repeated unauthorized VPN login attempt, user sweep
VPN IP
Hacking
Brute-Force
🇨🇿
lp
2026-09-12 00:22:30
(3 days ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 45.159.21.126
2026-09-12T02:05:31+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 45.159.21.126
2026-09-12T02:05:31+02:00 vpn Access-Reject 'trungthao.le' station: 45.159.21.126 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇨🇿
lp
2026-09-11 04:51:36
(4 days ago)
Unauthorized VPN login attempts: 1 attempts were recorded from 45.159.21.126
2026-09-11T06:40:47+02: ...
show more
Unauthorized VPN login attempts: 1 attempts were recorded from 45.159.21.126
2026-09-11T06:40:47+02:00 vpn Access-Reject 'bonika' station: 45.159.21.126 auth-type: - realm: vse.cz nas: <redacted> called: <redacted> => address-pool: - msg: '<redacted>'
show less
Brute-Force
Web App Attack
🇸🇪
OnTheEdge
2026-09-08 15:22:07
(6 days ago)
Password spraying. Multiple unauthorized login attempts
Hacking
Web App Attack
🇪🇸
Cognisant-Security
2026-07-24 07:37:00
(1 month ago)
Attempts to login WordPress using invalid username
Web App Attack
🇩🇪
LRob
2026-05-19 14:30:18
(3 months ago)
Repeated requests on blocked xmlrpc.php, blocked by fail2ban in custom-503-xmlrpc jail
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-05-04 16:23:17
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.159.21.126 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.21.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 04 12:23:12.910199 2026] [security2:error] [pid 31024:tid 31024] [client 45.159.21.126:42597] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||sheargrafix.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "sheargrafix.com"] [uri "/wp-json/wp/v2/users"] [unique_id "afjH8J0dld5oKowao0FD9AAAAAk"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-04-29 03:20:52
(4 months ago)
Accessed trap at '/xmlrpc.php'
Web App Attack
🇺🇸
TPI-Abuse
2026-04-17 22:28:28
(4 months ago)
(mod_security) mod_security (id:225170) triggered by 45.159.21.126 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.21.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 17 18:28:21.711966 2026] [security2:error] [pid 2369503:tid 2369567] [client 45.159.21.126:47261] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||usu.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "usu.net"] [uri "/wp-json/wp/v2/users"] [unique_id "aeK0BU6CcX7y7LSO3EQmiQAAAg0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-15 00:32:15
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.159.21.126 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.21.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 14 20:32:11.549583 2026] [security2:error] [pid 1481731:tid 1481731] [client 45.159.21.126:38417] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||architech.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "architech.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ad7ci6ac1X-htGJ2GEINcgAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-14 03:15:21
(5 months ago)
(mod_security) mod_security (id:225170) triggered by 45.159.21.126 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.21.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 13 23:15:13.590598 2026] [security2:error] [pid 4191498:tid 4191498] [client 45.159.21.126:25819] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||flamberge.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "flamberge.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ad2xQcnCnjMv1ztJDvuq3wAAAA0"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
backslash
2026-04-02 00:07:05
(5 months ago)
block ruleset bad bot: wordpress scans 82C095539D4FDAF84E2E2FD6B6FC0664645851A8
Bad Web Bot
🇺🇸
xmission.com
2026-03-02 13:42:04
(6 months ago)
45.159.21.126 - - [02/Mar/2026:06:42:03 -0700] "POST /wp-login.php HTTP/1.1" 200 2355 "https://dooce ...
show more
45.159.21.126 - - [02/Mar/2026:06:42:03 -0700] "POST /wp-login.php HTTP/1.1" 200 2355 "https://dooce.com/wp-login.php" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36"
...
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-02-27 01:54:00
(6 months ago)
(mod_security) mod_security (id:225170) triggered by 45.159.21.126 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:225170) triggered by 45.159.21.126 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 20:53:52.270162 2026] [security2:error] [pid 9354:tid 9354] [client 45.159.21.126:33693] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||caschettaconsulting.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "caschettaconsulting.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aaD5MBWSB05fs7UnaBr2NgAAAB8"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack